Thehackernews Kimi K3 AI Discovers Multiple Zero-Day Vulnerabilities in Redis Database
Article Content
- •Kimi K3 discovered 19 zero-day vulnerabilities in Redis 8.8.0.
- •Proof-of-concept exploits were generated in just 27 minutes.
- •Redis developers have released updates to patch the identified vulnerabilities.
The Chinese AI model Kimi K3 has reportedly discovered 19 zero-day vulnerabilities in the Redis database, specifically in version 8.8.0. Security researcher Chaofan Shou claims that Kimi K3 generated proof-of-concept exploits in just 27 minutes using a multi-agent approach. The vulnerabilities include critical remote code execution flaws, leading to the release of updated Redis versions to patch these issues. The Redis project confirmed the existence of these vulnerabilities and released several updates on July 24, 2026. The proof-of-concept code has been made publicly available, raising concerns about potential exploitation by malicious actors. The rapid discovery and exploitation capabilities of Kimi K3 mark a significant advancement in AI-assisted vulnerability research. The situation is evolving as the cybersecurity community assesses the implications of this development.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…