AI agent claims to have found 19 Redis zero-days and built a working exploit in 27 minutes 

Researcher Chaofan Shou claims that Moonshot AI’s Kimi K3 agents autonomously found 19 Redis zero-day vulnerabilities in about 90 minutes, then built a working remote-code-execution exploit for one of them in 27 minutes. 

That’s charming. Actually it isn’t. I’ll get to that in a moment. Now I am going to get to some commentary by Arti Raman, CEO & Founder, Portal26

“Whether the specific numbers in this claim hold up under scrutiny or not almost doesn’t matter. What matters is that the capability being described, AI agents autonomously chaining vulnerability discovery into a working exploit in under half an hour, is no longer hypothetical. The question every enterprise running AI agents internally should be asking isn’t ‘could this happen to us,’ it’s ‘would we even know if it did.’ Most organizations have no visibility into what their own AI agents are actually doing with the access and tooling they’ve been given, which means an agent operating outside its intended scope wouldn’t look like an attack, it would just look like normal activity in a system nobody’s watching closely enough. You cannot govern what you cannot see, and right now most enterprises can’t see their AI agents at all.”

Roman Sannikov, Global Research Coordinator, iCOUNTER follows with this:

“The verified part of this story is notable enough on its own: two new Redis vulnerability classes, both patched, both capable of chaining memory corruption into full remote code execution. The unverified part, that a set of AI agents found 19 of these in 90 minutes and built a working exploit in 27, is the part worth treating carefully. Redis confirmed the flaws and the fixes. Nobody has independently verified the count, the timing, or how much of this actually happened without a human steering it.

That said, I wouldn’t dismiss it. We’ve been tracking a real trend of AI compressing the gap between a patch landing and a working exploit existing, and if even a fraction of this claim holds up, it’s consistent with that trend, not a departure from it. The takeaway defenders should draw from this isn’t ‘AI found 19 zero-days in 90 minutes,’ it’s that tools capable of something close to that now exist and are being tested in public. Whether this specific run is accurate or exaggerated, the capability itself isn’t hypothetical anymore, and threat intelligence teams should treat

At this point, I would assume that your opposition is using AI to attack you. Therefore you need to make sure that your defenses take that into account or you will be pwned.

UPDATE: Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell) had this to say

“Intel’s Prescott chip hit 3.8 GHz in 2004 and Intel killed it because raw clock speed had become the wrong metric. K3’s 2.8 trillion parameter headline is the AI equivalent.

“The race now is efficiency, which K3’s own architecture proves with a sparse Mixture-of-Experts activating only 50 billion parameters per token at 2.5x K2’s scaling efficiency. Moonshot can give the weights away because you need 64 accelerators to serve them, and the moat is the deployment stack, not the weights themselves. The AI race will likely go to whoever puts GPT-4-class capability on consumer GPUs, not whoever adds another trillion parameters to their leading frontier model.”

Interestingly, Jacob explored this broader trend before this week’s news in a recent blog, arguing that AI’s next leap wouldn’t be smarter models – it would be AI becoming efficient enough to solve practical problems at scale. The Redis findings are an early proof point of that thesis. 

You can read it here. https://suzulabs.com/suzu-labs-blog/the-ai-industrys-prescott-moment

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading