Close Menu
    What's Hot

    Trump angers trade partners with new hikes on tariffs linked to claims of forced labor

    VT: Why Global Stocks May Be Rocky Ahead Of The Midterms (Downgrade) (NYSEARCA:VT)

    Hamzah Sheeraz escapes with narrow points win, while Josh Kelly overcomes horror gash to his nose in Saudi Arabia | Boxing News

    Facebook X (Twitter) Instagram
    Trending
    • Trump angers trade partners with new hikes on tariffs linked to claims of forced labor
    • VT: Why Global Stocks May Be Rocky Ahead Of The Midterms (Downgrade) (NYSEARCA:VT)
    • Hamzah Sheeraz escapes with narrow points win, while Josh Kelly overcomes horror gash to his nose in Saudi Arabia | Boxing News
    • How Many Electrolytes Should You Be Taking, and Can You Have Too Many?
    • Anthropic releases Claude Opus 5 for both AI coding and general office work
    • The hacker who humiliated spyware makers and was never caught
    • Anthony Joshua remembers late friends after win over Kristian Prenga sets up Tyson Fury fight and ‘lovely treat’ for fans | Boxing News
    • Appeals Court Upholds Blocks on Trump Order Restricting Mail Voting
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

    adminBy adminJuly 25, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 24, 2026Vulnerability / Database Security

    Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

    Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

    All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

    Redis 6.2.23, 7.2.15, and 7.4.10 fix the Streams shared-NACK use-after-free; Redis 8.2.8, 8.4.5, and 8.6.5 fix both the Streams issue and the RedisBloom and TDigest out-of-bounds writes; Redis 8.8.1 fixes the RedisBloom and TDigest loaders, while the Streams guard was already present in Redis 8.8.0.

    Two PoC targets, Redis 6.2.22 and 7.4.9, were the May security updates Redis told users to install, but those releases did not include the shared-NACK ownership guard.

    Upgrade to the fixed release for the deployed branch. Until then, revoke RESTORE from accounts that do not strictly need it and block untrusted network access. Restricting RESTORE cuts off both disclosed paths.

    Cybersecurity

    Neither Redis’s July 23 release notes nor the public PoC repositories reviewed reported in-the-wild exploitation as of July 24, 2026.

    Two Paths Through RESTORE

    The Redis Streams path is a shared-ownership bug. A corrupt RDB object can make two consumers point to the same pending-entry record, so removing both consumers frees the same object twice.

    The published script is designed to turn the resulting memory corruption into arbitrary memory access and ultimately invoke system().

    The RedisBloom path is an out-of-bounds write in the TDigest RDB loader. The loader allocated memory from one serialized value but trusted a separate attacker-controlled capacity field when deciding how much data to load.

    The Redis 8.8.0 script is designed to turn that mismatch into read and write primitives, leak Redis and libc addresses, and call system().

    The Streams Shared-NACK Chain

    The first path is in Redis Streams. A corrupt RDB object can make two consumers point to the same pending-entry record, represented internally by a streamNACK. Removing the first consumer frees the object and leaves the second holding a dangling pointer. The scripts then remove the second consumer too. One chunk, two frees.

    Redis 8.6.4’s release notes cite PR #15081. But a source review by The Hacker News found that the tagged 8.6.4 source lacks the duplicate-ownership check added by that change. The guard appears in Redis 8.6.5, released on July 23.

    The published Redis 8.6.4 script is designed to turn the double-free into arbitrary memory access, then poison a database hash function so a crafted GET invokes system(). It restores the pointer and checks whether Redis still responds.

    The RedisBloom TDigest Chain

    The second path sits in the RedisBloom TDigest RDB loader. It allocated its centroid arrays from a serialized compression value, then trusted a separate attacker-controlled capacity field when deciding how many nodes could be loaded. A small real allocation paired with inflated metadata produces an out-of-bounds write.

    The Redis 8.8.0 script is designed to turn the write into read and write primitives, leak Redis and libc addresses, and poison a database hash function so a crafted GET calls system(). A separate proof of concept published the same root cause and an authenticated RCE chain against Redis 8.8.0.

    Cybersecurity

    Redis’s July fix requires the loaded TDigest capacity to match the allocation derived from the compression value. It also bounds the merged and unmerged node counters before reading the arrays.

    Seven Releases, No New CVE Records

    The repository calls the Streams issue part of a CVE-2026-25589 “incomplete fix family,” but Redis maps that CVE to RedisBloom memory corruption during RESTORE, not the Streams shared-NACK flaw. Redis’s July release notes list no CVE or CVSS score for either new bug class.

    As of July 24, searches by The Hacker News found no separate NVD record for the July shared-NACK or TDigest findings. NVD still listed the May records for CVE-2026-25243 and CVE-2026-25589. A search of CISA’s Known Exploited Vulnerabilities catalog returned no entry for either identifier.

    The disclosure follows another AI-discovered Redis RCE flaw patched in May. Bera Buddies describes itself as “AI Agent Research.” Chaofan Shou said on X that Kimi K3 agents found 19 Redis zero-days in about 90 minutes, and said another run produced the Redis 8.8.0 exploit in 27 minutes.

    Those counts, timings, and the claimed degree of autonomy remain self-reported. Redis’s public record confirms the flaws and fixes. It does not validate the claimed zero-day count or how independently the agents worked.

    Redis 6.2.22 and 7.4.9 were the May destination. By July, both needed another update. Check the exact branch version, not whether Redis was merely “recently patched.”

    agents built Exploit Kimi RCE Redis Researchers ZeroDays
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy 25 states are fighting Trump over $740 million in emergency funding
    Next Article Chinese Companies Are Selling Vapes With Chemicals Potentially More Potent Than Nicotine
    admin
    • Website

    Related Posts

    Hungarian GP: Lando Norris jokes McLaren are in ‘new man’s land’ after pole as Lewis Hamilton, Kimi Antonelli plot fightbacks | F1 News

    July 25, 2026

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 25, 2026

    Rogue OpenAI agents forced the ‘AI Kill Switch’ bill. Here’s what it aims to do

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump angers trade partners with new hikes on tariffs linked to claims of forced labor

    VT: Why Global Stocks May Be Rocky Ahead Of The Midterms (Downgrade) (NYSEARCA:VT)

    Hamzah Sheeraz escapes with narrow points win, while Josh Kelly overcomes horror gash to his nose in Saudi Arabia | Boxing News

    How Many Electrolytes Should You Be Taking, and Can You Have Too Many?

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by