# Kimi K3 exploited the latest Redis server

_Friday, July 24, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Kimi K3 exploited the latest Redis server — Primary](https://cdn.eweek.com/unnamed (36)-1.png)

A security team using Moonshot AI's Kimi K3 said one of its agents found a Redis flaw and built a working remote code execution exploit in 27 minutes, according to a report published Thursday. The researchers published authenticated proof-of-concept exploits targeting Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with both attack paths requiring access to the RESTORE command.

Redis issued seven security updates on July 23 to address the underlying memory-corruption flaws. Fixed versions were released across supported branches, including 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1. Neither Redis' July 23 release notes nor the public proof-of-concept repositories reported exploitation in the wild as of July 24.

The first attack path involved a shared-ownership flaw in Redis Streams, while the second affected the RedisBloom TDigest loader. The published scripts were designed to turn memory errors into arbitrary read-and-write access and eventually execute system commands. CyberPress said the Kimi K3 agent cloned the Redis source code, fuzzed selected functions, and used the GDB debugger with limited human guidance.

The reported 27-minute exploit-development time and a separate claim that Kimi K3 agents found 19 Redis zero-days in about 90 minutes remain self-reported. Redis confirmed the underlying flaws and released fixes but did not verify how independently the agents worked or validate the claimed number of discoveries.

## Sources

- [eweek.com](https://www.eweek.com/news/moonshot-ai-kimi-k3-redis-rce-exploits-apac-china/)

---
Canonical: https://techandbusiness.org/newswire/jnDcHvAu_2ZQrSoVs2b__K
Retrieved: 2026-07-25T09:20:25.524Z
Publisher: Tech & Business (techandbusiness.org)
