AI-Powered Hack Chains Zero-Days, 543K Live Secrets Exposed
KI-generiertes Bild

AI-Powered Hack Chains Zero-Days, 543K Live Secrets Exposed

This week’s security discoveries show attackers chaining zero-day vulnerabilities with AI, plus over half a million valid secrets found sitting in public GitHub…

The past week brought a sharp set of reminders that everyday systems and forgotten defaults remain a rich attack surface. Automated tools are letting adversaries stitch together exploits faster, but the underlying weaknesses are often the ones that look harmless: a cache that mixes up requests, a public code repository that still holds live credentials, and a model inspection that unexpectedly runs code. Together, the latest incidents underline a common thread: the line between a routine operation and a full-blown compromise can be far thinner than defenders assume.

Attackers chained two zero-day flaws in the open-source Zammad ticketing system to break into the Dutch Institute for Vulnerability Disclosure (DIVD), the security organization itself reported. The vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, allowed session hijacking, remote code execution, and a privilege escalation that gave the intruders root access in seconds. DIVD described the intrusion as “loud and very, very messy,” noting that the assault appeared driven by artificial intelligence. The automated agent moved at lightning speed yet made sloppy missteps, even polluting its own man-in-the-middle attack with password spraying. While the breach exposed volunteer contact details and internal data, it also offered a clear warning: AI-assisted attack chains can weaponize vulnerabilities the moment they are discovered, leaving organisations with little time to react.

The same trend appears in the latest vulnerability statistics from Google’s Threat Intelligence Group. The company reported that the number of disclosed vulnerabilities per month more than doubled in 2026, jumping from 5,045 in January to over 10,700 in August. The average number of exploited flaws rose from 10.5 per month in 2025 to 18 per month in the first eight months of 2026, while zero-day exploitation climbed from an average of 8 to 11 per month. Google noted that AI is not only accelerating discovery but also changing the kind of vulnerabilities that are found; proportionally fewer low-risk bugs and more flaws leading to remote code execution are being unearthed. This shift directly threatens the websites and servers that businesses run every day.

A separate study by Truffle Security drove home the danger of exposed secrets. The firm found 543,699 unique credentials still valid in public GitHub repositories as of July 2026, with the median one sitting in a public default branch for 784 days. The oldest had been committed back in 2009 and still worked. Nearly 200,000 of those credentials were pushed after GitHub turned on push protection by default, showing that platform safeguards alone are not enough. For website owners, a leaked API key or database password can mean a data breach that starts not with an exploit but with a simple search of a public repo. Rotating those secrets and actively scanning for them is no longer optional.

Other new attack techniques emerged that directly affect web infrastructure. YesWeHack detailed a web cache poisoning method called cache key injection, where an attacker takes advantage of how a cache builds its key from user-controlled parts of a URL. If the cache simply glues those fragments together without clear separators, two different requests can end up with the same key. An attacker can then trick the cache into serving a poisoned response to other visitors, potentially leading to stored cross-site scripting or denial-of-service. Because the poisoning can propagate through edge or origin caching layers, any website relying on a vulnerable cache configuration is at risk. On a related note, Cloudflare announced plans to become a public certificate authority that issues quantum-safe Merkle Tree Certificates, preparing websites for a future where quantum computers could break today’s encryption. The certificates will be compatible with older devices and are expected to enter production in early 2027, alongside Google’s development of the same technology for Chrome.

Beyond cache tricks and secrets, several incidents highlighted risks for any host or developer. An attacker exploited the known Samsung MagicINFO vulnerability CVE-2025-4632 to gain access to a target endpoint, then installed a rogue remote desktop tool, created a local administrator account, and disabled security protections. Instead of dropping a pre-built miner binary, the attacker compiled the cryptocurrency miner directly on the victim’s machine, a step that evaded detection by avoiding known file signatures. Meanwhile, the open-source AI library Unsloth was caught with a vulnerability in its model picker that executed Python code from a HuggingFace repository simply by inspecting a model’s metadata. Pillar Security confirmed that no weights needed to be loaded; the act of reading a config.json file was enough to run arbitrary commands, which could expose SSH keys, cloud credentials, and training data. The issue was fixed in version 2026.6.9 released in June 2026.

Also making headlines, the messaging app Signal introduced on-device encrypted backups for iPhone and iPad, a feature already present on other platforms. While this does not directly affect hosting, it underscores the broader push towards end-to-end protection of sensitive data. On the darker side, a Vietnamese national was charged in a pig butchering cryptocurrency scam that cost one victim roughly 16 million dollars, and a threat actor advertisement claiming 22 terabytes of data stolen from Indian embassies came under scrutiny when researchers found the sample data overlapped with public sources, leaving the breach claim unverified.

For website owners and IT teams, these disparate threads converge on a single reality: protection depends on closing the mundane gaps. Managed WordPress hosting from AEU Hosting includes automatic security patching, web application firewalls, and malware scanning that help defend against remote code execution and cache poisoning attacks like those described, reducing the risk that a single unpatched plugin or misconfiguration leads to a breach.

So schützen Sie sich

  1. Enable push protection and secret scanning on your GitHub repositories to catch credentials before they ever become public.
  2. Ensure your web cache configuration uses clear, non-overlapping keys so that requests cannot be mixed up to poison the cache.
  3. Apply security updates for all software you use immediately, especially ticketing systems, content management systems, and AI tools.
  4. Rotate any credentials you have ever stored in code or config files and check that none of them appear in public secret databases.
  5. Use a web application firewall on your site to block known attack patterns, including cache poisoning and remote code execution exploits.

Schwachstellen & Lösungen

Begriffe Erklärt

  • zero-day vulnerability A security hole in software that is unknown to the maker and has no official fix, leaving systems open until a patch is released.
  • web cache poisoning An attack where a malicious response is stored in a website’s temporary memory so that later visitors see harmful content instead of the real page.
  • prompt injection A technique that hides commands inside the input given to an artificial intelligence model, making it do things the operator never intended.
  • Merkle Tree Certificate A new type of website identity card that uses a special tree structure to stay secure even against future quantum computers.
  • EDR (Endpoint Detection and Response) A security program that watches computers and servers for suspicious activity to catch attacks as they happen.
  • pig butchering scam A fraud where criminals build a fake friendship or romance to trick victims into investing huge sums of money, often using cryptocurrency.

Verwandte AEU-Dienste

  • AEU-I IT- und Sicherheitsberatung