July 25, 2026
- Kimi K3's Redis zero-days force seven security releases. Following last week's report of 32 subagents finding a Redis 0-day in 27 minutes (earlier coverage), Redis shipped seven patches on July 23 after researchers published authenticated RCE PoCs against stock 6.2.22, 7.4.9, 8.6.4 and 8.8.0. All four chains require
RESTORE; the Streams chains also needEVAL/XGROUP, and the 8.8.0 chain leans on the bundled RedisBloom module. The Hacker News. · AI & Model Security
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public