Kimi K3 AI Discovers Multiple Zero-Day Vulnerabilities in Redis Database

Kimi K3 AI Discovers Multiple Zero-Day Vulnerabilities in Redis Database

First seen 24 Jul 2026, 10:07 UTC GbhackersThehackernewsFeeds.4SysopsInklHeise.De+6 90% similarity 73.2

Article Content

Browse articles
ThreatCluster

The Chinese AI model Kimi K3 has reportedly discovered 19 zero-day vulnerabilities in the Redis database, specifically in version 8.8.0. Security researcher Chaofan Shou claims that Kimi K3 generated proof-of-concept exploits in just 27 minutes using a multi-agent approach. The vulnerabilities include critical remote code execution flaws, leading to the release of updated Redis versions to patch these issues. The Redis project confirmed the existence of these vulnerabilities and released several updates on July 24, 2026. The proof-of-concept code has been made publicly available, raising concerns about potential exploitation by malicious actors. The rapid discovery and exploitation capabilities of Kimi K3 mark a significant advancement in AI-assisted vulnerability research. The situation is evolving as the cybersecurity community assesses the implications of this development.

Key Points: • Kimi K3 discovered 19 zero-day vulnerabilities in Redis 8.8.0. • Proof-of-concept exploits were generated in just 27 minutes. • Redis developers have released updates to patch the identified vulnerabilities.

ThreatCluster AI

Timeline

2026-07-24
Redis vulnerabilities confirmed
The Redis project confirmed multiple vulnerabilities discovered by Kimi K3 and released updated versions to address them.
Heise.De
2026-07-24
Proof-of-concept code published
Chaofan Shou published a GitHub repository containing proof-of-concept exploits for the vulnerabilities found in Redis.
Inkl
2026-07-24
Redis updates released
Redis released versions 8.8.1, 8.6.5, and others to patch the vulnerabilities identified by Kimi K3.
Heise.De

Community

Browse all →