Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

Redis 6.2.23, 7.2.15, and 7.4.10

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Anatomy of a Failed (Nation-State?) Attack

Anatomy of a Failed (Nation-State?) Attack Source: Hacker News

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and

OpenAI reduces Codex Model Context Size from 372k to 272k

OpenAI reduces Codex Model Context Size from 372k to 272k Source: Hacker News