VMTech
Discuss a project →

AI-assisted attacks and exposed credentials dominate security roundup

AI-assisted attacks and exposed credentials dominate security roundup

A new ThreatsDay security roundup brings together evidence of AI-assisted intrusion, long-lived credential exposure and software flaws that turn routine operations into attack paths. Among its clearest figures, Truffle Security identified 543,699 unique credentials in public GitHub repositories that were still valid as of July 2026, while attackers chained two Zammad zero-days to compromise the Dutch Institute for Vulnerability Disclosure (DIVD).

The Zammad flaws, CVE-2026-102489 and CVE-2026-102490, enabled session hijacking, remote code execution and escalation from the Zammad user to root. DIVD said the attackers accessed other services and exfiltrated data, including volunteer email addresses and potentially contact details. It described the operation as apparently powered by AI, with an agent selecting subsequent actions automatically.

Exposure persists long after a secret is committed

Truffle Security said the median valid credential had been present in a public default branch for 784 days. The oldest working credential was committed in 2009. Nearly 200,000 of the still-valid credentials had been pushed after GitHub enabled push protection by default, showing that preventive controls do not remove secrets already committed or ensure that every type of credential is detected.

The risk sits alongside a familiar pattern of attack chains. In the wider security landscape, DeFi hack, npm chains, macOS LotL and SIM farms illustrates how multiple technical steps can be combined into a damaging campaign rather than treated as isolated incidents. The current Zammad intrusion similarly shows how two defects can create a path from an internet-facing application to root-level access.

Inspection and automation can become execution paths

Pillar Security found a critical arbitrary code execution issue in Unsloth Studio, the interface associated with the open-source Unsloth library for fine-tuning and quantizing LLMs. Selecting a model caused the backend to download and run Python code from that model’s Hugging Face repository. The researchers said that reading config.json alone could trigger execution; neither model weights nor inference had to be loaded.

An attacker exploiting that behavior could access proprietary training data and model artifacts, along with Hugging Face tokens, SSH keys or cloud credentials available to the affected process. Unsloth addressed the issue in version 2026.6.9, released on June 18, 2026.

Google Threat Intelligence Group also reported a sharp rise in disclosed vulnerabilities during 2026: monthly disclosures increased from 5,045 in January to 10,740 in August. The average number of exploited vulnerabilities rose from 10.5 per month in 2025 to 18 per month between January and August 2026, while average zero-day exploitation increased from eight to 11 per month.

Controls need to cover ordinary system behavior

The roundup also documented cache-key injection, which can make distinct HTTP requests map to the same cache key when unsafe fragments are concatenated without boundaries. YesWeHack said the resulting collision may support cache deception, restricted-response leakage, denial of service or, in particular circumstances, stored cross-site scripting.

For businesses, the practical implication is to identify which secrets remain reachable, apply fixes to exposed services and review workflows that download, inspect, cache or execute external content. Routine system behavior deserves the same scrutiny as a clearly malicious payload.

#cybersecurity#secretsmanagement#zeroday#aisecurity
Open analytics
On the site 2 views
min read 4 01.10.2026
Instagram

AI-assisted attacks and exposed credentials dominate security roundup

Open the post on Instagram ↗