Researcher Chaofan Shou claims that Moonshot AI’s Kimi K3 agents autonomously found 19 Redis zero-day vulnerabilities in about 90 minutes, then built a working remote-code-execution exploit for one of them in 27 minutes.
Kimi K3 found 19 0days in latest Redis 8.8.0 in 1.5hrs.
That’s charming. Actually it isn’t. I’ll get to that in a moment. Now I am going to get to some commentary by Arti Raman, CEO & Founder, Portal26
“Whether the specific numbers in this claim hold up under scrutiny or not almost doesn’t matter. What matters is that the capability being described, AI agents autonomously chaining vulnerability discovery into a working exploit in under half an hour, is no longer hypothetical. The question every enterprise running AI agents internally should be asking isn’t ‘could this happen to us,’ it’s ‘would we even know if it did.’ Most organizations have no visibility into what their own AI agents are actually doing with the access and tooling they’ve been given, which means an agent operating outside its intended scope wouldn’t look like an attack, it would just look like normal activity in a system nobody’s watching closely enough. You cannot govern what you cannot see, and right now most enterprises can’t see their AI agents at all.”
Roman Sannikov, Global Research Coordinator, iCOUNTERfollows with this:
“The verified part of this story is notable enough on its own: two new Redis vulnerability classes, both patched, both capable of chaining memory corruption into full remote code execution. The unverified part, that a set of AI agents found 19 of these in 90 minutes and built a working exploit in 27, is the part worth treating carefully. Redis confirmed the flaws and the fixes. Nobody has independently verified the count, the timing, or how much of this actually happened without a human steering it.
That said, I wouldn’t dismiss it. We’ve been tracking a real trend of AI compressing the gap between a patch landing and a working exploit existing, and if even a fraction of this claim holds up, it’s consistent with that trend, not a departure from it. The takeaway defenders should draw from this isn’t ‘AI found 19 zero-days in 90 minutes,’ it’s that tools capable of something close to that now exist and are being tested in public. Whether this specific run is accurate or exaggerated, the capability itself isn’t hypothetical anymore, and threat intelligence teams should treat
At this point, I would assume that your opposition is using AI to attack you. Therefore you need to make sure that your defenses take that into account or you will be pwned.
“Intel’s Prescott chip hit 3.8 GHz in 2004 and Intel killed it because raw clock speed had become the wrong metric. K3’s 2.8 trillion parameter headline is the AI equivalent.
“The race now is efficiency, which K3’s own architecture proves with a sparse Mixture-of-Experts activating only 50 billion parameters per token at 2.5x K2’s scaling efficiency. Moonshot can give the weights away because you need 64 accelerators to serve them, and the moat is the deployment stack, not the weights themselves. The AI race will likely go to whoever puts GPT-4-class capability on consumer GPUs, not whoever adds another trillion parameters to their leading frontier model.”
Interestingly, Jacob explored this broader trend before this week’s news in a recent blog, arguing that AI’s next leap wouldn’t be smarter models – it would be AI becoming efficient enough to solve practical problems at scale. The Redis findings are an early proof point of that thesis.
The dental benefits administrator DentaQuest has started issuing notification letters to individuals affected by a May 2026 cybersecurity incident. The number of affected individuals has yet to be confirmed, although DentaQuest has confirmed that at least 15 million individuals have been affected.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“This is a major data breach both in terms of the number of people affected and the types of personal information involved. DentaQuest customers should take advantage of free credit monitoring offered by DentaQuest and monitor their credit reports, bank accounts, and medical bills for unrecognized activity. Whether or not DentaQuest paid ShinyHunters’ ransom demand, there is no guarantee that the group will delete the stolen data. Breach victims should assume the worst and act accordingly to protect their accounts and identities.”
Comparitech recently published an in-depth research study looking at ransomware attacks against healthcare institutions in the first half of 2026, finding that attacks increased nearly 14% since the last half of 2025.
On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.
The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.
One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.
Key Points:
A threat actor operating as “KING” (@Real_King_Engine) sells a paid course, the ISAL Framework, that teaches students to stand up attack infrastructure, generate exploits with commercial AI assistants, deploy web shells, and run a credential-harvesting botnet at internet scale.
KING is a WPScan-credited vulnerability researcher with three published advisories and a Wordfence Intelligence researcher account carrying an approved bounty payout. These are real, verifiable identities – used as legal cover (“educational and defensive research only”) and as a credibility funnel to convert hobbyists into paying students.
