On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- GPT-6 AstraAI Exploit GenerationChrome Zero-Day
GPT-6 Astra Writes Working Exploits — and CVE-2026-85046 Is the Live Test
OpenAI's GPT-6 Astra crossed the 'Critical' cyber threshold, scoring 100% on ExploitBench. AI exploit generation just collapsed the patch window — CVE-2026-85046 shows why.
8 min read - Kestra RCECVE-2026-49869Authentication Bypass
Kestra CVE-2026-49869: One Path Ending in /configs Is Root Without a Password
Kestra CVE-2026-49869 is a CVSS 10.0 unauthenticated RCE: a suffix check in the auth filter turns any /configs-ending path into root. KEV-listed, exploited for cryptomining. Fix + hunt runbook.
9 min read - AI-Generated ExploitsOT SecurityPLC Security
AI Ported a Pre-Auth PLC Exploit for $535: Reading Forescout's WAGO Experiment
Forescout used Claude to port a pre-auth RCE exploit (CVE-2021-31886) between WAGO PLC models for $535 in under a day. What AI-lowered exploit cost means for OT defenders who can't patch.
10 min read - Starlette BadHostCVE-2026-48710FastAPI Security
BadHost (CVE-2026-48710): the FastAPI Auth Bypass Now Chained to Ransomware
'BadHost' (CVE-2026-48710) is a one-character Host-header auth bypass in Starlette, the framework under FastAPI, vLLM and LiteLLM — CVSS 6.5, now KEV-listed and chained to ransomware.
9 min read - AI Coding AgentsGitSpawnSupply Chain
GitSpawn: A Malicious Git Config Makes AI Coding Agents Run Attacker Code
GitSpawn: a repo's own .git/config can make Claude Code, Codex, Cursor and other AI coding agents run attacker code outside the sandbox, with no prompt. What to check now.
10 min read - JFrog ArtifactoryCVE-2026-82329Supply Chain
JFrog Artifactory CVE-2026-82329: One Request Away From Admin on Your Build Pipeline
CVE-2026-82329 is a CVSS 9.8 authentication bypass in JFrog Artifactory. A phantom join key lets an unauthenticated attacker forge admin tokens — patched Aug 28, exploited Sep 1.
8 min read - LangflowCVE-2026-0768AI Stack Security
Langflow CVE-2026-0768: One Endpoint Turns Your AI Stack Into an Attacker's Python Shell
CVE-2026-0768 gives unauthenticated attackers root-level Python on exposed Langflow servers — and they are already harvesting OpenAI and AWS keys. Why the AI stack is the soft target.
9 min read - PaperCutCVE-2026-82078Zero-Day RCE
PaperCut CVE-2026-82078: a Pre-Auth RCE Turns the Print Server Into a Ransomware Doorway
Two chained flaws give unauthenticated attackers RCE on PaperCut NG/MF. Exploited as a zero-day since Aug 26, with the first patch already bypassed — the fix and the hunt.
7 min read - GiteaCVE-2026-60004CISA KEV
Gitea CVE-2026-60004: Self-Register, Push a Patch, Own the Git Server
Gitea CVE-2026-60004 is a CVSS 9.8 RCE in the diffpatch endpoint. Open registration turns a self-hosted Git server into a pre-auth shell. CISA KEV, exploited now.
8 min read