First reported oligo.security
Research · latest
First reported thehackernews.com
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Researchers report that Kimi K3 AI agents autonomously discovered multiple Redis zero-day memory-corruption flaws and built working authenticated RCE proof-of-concept exploits against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0; the chains abuse RESTORE (plus EVAL/XGROUP and the RedisBloom module), and Redis shipped seven security releases on July 23 to fix the Streams shared-NACK use-after-free and RedisBloom/TDigest out-of-bounds writes. Defenders are advised to upgrade and revoke RESTORE from accounts that do not need it. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector