logo

Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes

ID: c8b3e6bd-5a88-5531-b2f2-ab160777230f

STIX ID: report--c8b3e6bd-5a88-5531-b2f2-ab160777230f

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Researcher Chaofan Shou used 32 autonomous agents powered by the Kimi K3 LLM to find 19 zero-day memory-safety vulnerabilities in Redis, producing authenticated RCE proof-of-concepts within 27–90 minutes; Redis released multiple security updates on July 23, 2026 to patch the issues. Key findings include a stream consumer-group double-free leading to system() execution and a RedisBloom TDigest RDB loader heap overflow, all exploits requiring authenticated RESTORE permissions; mitigations include immediate patching, revoking RESTORE rights, and restricting network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.