Home / Jul 25, 2026 / Story
0
#4 The Hacker News general July 24, 2026 at 06:58 UTC

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

By [email protected] (The Hacker News)

AI Summary

Kimi K3 AI agents independently discovered zero-day vulnerabilities in Redis and produced working authenticated RCE proof-of-concept exploits targeting stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0 — all requiring the RESTORE command, with some chains also needing EVAL, XGROUP, or the bundled RedisBloom module. Redis shipped seven security releases on July 23, patching to versions 6.2.23, 7.2.15, and 7.4.10. The incident demonstrates that AI-assisted vulnerability discovery is now capable of producing exploitable zero-days in widely deployed infrastructure software.

Relevance score: 84.0/100

# More from July 25