CRITICAL
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit
Redis shipped seven security releases on July 23 after researchers published authenticated RCE proof-of-concept exploits — reportedly produced by AI agents built on Moonshot’s Kimi K3 model — against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four exploit chains require the RESTORE command; the Streams-based chains also need EVAL and XGROUP, and the 8.8.0 chain additionally needs EVAL plus the bundled RedisBloom module. Redis says the underlying memory-safety flaws may lead to remote code execution and has released patched versions, including 6.2.23, 7.2.15, and 7.4.10.