Three Execution Paths Expose Trust Failures in Zammad, MagicINFO, and Unsloth Studio
Zammad session hijack led to root at DIVD, MagicINFO flaw enabled AnyDesk and cryptomining, and Unsloth executed code on model selection.
Illustrative image generated with AI
Recent security findings show how seemingly routine operations can become entry points for serious compromise. The cases involve support-platform sessions, arbitrary file writes on a signage server, and metadata inspection inside an AI development tool.
Threat actors reportedly chained two Zammad vulnerabilities to breach the Dutch Institute for Vulnerability Disclosure (DIVD), reaching root privileges and exfiltrating data. DIVD attributed the intrusion’s speed and decision-making pattern to an apparently AI-assisted agent.
In another incident, Huntress traced a compromise to an exploited Samsung MagicINFO 9 Server flaw already listed in CISA’s Known Exploited Vulnerabilities catalog. The attacker installed AnyDesk, weakened endpoint defenses, created an administrator account, and compiled a cryptocurrency miner on the victim system.
A third issue affected Unsloth Studio. Merely selecting a Hugging Face model could cause repository-controlled Python code to execute during inspection, before weights were loaded or inference began.
Two Zammad flaws gave attackers a path from hijacked sessions to root
Threat actors compromised DIVD by combining CVE-2026-102489 and CVE-2026-102490, according to reporting by The Hacker News.
The first vulnerability affects Zammad versions 6.3.0 through 6.5.4. It permits session hijacking that can progress to remote code execution under the local zammad account.
The vulnerability is also present in versions 7.0.0 through 7.1.3. However, the NVD description states that environmental conditions make it non-exploitable across that version range.
The second flaw completes the privilege chain. CVE-2026-102490 affects every Zammad version, including the latest alpha, and allows a local zammad user to elevate privileges to root.
DIVD said attackers used the two vulnerabilities together to take over sessions, execute code, and obtain root-level control. After compromising the Zammad system, they accessed other services and read and exfiltrated data. The affected information included volunteer user data, such as DIVD email addresses and possibly additional contact details.
This sequence matters for incident scoping. The compromise did not end with the initial application server, so an investigation limited to Zammad logs or filesystem changes could overlook subsequent access to connected services.
DIVD characterized the operation as automated and apparently AI-assisted. According to its account, the agent chose a new action after each step and operated rapidly, but its behavior was also erratic. DIVD reported that the attacker contaminated its own man-in-the-middle activity by introducing password spraying into the operation.
That description is DIVD’s assessment of the observed behavior. It should not be expanded into claims about the specific model, operator, or automation framework involved, none of which are established by the cited account.
MagicINFO path traversal led to remote access and cryptomining
Huntress reported a separate compromise beginning with exploitation of CVE-2025-4632, a path traversal vulnerability in Samsung Electronics MagicINFO 9 Server.
The flaw affects versions before 21.1052.0. NVD’s affected-product table expresses the range as versions 0 to below 21.1052, while the corresponding configuration defines vulnerable software as anything earlier than 21.1052.0.
The underlying weakness is CWE-22, improper restriction of a pathname to an authorized directory. An attacker can abuse the condition to write an arbitrary file with system authority.
CVE-2025-4632 carries a CVSS 3.1 score of 9.8 Critical from both NVD and Samsung TV & Appliance. Its vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Those metrics describe a network-reachable attack with low complexity, requiring neither prior privileges nor user interaction. Successful exploitation can have high confidentiality, integrity, and availability impact.
In the incident described by Huntress, the attacker made three attempts before deploying a rogue AnyDesk instance. The operator then created a new local administrator account, disabled Defender protections, and compiled cryptocurrency-mining software directly on the compromised endpoint.
The local compilation stage is operationally significant. Detection focused only on known miner binaries may miss earlier signs, including repeated remote-management software downloads, unusual compiler activity, unauthorized administrator creation, and changes to Defender settings.
The NVD entry for CVE-2025-4632 was published on May 13, 2025, and last modified on June 17, 2026. It points to Samsung’s security update section SVP-MAY-2025.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on May 22, 2025. The remediation deadline for U.S. federal agencies was June 12, 2025.
