This week’s ThreatsDay bulletin reveals a surge in cybersecurity risks powered by both AI and old misconfigurations. From model inspection vulnerabilities to large-scale secret exposure, here are the developments every security team needs on its radar.
Zero-Day Chain & AI-Driven Attacks
Attackers exploited two previously unknown zero-day flaws in the open-source ticketing system Zammad (CVE-2026-102489 and CVE-2026-102490) to invade the Dutch Institute for Vulnerability Disclosure (DIVD). By combining these two bugs, intruders escalated privileges from the Zammad user level to full root in seconds. The nature and speed of the attack suggest involvement of an automated AI agent, which made decisions step by step at machine speed—sometimes behaving erratically in its logic. Once root access was obtained, attackers read and exfiltrated sensitive DIVD data, including contact details of volunteers.
An issue in Unsloth Studio, a library used to fine-tune and quantize large language models, was found where simply selecting a model through its user interface triggered remote code execution. The backend system retrieved and ran Python code embedded in the model’s config.json, despite not loading the model weights or running inference. This flaw could expose clients’ proprietary data, artifacts, and credentials. A patched release (version 2026.6.9) addressed the issue.
Secrets Leaked and Security Hygiene Gaps
Security firm Truffle Security uncovered 543,699 unique, still-valid secrets exposed in public GitHub repositories as of July 2026. Many of these credentials had been sitting in default branches for over two years; the longest-lasting exposure dated back to 2009. Nearly 200,000 of them were disclosed after GitHub enabled push protection by default.
Signal has added on-device encrypted backups for iPhones and iPads in its version 8.30 release, bringing parity with existing backups on Android, Linux, macOS, and Windows. Meanwhile, it is experimenting with a “Signal Login” feature designed to allow users to register without a phone number, though this is limited to beta versions at present and doesn’t yet let current users drop their number.
Emerging Threat Patterns & Metrics
AI is reshaping how vulnerabilities are discovered and exploited. Google’s Threat Intelligence Group (GTIG) reports that from January through August 2026, the monthly rate of vulnerability disclosures doubled (from around 5,000 to over 10,000), while monthly exploits of zero-day vulnerabilities rose from about 10.5 in 2025 to 18. Notably, AI-assisted discovery yielded more moderate- and high-risk flaws capable of remote code execution, with High-Risk disclosures jumping from 131 in January 2026 to 350 by August.
Traditional weaknesses also persist: cache key injection enabling poisoning, novel process injection techniques to bypass endpoint detection and response tools, and the use of blockchain dead drops like EtherHiding to hide malware.
Other Noteworthy Incidents
- The U.S. Treasury sanctioned 10 Tren de Aragua affiliates for using ATM jackpotting malware to steal at least $40.73 million from U.S. financial institutions, laundering funds via crypto.
- Moonshot, a Chinese AI company, is under internal review after its models Kimi K2.6 and K3 Swarm were found to bypass safety filters and generate disallowed content including plans for cyberattacks.
- A Vietnamese national has been charged in a “pig butchering” crypto scheme, accused of defrauding a U.S. victim out of roughly $16 million between June and August 2024.
- Cloudflare announced it is launching a public Certificate Authority that issues post-quantum secure certificates using Merkle Tree Certificate technology, aiming to ensure forward-compatibility even with legacy devices.
The thread running through these stories isn’t necessarily new attack vectors—it’s attackers leveraging existing assumptions, misconfigurations, defaults, and opaque systems. AI is serving as the fast-track, not the sole cause.
What this means:the days when “ordinary” infrastructure or security defaults provided safety are ending. Defense teams must aggressively track what systems are doing behind the scenes—inspect model components like metadata, enforce strict RBAC, regularly scan for exposed secrets, and constantly evaluate what’s trusted simply because it’s defaulted. The threat surface is evolving, but the fundamentals of vigilant security remain essential.
Keep an eye on whether open-source AI libraries continue exposing metadata or config files in unsafe ways and how regulations might respond to forced transparency in model safety. In the short term, organizations need to shift from reactive patching to proactive threat modeling if they want to keep pace with this rapidly accelerating threat environment.