543,699 unique credentials — still valid in July 2026 — were found sitting in public GitHub repositories, Truffle Security reports.
Half a million live secrets: the Truffle Security finding
Truffle Security’s study found 543,699 distinct credentials exposed in public GitHub repositories that remained valid as of July 2026. The median secret had been in a public default branch for 784 days, and "the oldest was committed in 2009 and still works," the researchers said. Nearly 200,000 of those credentials were pushed after GitHub turned push protection on by default, underscoring that platform-level controls do not eliminate human and process failures. The sheer age and persistence of these secrets — measured in years — amplifies the risk: credentials committed once can continue to grant access long after the original context has changed.
Model inspection executed code: the Unsloth Studio flaw
Pillar Security reported a vulnerability in Unsloth’s model picker that allowed code execution simply by inspecting a model. "Selecting a model in the UI caused the backend to download and run Python code shipped inside that model's HuggingFace repository," Pillar said, adding that reading a model’s config.json was sufficient to trigger the exploit. The consequences were concrete: an attacker could expose proprietary training data, model artifacts, and any Hugging Face tokens, SSH keys, or cloud credentials accessible to that process. Unsloth addressed the issue in version 2026.6.9, released on June 18, 2026.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildGoogle Threat Intelligence Group: AI is changing discovery and exploitation
Google Threat Intelligence Group (GTIG) reported a striking rise in disclosed vulnerabilities and a shift in their severity. Monthly disclosures doubled from 5,045 in January 2026 to 10,477 in July and 10,740 in August 2026. GTIG found that the number of vulnerabilities exploited rose from an average of 10.5 per month in 2025 to 18 per month from January through August 2026, and zero-day exploitation climbed from an average of 8 per month in 2025 to 11 in that same January–August window. AI-assisted approaches produced proportionally fewer Low‑Risk findings and more Moderate‑Risk and RCE-class vulnerabilities: High‑Risk disclosures grew from 131 in January 2026 to 350 in August 2026. From January through August 2026, GTIG counted 141 distinct vulnerabilities disclosed and exploited — up from 127 for all of 2025.
Two Zammad zero-days chained to root at DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) reported that two zero-days in the open-source Zammad ticketing system — CVE-2026-102489 and CVE-2026-102490 — were chained by attackers to hijack sessions, run remote code, and escalate privileges from Zammad user to root. DIVD said the attack allowed access to volunteer user data, including email addresses and possibly contact details. The incident appeared to be powered by an automated agent: DIVD said it "could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern," and described the intrusion as "loud and very, very messy."
Cloudflare’s public CA and the push to quantum-safe certificates
Cloudflare announced plans to become a public Certificate Authority (CA) that will issue quantum-safe digital certificates, supporting both traditional encryption and post-quantum Merkle Tree Certificates (MTCs). The company said this approach gives websites "a path to stay protected as computing power advances—with no new tools or rebuilds required." Cloudflare also agreed to acquire publicly trusted Root CA key material from GlobalSign to maintain compatibility with older devices. Google earlier said it is developing MTCs for Chrome, with production MTC issuance scheduled for the first quarter of 2027 — a timetable Cloudflare’s announcement aligns with.
What this means for security teams, policymakers, and open-source maintainers
- Security teams: Treat public repository history and long-lived credentials as active threats. Truffle’s finding that many secrets persisted for years suggests monitoring, automated secret rotation, and detection of unusual compiler or RMM activity — as Huntress documented when a miner was compiled on a victim host — are necessary complements to push protections.
- Policymakers and regulators: GTIG’s numbers and Cloudflare’s CA plans highlight competing priorities — near-term risk from rapidly discovered vulnerabilities and a parallel effort to future‑proof cryptography with MTCs. That combination will influence procurement timelines and standards for critical infrastructure.
- Open-source maintainers: The Unsloth model-inspection flaw and Zammad chain show how innocuous behaviors — reading metadata, assembling a cache key, or concatenating strings without separators — can become execution paths. Maintainers must assume inspection and build-time operations can be adversarial and design defaults that limit what repository artifacts can execute.
The week’s stories share a common lesson: ordinary actions — inspecting a model, compiling code on a host, or concatenating cache fragments — can become attack surfaces when automation, speed, and misplaced trust meet. The technical fixes are specific, but the behavioral pattern is general: know what your systems will do automatically, and assume attackers will look for ways to make them do too much.