The recovered botnet server does not belong to KING. It belongs to one of his students, a self-published developer who identifies publicly as Saeful Rochim (“dalung,” github.com/dalungid), tied to the recovered toolkit by a confirmed code-authorship fingerprint match.
The course teaches push-button, AI-assisted exploitation. In a paying student’s own words: “The system did everything automatically – I only drank soda.” Both Anthropic Claude and Google Gemini appear in the toolchain.
The output SOCRadar recovered: 272 million sites scanned, 2,118,764 administrator credentials harvested across 606,591 domains in 100 countries, and 137 active web shells across 24 countries.
As of the time of writing, the master command-and-control server (217.216.72.31) remained online and continued ingesting fresh target lists.
This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.
Posted in Commentary with tags Hacked on July 24, 2026 by itnerd
Another day. Another company pwned. Rather than go through the story I’ll let this report tell you:
Hacking gang Anubis claimed credit on Tuesday for an attack on Coca-Cola-owned dairy company fairlife, threatening to publish stolen data unless it received an unspecified ransom.
The group made the claim on its dark web site, saying it had stolen 1 terabyte of data from fairlife.
Coca-Cola did not immediately respond to a request for comment, and the hackers did not immediately return a message.
Arvind Parthasarathi, CEO and founder, CYGNVS had this comment:
“AI has fundamentally changed the scale and success of cyberattacks. Instead of manually looking for truffles in a forest, imagine an army of truffle pigs that are searching every square inch of the forest. Where attackers once had to hunt manually for vulnerabilities, today’s frontier AI models give them an army of infinitely scalable AI, constantly digging and searching for weaknesses across every corner of an organization’s environment, while also creating the exploit, taking advantage, and executing it.
That means organizations should expect more successful attacks, more major incidents, more simultaneous incidents, and far greater operational disruption than security teams have historically planned for.
Major cyber incidents used to be treated like once-in-a-decade hurricanes, something that only happened to someone else. Today, many CISOs are dealing with serious incidents every couple of months, and some organizations are managing multiple incidents at the same time.
The question has shifted from ‘will you have a major incident?’ to ‘how do you treat a major incident like business as usual?’
Major incidents like the Coca-Cola and Fairlife attack reinforce that resilience is the key muscle.
Organizations need an out-of-band command center that brings together security, IT, legal, risk, communications, executive leadership and trusted external partners, with pre-defined playbooks covering technical recovery, regulatory reporting, customer communications and evidence preservation. Organizations build resilience more quickly if they have already practiced these scenarios through regular tabletop exercises. Cyber resilience is about making incident response and recovery a repeatable business process.”
This should be a warning to organizations. It’s a matter of when not if you will get pwned. The question is how will you react when that happens.
Claude Cowork has a major issue that could let an AI agent act outside its intended boundaries is the latest example of a pattern the security and compliance community keeps circling back to: we’re deploying autonomous agents faster than we’re building the evidence trail to govern what they actually do.
Justin Beals, CEO & Founder of Strike Graph, an AI-native GRC and compliance automation platform had this to say:
“Every agentic AI vulnerability disclosure tells the same story. We built these tools to act on our behalf, then forgot to build the evidence trail for what they actually did. This isn’t a bug in one product. It’s a category problem.
Once an agent can take action inside a system, it’s not a feature anymore. It’s an identity. And most organizations still govern it like a checkbox on a vendor questionnaire instead of a live risk surface that needs continuous verification.
The companies that get burned by the next version of this flaw will be the ones still treating AI agent oversight as a one-time approval. Continuous evidence of what an agent did, not just what it was authorized to do, is the only model that scales.”
It would really be nice if AI was treated more strictly. But sadly it isn’t and that will come back to bite us all sooner rather than later.
Brand phishing is when a scammer impersonates a trusted, well known company, through email, a fake website, or both, in order to steal login credentials, payment details, or personal information. It works because trust is transferable. If a message looks like it came from a brand you already use and rely on, your guard drops. You’re not evaluating a stranger’s request. You’re responding to what feels like routine correspondence from a company you already have a relationship with. That single psychological shortcut is the entire business model behind brand phishing.
Which Brand Was Impersonated Most in Q2 2026?
