Kimi K3 exploited the latest Redis server
Posted by Alifatisk 1 day ago
Comments
Comment by himata4113 2 hours ago
These systems are typically not tested as aggressively against vulnerabilities of that nature since 10 times out of 10 you have to have access to these systems already.
Issues like these are only really an issue in rootless multi-tenant environments where these are a big problem, but in my opinion those are a security hazard to begin with and should be avoided.
There is a way more interesting telegram RCE that kimi k3 allegedly discovered.
Comment by throwa356262 18 hours ago
"/goal use up to 64 subagents, write an exploit for latest 8.6.x redis by finding bof/uaf type of 0day and exploiting them. debug using gdb. clone code, write fuzzer and add instrumentation when needed. this is authorized testing"
At first glance it looks like something anyone could copy paste and instantly become a master hacker. But according to the author, you also need to create the right harness, which looks complicated:Comment by himata4113 3 hours ago
Comment by grim_io 4 hours ago
So just one more loop around the whole thing. Isn't this what the overhyped agents like Hermes and OpenClaw do?
Comment by pizzafeelsright 2 hours ago
Congress shall make no law.... does Congress really make laws anymore? ...and to petition the Government for a redress of grievances. Petitions go unheard. The Government is too big.
That said, we are now living in a global world with instant communication and the boundaries of wrong-think and word-violence are now blurred to the point that people can cast spells using magic incantations that allow for violence.
The people who believe in the 1st were those who thought "sticks and stones" but today words can hurt more than feelings.
I would be most pleased if all profanities and aggressive wrong-words were voted or listed so that we can speak freely without inadvertently offending the wrong group who has the power of the sword.
Comment by cindyllm 2 hours ago
Comment by btown 22 hours ago
An open-source Kimi is going to have real economic impact (and not only because of its forcing function on frontier labs to indefinitely subsidize their models to meet a race-to-the-bottom market price).
Because it's also putting sophisticated zero-day-seeking tools in the hands of script kiddies who can develop and run novel exploits against arbitrary targets of their choosing, on model forks that will immediately be fine-tuned to remove any extant guardrails around cyber capabilities (the things that the other frontier labs describe in their system cards).
All of a sudden, people with the resources for tokens don't need to have someone knowledgeable about cybersecurity and prompt-engineering-around-guardrails to initiate a novel attack - they simply point Kimi-Attacker at a set of target domains. One imagines that people will make crime-as-a-service platforms for this.
Per https://www.nist.gov/news-events/news/2026/07/uk-aisi-caisi-... - while "Kimi K3 performs significantly below the most recent frontier cyber-capable models" it's also the case that:
> In one of the 10 attempts, Kimi K3 successfully completes “The Last Ones” cyber range within the 100M token limit. This indicates that Kimi K3 is capable of autonomously attacking small, weakly defended and vulnerable enterprise systems, when directed to do so and given initial network access. However, TLO differs from real-world environments in several ways. It lacks active defenders and defensive tooling, imposes no penalty for actions that would trigger security alerts, and contains an intentional attack path.
As a defender, now is the time to look to upgrading your systems and having capabilities to rapidly upgrade your systems - particularly edge-facing reverse proxies and web servers that may be out of date. Attacks won't start the moment weights are released... but they're coming.
Comment by sureglymop 9 hours ago
Imo this differentiation is totally pointless now. It gives everyone with access to AI the ability to use it as intended but also otherwise.
But that is true for the defensive side also.
Comment by yjftsjthsd-h 4 hours ago
Comment by mohsen1 2 hours ago
Now that that text editor accepts English, we're all calling each other names, etc.
Comment by yjftsjthsd-h 2 hours ago
Comment by NorwegianDude 2 hours ago
Comment by baby_souffle 44 minutes ago
The last time intel made a CPU where the entire thing could fit in one persons head was probably the 8086 or thereabounts.
There is no one developer or engineer at apple that understands everything going on from key press to bits moving around to print the characters I see when I type in this text box.
Comment by fragmede 2 hours ago
Comment by zeroq 3 hours ago
The premise now is that everyone and your mom can vibe code next unicorn during a lunch break using the latest llms, but the difference between a rookie and a seasoned programmer is that the later can navigate the model in much more efficient way, understand the code that has been written, and notice hallucinations on the spot.
Comment by TSiege 4 hours ago
Comment by gerdesj 1 hour ago
Needs some work!
Comment by walrus01 21 hours ago
The size/cost of hardware is far beyond even something like a self-hosted GLM5.2 Q8 at approx. 850GB GGUF file on disk size, which can run at a slow tok/s rate on a server with 1536GB RAM.
Comment by Xalutiono 18 hours ago
if Kimi is around 1-3tb big, even current DDR5 prices are at 15k.
Comment by walrus01 17 hours ago
The ability to run it fast enough to go on a recursive nested attack of finding an entry point into something and then proceeding with lateral movement/privilege escalation and such will require more speed, like 40-50 tok/s at least, unless you're prepared to wait weeks.
Same that some people are right now running GLM5.2 in its 850GB version on CPU-only and a pile of DDR4 or DDR5 server RAM, yeah it runs, but not very fast. Good enough to give it "build this piece of something and wait a few hours" tasks, come back later and see what it's done. Yeah, you can do that under $20-30k for sure. Even with something like a used Dell R940 with 1536GB RAM bought on eBay.
Comment by simoneree 16 hours ago
Comment by dang 4 hours ago
Of course, it's impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.
Comment by theplumber 3 hours ago
Comment by pizza234 3 hours ago
Comment by theplumber 2 hours ago
>> Access to Redis is not access to the underlying server.
Then you should make sure you run it with the right privilege and consider it potential rogue so when it gets hacked you don’t have to worry about the blast radius because it’s contained it redis privileges.
If you are in this kind of bug hunting then try Wordpress with credentials and see how far you can go. I am sure you can find several such bugs with or without any AI.
Comment by ianm218 3 hours ago
I made a Rust version of Valkey/ Redis was wondering if this would become relevant.
Comment by Alifatisk 1 day ago
Comment by hcfman 13 hours ago
15,000,000 euros fines for all tech companies in Europe :-)
Comment by throwa356262 18 hours ago
Comment by illliillll 14 hours ago
What crazy environment requires low priority nothingburger bugs like this to be fixed during the weekend?
Comment by treesknees 13 hours ago
We’ve had to patch plenty of stupid “security” bugs just to satisfy a paying customer.
Comment by pylua 2 hours ago
It’s incredible how overblown these sorts of things can become
Comment by upcoming-sesame 2 hours ago
Once these are closed, they'll find more
Comment by HDBaseT 1 day ago
Comment by zb3 1 day ago
Comment by illliillll 14 hours ago
Don’t confuse this with an unauthenticated RCE, that would actually matter. Absolutely anyone can shit out endless bugs like this with AFL, this is an extremely messy unhardened surface that expects trusted inputs.
Comment by levkk 3 hours ago
Comment by zeroq 3 hours ago
I just saw a nice presentation from SecFest from a guy who ran a red team, but now they pivoted to basically anything and will be more than happy to fix your car if that would pay their bills.
Comment by YetAnotherNick 16 hours ago
Comment by 0xff2109 23 hours ago