WalkureARCH (@WalkureARCH)
Posted
0 replies · 0 reposts · 1 likes
Redis issued seven security releases on July 23 after researchers published authenticated RCE proofs-of-concept for multiple versions (6.2.22, 7.4.9, 8.6.4, 8.8.0). The flaws involve RESTORE-related memory corruption in Streams (shared-NACK use-after-free) and RedisBloom/TDigest loaders (out-of-bounds writes). Kimi K3 AI agents are credited by researchers with rapidly discovering and exploiting the issues. No confirmed in-the-wild exploitation was reported at the time of writing. Users are advised to upgrade immediately and restrict RESTORE privileges where possible. https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html