Archive for July 24, 2026

AI agent claims to have found 19 Redis zero-days and built a working exploit in 27 minutes 

Posted in Commentary with tags on July 24, 2026 by itnerd

Researcher Chaofan Shou claims that Moonshot AI’s Kimi K3 agents autonomously found 19 Redis zero-day vulnerabilities in about 90 minutes, then built a working remote-code-execution exploit for one of them in 27 minutes. 

That’s charming. Actually it isn’t. I’ll get to that in a moment. Now I am going to get to some commentary by Arti Raman, CEO & Founder, Portal26

“Whether the specific numbers in this claim hold up under scrutiny or not almost doesn’t matter. What matters is that the capability being described, AI agents autonomously chaining vulnerability discovery into a working exploit in under half an hour, is no longer hypothetical. The question every enterprise running AI agents internally should be asking isn’t ‘could this happen to us,’ it’s ‘would we even know if it did.’ Most organizations have no visibility into what their own AI agents are actually doing with the access and tooling they’ve been given, which means an agent operating outside its intended scope wouldn’t look like an attack, it would just look like normal activity in a system nobody’s watching closely enough. You cannot govern what you cannot see, and right now most enterprises can’t see their AI agents at all.”

Roman Sannikov, Global Research Coordinator, iCOUNTER follows with this:

“The verified part of this story is notable enough on its own: two new Redis vulnerability classes, both patched, both capable of chaining memory corruption into full remote code execution. The unverified part, that a set of AI agents found 19 of these in 90 minutes and built a working exploit in 27, is the part worth treating carefully. Redis confirmed the flaws and the fixes. Nobody has independently verified the count, the timing, or how much of this actually happened without a human steering it.

That said, I wouldn’t dismiss it. We’ve been tracking a real trend of AI compressing the gap between a patch landing and a working exploit existing, and if even a fraction of this claim holds up, it’s consistent with that trend, not a departure from it. The takeaway defenders should draw from this isn’t ‘AI found 19 zero-days in 90 minutes,’ it’s that tools capable of something close to that now exist and are being tested in public. Whether this specific run is accurate or exaggerated, the capability itself isn’t hypothetical anymore, and threat intelligence teams should treat

At this point, I would assume that your opposition is using AI to attack you. Therefore you need to make sure that your defenses take that into account or you will be pwned.

UPDATE: Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell) had this to say

“Intel’s Prescott chip hit 3.8 GHz in 2004 and Intel killed it because raw clock speed had become the wrong metric. K3’s 2.8 trillion parameter headline is the AI equivalent.

“The race now is efficiency, which K3’s own architecture proves with a sparse Mixture-of-Experts activating only 50 billion parameters per token at 2.5x K2’s scaling efficiency. Moonshot can give the weights away because you need 64 accelerators to serve them, and the moat is the deployment stack, not the weights themselves. The AI race will likely go to whoever puts GPT-4-class capability on consumer GPUs, not whoever adds another trillion parameters to their leading frontier model.”

Interestingly, Jacob explored this broader trend before this week’s news in a recent blog, arguing that AI’s next leap wouldn’t be smarter models – it would be AI becoming efficient enough to solve practical problems at scale. The Redis findings are an early proof point of that thesis. 

You can read it here. https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident 

Posted in Commentary with tags on July 24, 2026 by itnerd

The dental benefits administrator DentaQuest has started issuing notification letters to individuals affected by a May 2026 cybersecurity incident. The number of affected individuals has yet to be confirmed, although DentaQuest has confirmed that at least 15 million individuals have been affected.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech

“This is a major data breach both in terms of the number of people affected and the types of personal information involved. DentaQuest customers should take advantage of free credit monitoring offered by DentaQuest and monitor their credit reports, bank accounts, and medical bills for unrecognized activity. Whether or not DentaQuest paid ShinyHunters’ ransom demand, there is no guarantee that the group will delete the stolen data. Breach victims should assume the worst and act accordingly to protect their accounts and identities.”

Comparitech recently published an in-depth research study looking at ransomware attacks against healthcare institutions in the first half of 2026, finding that attacks increased nearly 14% since the last half of 2025. 

WP Botnet Master – How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet

Posted in Commentary with tags on July 24, 2026 by itnerd

Today, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.

On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.

The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.

One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.

Key Points:

  • threat actor operating as “KING” (@Real_King_Engine) sells a paid course, the ISAL Framework, that teaches students to stand up attack infrastructure, generate exploits with commercial AI assistants, deploy web shells, and run a credential-harvesting botnet at internet scale.
  • KING is a WPScan-credited vulnerability researcher with three published advisories and a Wordfence Intelligence researcher account carrying an approved bounty payout. These are real, verifiable identities – used as legal cover (“educational and defensive research only”) and as a credibility funnel to convert hobbyists into paying students.
  • The recovered botnet server does not belong to KING. It belongs to one of his students, a self-published developer who identifies publicly as Saeful Rochim (“dalung,” github.com/dalungid), tied to the recovered toolkit by a confirmed code-authorship fingerprint match.
  • The course teaches push-button, AI-assisted exploitation. In a paying student’s own words: “The system did everything automatically – I only drank soda.” Both Anthropic Claude and Google Gemini appear in the toolchain.
  • The output SOCRadar recovered: 272 million sites scanned, 2,118,764 administrator credentials harvested across 606,591 domains in 100 countries, and 137 active web shells across 24 countries.
  • As of the time of writing, the master command-and-control server (217.216.72.31) remained online and continued ingesting fresh target lists.

This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.

To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet 

Anubis Claims To Have Pwned Fairlife/Coca-Cola

Posted in Commentary with tags on July 24, 2026 by itnerd

Another day. Another company pwned. Rather than go through the story I’ll let this report tell you:

Hacking gang Anubis claimed credit on Tuesday for an attack on Coca-Cola-owned dairy company fairlife, threatening to publish stolen data unless it received an unspecified ransom.

The group made the claim on its dark web site, saying it had stolen 1 terabyte of data from fairlife.

Coca-Cola did not immediately respond to a request for comment, and the hackers did not immediately return a message.

Arvind Parthasarathi, CEO and founder, CYGNVS had this comment:

“AI has fundamentally changed the scale and success of cyberattacks. Instead of manually looking for truffles in a forest, imagine an army of truffle pigs that are searching every square inch of the forest. Where attackers once had to hunt manually for vulnerabilities, today’s frontier AI models give them an army of infinitely scalable AI, constantly digging and searching for weaknesses across every corner of an organization’s environment, while also creating the exploit, taking advantage, and executing it. 

That means organizations should expect more successful attacks, more major incidents, more simultaneous incidents, and far greater operational disruption than security teams have historically planned for. 

Major cyber incidents used to be treated like once-in-a-decade hurricanes, something that only happened to someone else. Today, many CISOs are dealing with serious incidents every couple of months, and some organizations are managing multiple incidents at the same time. 

The question has shifted from ‘will you have a major incident?’ to ‘how do you treat a major incident like business as usual?’ 

Major incidents like the Coca-Cola and Fairlife attack reinforce that resilience is the key muscle. 

Organizations need an out-of-band command center that brings together security, IT, legal, risk, communications, executive leadership and trusted external partners, with pre-defined playbooks covering technical recovery, regulatory reporting, customer communications and evidence preservation. Organizations build resilience more quickly if they have already practiced these scenarios through regular tabletop exercises. Cyber resilience is about making incident response and recovery a repeatable business process.”

This should be a warning to organizations. It’s a matter of when not if you will get pwned. The question is how will you react when that happens.