Microsoft, by a wide margin. In Q2 2026, Microsoft remained the most impersonated brand in phishing attacks, accounting for 23% of all brand impersonation attempts, nearly double the next closest brand. Here’s how the full top ten broke down.
Together, the top five brand names cover more than half of all brand phishing activity this quarter. That concentration is worth sitting with. Scammers aren’t spreading their efforts across thousands of brands. They’re focused on a small set of names that nearly everyone recognizes and uses daily, since that recognition is what makes the con work in the first place.
Why Did ChatGPT Suddenly Join the Top Ten?
For the first time, the ChatGPT appeared among the ten most impersonated brands tracked in this report. It’s a strong signal of where attacker attention is heading next. As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. One example from June involved a fake ChatGPT Plus billing email, built to look exactly like an OpenAI payment failure notice, that led to a page designed to harvest full credit card details. Expect AI platforms to keep climbing this list in future quarters.
Which Industries Get Targeted Most?
Technology led as the most impersonated sector overall, with Social Networks and Banking close behind. This lines up neatly with the brand rankings above. The industries under the most pressure are the ones handling our identities, our professional relationships, and our money, which also happen to be the accounts most people would be quickest to protect if only they knew an attack was happening.
What Do Real Phishing Attempts Actually Look Like?
The following sample of documented cases from this quarter demonstrate just how varied these schemes can be.
ChatGPT. A fake subscription failure email led to a payment page built to steal credit card details, using an official looking OpenAI subject line and branding.
Michael Kors. A registered lookalike site replicated the entire shopping experience, browsing, cart, and checkout, all designed to capture payment information under the guise of a real purchase.
UNIQLO. A fake regional storefront appeared for a market UNIQLO doesn’t officially operate in. The giveaway was that its social media icons didn’t actually connect to UNIQLO’s real accounts.
Apple. A fake iCloud login page, presented in Russian, used Apple’s real logo and branding. The sign in button itself didn’t work, suggesting the page was still being tested before a fuller campaign.
PayPal. A near identical login page carried a noticeably distorted PayPal logo, a likely sign it had been produced with an AI image tool rather than lifted from PayPal’s actual assets.
Microsoft. A fake support page pushed an urgent Office security update. Clicking through didn’t install anything from Microsoft. It delivered a disguised executable file, the first step of a malware infection.
What Gives Phishing Attempts Away?
A few patterns showed up across nearly every case.
A sense of urgency is doing the work. Payment failures, security alerts, and required updates all push you to act before you stop to think, which is exactly the point.
Small visual flaws are common. A distorted logo, a button that doesn’t respond, icons that lead nowhere. None of these are obvious at a glance, but a more thorough review tends to reveal them.
Domains rarely match the real brand exactly. A slightly off spelling, an unusual extension, or a domain that has no business hosting that brand’s content is a strong signal on its own.
AI-generated assets are starting to leave their own fingerprints. As logos and pages get faked with AI tools, subtle distortions and inconsistencies are becoming one of the more reliable ways to spot a fake.
Posted in Commentary with tags Cinchy on July 23, 2026 by itnerd
Cinchy today announced the general availability of PeriMind, a new suite of AI governance solutions designed to help enterprises run AI safely, predictably and with confidence as artificial intelligence moves from pilots into business-critical operations.
The AI Trust Gap
Enterprise AI adoption is accelerating, but operational trust has not kept pace. Organizations are rapidly deploying copilots, AI agents and autonomous workflows to improve productivity, reduce costs and accelerate decision making. Yet many executives still lack visibility into where AI is being used, what systems it can access, how much it is costing the business or whether its actions align with organizational policy.
As AI becomes embedded in everyday business operations, these blind spots create new challenges. Shadow AI introduces unmanaged applications and models, AI systems consume resources without clear accountability, and security and compliance teams are expected to govern AI behavior without the operational visibility needed to understand what AI is actually doing.
The result is a growing gap between AI adoption and AI trust.
Many enterprise AI initiatives will struggle to scale, not because the technology fails, but because organizations lack the governance, visibility and operational controls needed to deploy AI confidently in production.
Introducing AI Action Governance
Cinchy believes organizations need more than governance frameworks, policies and risk assessments. They need operational control over AI as it works across enterprise systems.
The company defines AI Action Governance as the discipline of observing, governing and enforcing policy over AI behavior in real time as AI systems access data, interact with applications and execute business actions.
