On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Acronis BackupCVE-2026-87886Ransomware Recovery
Acronis Backup Plugin CVE-2026-87886: One Tenant, Root on the Whole cPanel Host
CVE-2026-87886 is an actively exploited privilege escalation in the Acronis Backup plugin for cPanel/WHM: a low-priv tenant reaches root via the recovery tool.
8 min read - AI Exploit FoundryZero-DaySecurity Appliances
AI Exploit Foundries: a Zero-Day Assembly Line Aimed at Your Appliances
AI exploit foundries now run scheduled, unattended zero-day research against security appliances — Anthropic's Sept 2026 report found 12+ per month. The defense.
8 min read - Cisco Secure Email GatewayCVE-2026-76461Email Security
Cisco Secure Email Gateway CVE-2026-76461: an inbound email gets root
A crafted email injects SQL into Cisco AsyncOS mail parsing and lands root — no login, no click. CVSS 9.8, KEV, federal deadline 17 Sept. Patch, then hunt the wire.
9 min read - GitLabCVE-2026-85706CI/CD Security
GitLab CVE-2026-85706: Unauthenticated File Read Empties Your CI/CD Secrets
A CVSS 10 path-traversal in GitLab's commits API lets anyone read secrets.yml, deploy tokens and CI/CD variables — no login, no auth log. Patch, then rotate.
8 min read - Cisco FMCCVE-2026-20079Qilin Ransomware
Cisco FMC CVE-2026-20079: the Firewall Manager Roots Itself, and Three Crews Walked In
CVE-2026-20079 is a CVSS 10 pre-auth bypass to root on Cisco Secure FMC, exploited by Sandworm, Qilin, and a crimeware crew. Patch it, hunt it, catch it on the wire.
9 min read - Windows Zero-DayCVE-2026-85880Privilege Escalation
Windows Zero-Days CVE-2026-85880 & CVE-2026-81963: Two SYSTEM Escalations Rated 'Important'
Microsoft's two actively exploited September 2026 zero-days, CVE-2026-85880 and CVE-2026-81963, are both local privilege escalations to SYSTEM — and both scored only 7.8.
8 min read - SAP OVERPASSCVE-2026-44756Pre-Auth RCE
SAP OVERPASS CVE-2026-44756: a CVSS 10 RCE Before SAP Checks Who You Are
CVE-2026-44756 (OVERPASS) is a CVSS 10 memory-corruption RCE in the SAP kernel, reachable pre-auth over HTTP, SAP GUI and RFC. Patch it, hunt it, catch it on the wire.
10 min read - Agentic AICredential HarvestingAutonomous Attack Framework
AI Agents Harvested Thousands of Credentials in Under Six Hours
Google's GTIG watched a financially motivated actor use a multi-agent AI framework to build and run a mass credential-harvesting campaign in under six hours — no human in the loop. What it changes for defenders.
8 min read - Magento Zero-DayAdobe CommerceCVE-2026-75650
StyleSmuggler: the Magento zero-day (CVE-2026-75650) backdooring stores
CVE-2026-75650 is a CVSS 10.0 unauthenticated RCE in Magento and Adobe Commerce, exploited in the wild since 4 September to plant a Rust backdoor that beacons as NTP. Here is how it works and how to catch it.
9 min read