ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
AI Summary
Threat actors are exploiting a critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, which allows arbitrary code execution during model inspection. The flaw, triggered by reading a model's config.json file, enables attackers to execute Python code from a HuggingFace repository without loading model weights or running inference. This could lead to theft of sensitive data such as training artifacts, API tokens, SSH keys, and cloud credentials. The vulnerability has been patched in version 2026.6.9, released on June 18, 2026. Additionally, two zero-day vulnerabilities in Zammad (CVE-2026-102489 and CVE-2026-102490) were chained to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), enabling remote code execution and privilege escalation to root.
AI-extracted · verify before operational use