PeriMind helps organizations close the AI trust gap by providing the visibility, governance and operational oversight needed to confidently scale AI across the enterprise. Rather than asking organizations to choose between innovation and control, PeriMind enables them to move faster with AI while maintaining confidence that AI systems are operating safely, responsibly and in alignment with business objectives.
Built to Help Organizations Trust AI
PeriMind is designed to help organizations:
Build trust in AI through operational visibility and accountability.
Reduce the risks associated with Shadow AI and uncontrolled AI adoption.
Better understand and manage the operational cost of AI across models, agents and enterprise workflows.
Govern how AI interacts with enterprise data and business applications.
Strengthen security, compliance and human oversight as AI adoption expands.
Built on a Foundation of Trusted Data Access
PeriMind is built on the same governance principles that established Cinchy as a trusted provider of enterprise data access and control solutions.
Organizations worldwide rely on Cinchy’s Data Collaboration Platform to govern how information is shared across complex enterprise environments. With PeriMind, Cinchy extends that foundation to AI, giving organizations the visibility, accountability and control needed to confidently deploy AI across enterprise data, applications and business processes.
Organizations interested in evaluating their AI readiness, governance posture and adoption strategy can schedule a complimentary trusted AI adoption assessment with Cinchy.
Comparitech has published a new study looking at ransomware attacks against the education sector in H1 2026, finding that while overall attacks against educational institutions declined, attacks on higher education actually increased.
Key findings include:
104 attacks in total
36 confirmed attacks
68 unconfirmed attacks
Nearly 693,000 records are known to have been breached in the confirmed attacks
Median ransom demand: $420,620 – up 53% from $275,000 in H2 2025
The ransomware strains that made the most attack claims were The Gentlemen and Qilin (15 each), LockBit (9), Interlock and Nova (6 each)
The Gentlemen claimed the most confirmed attacks (6), followed by Interlock (4) and Qilin and LockBit (3 each)
Posted in Commentary with tags Volvo on July 23, 2026 by itnerd
Volvo Car Canada Ltd. has received Environmental Natural Resources Canada (NRCan) certification for the all-new 2027 Volvo EX60 P10 AWD with an estimated driving range of up to 531 kilometres on a single charge*, exceeding earlier estimates by the company. This marks a significant milestone as the company prepares for customer deliveries.
After its debut earlier this year and the opening of Canadian order books this spring, the EX60 positions Volvo Cars in the mid-size electric SUV segment, the largest and fastest-growing category in the electric vehicle market. The game-changing SUV offers impressive range, fast charging, and exceptional performance – all at a competitive price.
The EX60 P10 AWD delivers the longest electric driving range of any Volvo car sold in the Canadian market to date, transforming range anxiety into a sense of freedom.
The EX60 is the first vehicle built on Volvo Cars’ new SPA3 architecture, which features an 800-volt electrical system that enables the EX60 to charge quickly. For the P10 AWD variant, drivers can add up to 265 kilometres** of range in just 10 minutes, about the amount of time it takes to grab a coffee.
As the first Volvo car equipped with a native North American Charging Standard (NACS) port, the EX60 provides customers with seamless, adapter-free access to more than 29,000 Tesla Supercharger stations across the United States and Canada.
This NRCan certification provides customers with independently verified range performance and underscores the company’s commitment to delivering practical, long-range electric mobility without compromising safety, comfort, or Scandinavian design.
* MY27 EX60 P10 AWD has an estimated range of up to 531 kilometres with 20″ or 21″ all-season tires and up to 502 kilometres with 22″ all-season tires. The figures are based on Natural Resources Canada (NRCan) approved test cycles. Actual range, energy consumption, and charging times will vary depending on factors such as ambient temperature, battery temperature, charging equipment, driving conditions, vehicle configuration, and battery condition. See https://fcr-ccc.nrcan-rncan.gc.ca/en for more information.
** The figures are based on Natural Resources Canada (NRCan) approved test cycles. Actual range, energy consumption, and charging times will vary depending on factors such as ambient temperature, battery temperature, charging equipment, driving conditions, vehicle configuration, and battery condition. See https://fcr-ccc.nrcan-rncan.gc.ca/en for more information. Peak charging estimates are based on the use of a DC fast charger capable of delivering up to 400 kW.
