New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server
ID: 80d25672-f0c4-536c-8815-a73e90755d82
STIX ID: report--80d25672-f0c4-536c-8815-a73e90755d82
Feed Name: cybersecurityNews.com
Research tied to the Kimi K3 AI agent discloses multiple authenticated RCE vectors in Redis: a shared-NACK double-free affecting 6.2.22, 7.4.9, and 8.6.4, and a TDigest heap overflow in the bundled RedisBloom module on 8.8.0. Both attack paths require commonly enabled admin commands (EVAL, RESTORE, XGROUP) and valid credentials; the issues can yield host-level shells without crashing the service. The report urges rapid patching, command restriction/ACLs, network isolation, credential hygiene, module auditing, and monitoring while warning that 8.8.0 is not automatically safe until RedisBloom is fixed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
