The easy way to close the biggest part of the threat surface is to simply not run thumbnailers on removable media by default. And to lessen the inconvenience of such a change, perhaps add some sort of a whitelist to trust specific media and/or readers. Unfortunately, GNOME 2.32 lacks the necessary fine-grained settings for thumbnailing control; you can turn off the Nautilus thumbnailers for network mounts, but there is no way to turn off thumbnailing of random USB flash drives while still showing thumbnails for files on the local hard drive.