Approov today announced the appointment of Rex S. Jackson as independent Chairman of its Board of Directors. Mr. Jackson succeeds Dr. Lucio Lanza, who has been recognized for his years of leadership and who will continue to serve on the Board as a non-executive director.
Mr. Jackson brings more than three decades of executive and board leadership in Silicon Valley technology companies. He has served as Chief Financial Officer and General Counsel across multiple public and private technology companies, most recently as CFO helping lead ChargePoint through its merger and public listing. He currently serves on the board of Terra Innovatum (Nasdaq: NKLR), where he chairs the audit committee and serves on the compensation committees. Mr. Jackson holds a J.D. from Stanford Law School and a B.A. from Duke University.
The company also paid tribute to Dr. Lanza’s tenure. A legendary figure in semiconductor and electronic design automation investing, Dr. Lanza backed Approov’s vision early and has chaired its Board through years of sustained growth, championing the company’s pioneering work in cloud-based cryptographic mobile app attestation.
The appointment was approved unanimously by Approov’s Board and shareholders, including investors Maven Capital Partners, Lanza Tech Ventures and Scottish Enterprise.
AI agent claims to have found 19 Redis zero-days and built a working exploit in 27 minutes
Posted in Commentary with tags Kimi K3 on July 24, 2026 by itnerdResearcher Chaofan Shou claims that Moonshot AI’s Kimi K3 agents autonomously found 19 Redis zero-day vulnerabilities in about 90 minutes, then built a working remote-code-execution exploit for one of them in 27 minutes.
That’s charming. Actually it isn’t. I’ll get to that in a moment. Now I am going to get to some commentary by Arti Raman, CEO & Founder, Portal26
“Whether the specific numbers in this claim hold up under scrutiny or not almost doesn’t matter. What matters is that the capability being described, AI agents autonomously chaining vulnerability discovery into a working exploit in under half an hour, is no longer hypothetical. The question every enterprise running AI agents internally should be asking isn’t ‘could this happen to us,’ it’s ‘would we even know if it did.’ Most organizations have no visibility into what their own AI agents are actually doing with the access and tooling they’ve been given, which means an agent operating outside its intended scope wouldn’t look like an attack, it would just look like normal activity in a system nobody’s watching closely enough. You cannot govern what you cannot see, and right now most enterprises can’t see their AI agents at all.”
Roman Sannikov, Global Research Coordinator, iCOUNTER follows with this:
“The verified part of this story is notable enough on its own: two new Redis vulnerability classes, both patched, both capable of chaining memory corruption into full remote code execution. The unverified part, that a set of AI agents found 19 of these in 90 minutes and built a working exploit in 27, is the part worth treating carefully. Redis confirmed the flaws and the fixes. Nobody has independently verified the count, the timing, or how much of this actually happened without a human steering it.
That said, I wouldn’t dismiss it. We’ve been tracking a real trend of AI compressing the gap between a patch landing and a working exploit existing, and if even a fraction of this claim holds up, it’s consistent with that trend, not a departure from it. The takeaway defenders should draw from this isn’t ‘AI found 19 zero-days in 90 minutes,’ it’s that tools capable of something close to that now exist and are being tested in public. Whether this specific run is accurate or exaggerated, the capability itself isn’t hypothetical anymore, and threat intelligence teams should treat
At this point, I would assume that your opposition is using AI to attack you. Therefore you need to make sure that your defenses take that into account or you will be pwned.
UPDATE: Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell) had this to say
“Intel’s Prescott chip hit 3.8 GHz in 2004 and Intel killed it because raw clock speed had become the wrong metric. K3’s 2.8 trillion parameter headline is the AI equivalent.
“The race now is efficiency, which K3’s own architecture proves with a sparse Mixture-of-Experts activating only 50 billion parameters per token at 2.5x K2’s scaling efficiency. Moonshot can give the weights away because you need 64 accelerators to serve them, and the moat is the deployment stack, not the weights themselves. The AI race will likely go to whoever puts GPT-4-class capability on consumer GPUs, not whoever adds another trillion parameters to their leading frontier model.”
Interestingly, Jacob explored this broader trend before this week’s news in a recent blog, arguing that AI’s next leap wouldn’t be smarter models – it would be AI becoming efficient enough to solve practical problems at scale. The Redis findings are an early proof point of that thesis.
You can read it here. https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment
Leave a comment »