A weekly ThreatsDay bulletin highlights how ordinary components can become attack paths when misused, with AI and automation accelerating both discovery and exploitation. The piece surveys a wide range of incidents and research, from model inspection triggering arbitrary code execution in Unsloth Studio to new evasion techniques for endpoint detection and a growing trend of AI-assisted vulnerability discovery.
Notable items include a critical model inspection flaw in Unsloth Studio that could execute Python code from a HuggingFace repository just by selecting a model (addressed in version 2026.6.9 as of 18 June 2026), and a report from GTIG showing AI-driven vulnerability disclosures jumping sharply in 2026, with high-risk and RCE-class flaws becoming more prevalent.
The bulletin also notes a shift in attack surface due to automation and AI, where attackers chain multiple vulnerabilities for remote code execution or privilege escalation, sometimes leveraging public infrastructure to hide commands.
The collection of stories covers financial, cryptomining, governance and infrastructure vectors, including CVEs such as CVE-2025-4632 linked to a Samsung MagicINFO flaw exploited to compile a miner on an infected host, and CVE-2026-102489 and CVE-2026-102490 chained to break into the DIVD via Zammad. Other entries discuss EtherHiding on blockchains, cache poisoning via web cache key collisions, and new EDR-evading process injection techniques.
The report also highlights policy actions (OFAC sanctions tied to ATM jackpotting) and substantial exposure risks (543,699 public GitHub credentials still valid as of July 2026). Practically, defenders are urged to question assumed safe normality, audit trusted pathways and data flows, tighten model inspection safeguards, monitor AI-assisted tooling, and treat high‑risk disclosures with heightened remediation priority.