On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- FortinetCredential TheftVPN Security
FortiBleed: 74,000 Fortinet Firewalls Leaked and Nothing to Patch
FortiBleed leaked working VPN credentials for ~74,000 Fortinet firewalls in 194 countries. No CVE to patch — the attacker logs in as a valid admin, and scanners see nothing.
7 min read - Arista EOSCVE-2026-7473Network Segmentation
Arista EOS CVE-2026-7473: An Exploited Bug With No Patch Coming
CVE-2026-7473 is on CISA KEV, actively exploited, and Arista plans no patch. Why your scanner and patch dashboard both miss this Arista EOS segmentation bypass.
7 min read - DragonForce RansomwareMicrosoft Teams C2TURN Relay Abuse
DragonForce's Backdoor.Turn: Ransomware C2 That Rides Microsoft Teams Relays
DragonForce's Backdoor.Turn tunnels ransomware C2 through legitimate Microsoft Teams TURN relays over QUIC, invisible to signature NDR. Why behavioral traffic ML is the only witness.
6 min read - FortiSandboxCVE-2026-39808Edge Appliance Security
FortiSandbox CVE-2026-39808: The Security Appliance Nobody Watches
Two FortiSandbox flaws (CVE-2026-39808, CVE-2026-39813) patched in April are now exploited in the wild. Why agentless security appliances are a detection blind spot — and how to catch their compromise.
6 min read - AI GatewayLiteLLMMCP Security
LiteLLM CVE-2026-42271: the AI gateway is now an RCE surface
LiteLLM CVE-2026-42271 turns the most widely deployed AI gateway into unauthenticated RCE via its MCP test endpoints. Why the LLM proxy is the asset nobody inventoried.
8 min read - Air-Gap SecurityVelvet AntCritical Infrastructure
Ten Years Inside an Air-Gapped Network: Velvet Ant's Operation Highland
Velvet Ant spent a decade inside an air-gapped critical-infrastructure network by backdooring Linux PAM and OpenSSH. Why the air gap is not the control you think it is.
8 min read - SplunkPre-Auth RCESIEM Security
Splunk CVE-2026-20253: a Pre-Auth RCE Inside Your SIEM
Splunk Enterprise CVE-2026-20253 is an unauthenticated RCE chained through a PostgreSQL sidecar — the SIEM itself becomes the attack surface. The mechanism and the blind spot.
10 min read - RansomwareSelf-Propagating MalwareLateral Movement
The Gentlemen Ransomware: A Self-Propagating Worm Your EDR Can't See
The Gentlemen (Storm-2697) turned its encryptor into a worm with 21 lateral-movement methods — and disables Defender on every host it touches. Why the network sees what the endpoint can't.
7 min read - Oracle PeopleSoftShinyHuntersCVE-2026-35273
Oracle PeopleSoft Zero-Day CVE-2026-35273: ShinyHunters Was Gone Before the Advisory
ShinyHunters exploited a CVSS 9.8 PeopleSoft zero-day (CVE-2026-35273) against 100+ orgs — 68% universities — and Google had to notify the victims. The breach-evidence reckoning.
8 min read