This week’s bulletin shows how ordinary system behaviors like inspecting models, using caches, trusting public infrastructure, and storing secrets can become attack paths when assumptions are too loose. It also highlights active abuse of ATM jackpotting, EtherHiding, Unsloth, Zammad, and exposed GitHub credentials, showing that simple weaknesses still power many modern attacks. #TrenDeAragua #Ploutus #EtherHiding #Unsloth #Zammad #GitHub
Keypoints
- OFAC sanctioned 10 targets tied to Tren de Aragua ATM jackpotting.
- Threat actors are hiding malware instructions on public blockchains with EtherHiding.
- Unsloth Studio could execute Python code just by inspecting a model.
- Cache key injection can cause poisoning, data leakage, or denial of service.
- More than 543,699 valid credentials were found exposed in public GitHub repositories.
Read More: https://thehackernews.com/2026/10/threatsday-ai-powered-zero-day-chain.html