Security · 4h ago
Redis Patches Zero-Days Exploited by Kimi K3 AI Agents
Researchers from Kimi K3 discovered four zero-day vulnerabilities in Redis, leading to authenticated remote code execution exploits. Redis shipped security updates on July 23 for versions 6.2.23, 7.2.15, and 7.4.10. The flaws involve memory issues exploitable via RESTORE, EVAL, and XGROUP commands.
Meridian48 take
The involvement of AI agents in finding and exploiting zero-days signals a new era in vulnerability research, but the real story is Redis's slow response to memory safety issues.
Read the full reporting
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say →
The Hacker News
rediszero-day