CISA’s required action is explicit: apply mitigations following vendor instructions, use applicable BOD 22-01 guidance for cloud services, or discontinue the product if mitigations are unavailable. Its KEV status, combined with Huntress’s incident findings, establishes that defenders are dealing with exploited attack surface rather than a purely theoretical flaw.
Unsloth Studio executed code while inspecting model metadata
Pillar Security identified another trust-boundary failure in Unsloth Studio, part of an open-source library used to fine-tune and quantize large language models.
The issue was located in the model-selection workflow. Choosing a model in the interface could prompt the backend to download and execute Python code contained in that model’s Hugging Face repository.
No inference was necessary. The backend also did not have to load the model weights.
Instead, reading config.json as part of a metadata check was sufficient to trigger execution. This turned model inspection into a code-execution event, even though users could reasonably view the operation as passive examination of repository metadata.
The injected code ran with the privileges of the account operating Unsloth Studio. Depending on that account’s permissions and environment, an attacker could access proprietary training data, model artifacts, Hugging Face tokens, SSH keys, or cloud credentials.
Pillar also identified other potential consequences, including modification of models or training outputs and the use of accessible credentials to enter additional systems. These impacts depend on what the affected process can reach.
The issue was fixed in Unsloth version 2026.6.9, released June 18, 2026. No CVE identifier or severity score is established in the cited reporting.
Organizations using Unsloth Studio should verify that deployments have been updated to the corrected version. They should also minimize credentials and sensitive data available to the Studio process, because repository-supplied code executes within that user’s security context.
Defenders should investigate the entire execution chain
Each case exposes a different sequence of observable behavior.
For Zammad, defenders should examine session anomalies alongside execution under the zammad account, privilege escalation to root, and subsequent access to other services. Because DIVD reported data exfiltration, reviews should extend beyond evidence of initial code execution.
MagicINFO administrators should first identify deployments older than 21.1052.0 and follow Samsung’s remediation guidance. Systems exposed while vulnerable warrant investigation for unexpected file creation, AnyDesk installation, repeated remote-management-tool downloads, new local administrators, Defender configuration changes, and unexplained compiler processes.
The miner itself may be the final stage, not the best detection point.
Unsloth Studio requires a different control model. Model repositories should be handled as potentially executable input rather than passive collections of weights and configuration files. Restricting the Studio process’s access to secrets, training assets, SSH keys, and cloud credentials can reduce the impact of repository-controlled execution.
Other research extends the same trust-boundary problem
Several related developments show how data can become an instruction when software assigns it unintended authority.
Chainalysis described EtherHiding, a form of Blockchain Dead Drop that stores malware instructions on public blockchains. Such infrastructure is harder to seize or remove than a conventional attacker-controlled server. Chainalysis said North Korean and Iranian state operators were developing distinct techniques and reported a 440% rise in BDD activity since the launch of high-capacity Chinese open-source AI models without malicious-code restrictions. That timing does not establish causation.
YesWeHack detailed cache key injection, where applications concatenate attacker-influenced values without clear separators. Two different HTTP requests can then generate the same cache key. Depending on the endpoint and caching architecture, a collision may enable cache deception, restricted-response disclosure, denial of service, or stored cross-site scripting under more specific conditions.
Tracebit explored indirect prompt injection as a defensive mechanism through Context Bombs. Its test placed crafted instructions inside a canary secret in AWS Secrets Manager. Conversation delimiters and a forged user message were designed to convince an exploring agent that its operator had ordered it to stop.
Across these cases, the core failure is not limited to one product category. Sessions become execution footholds, file paths become privileged write primitives, metadata becomes Python code, and cached or retrieved content becomes operational instruction. Defenders must therefore examine not only what systems process, but what authority they grant during processing.
Sources
This article is an original reworking based on the sources below.
- primary sourceNVD (NIST)
- The Hacker News
CVEs covered in this article
- CVE-2025-4632Critical9.8Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- CVE-2026-102489Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- CVE-2026-102490All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.




