On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- NIS2DORAEU AI Act
NIS2, DORA and the AI Act: One Control Set, Three Regulators, One Evidence Problem
The AI Act's transparency rules went live on August 2 while high-risk obligations slipped to December 2027. NIS2, DORA and the AI Act now demand the same evidence — three times over.
8 min read - miniOrange SAML SSOCVE-2026-15981SAML Authentication Bypass
miniOrange SAML SSO CVE-2026-15981: Anyone Can Be Your WordPress Admin
CVE-2026-15981 (CVSS 9.8) and CVE-2026-61979 let an unauthenticated attacker forge a SAML assertion and log into wp-admin as anyone. Already probed in the wild. Here is the fix runbook.
8 min read - Windows IKECVE-2026-33824Autonomous AI Attack
Windows IKE CVE-2026-33824: The AI Ran Recon, a Human Pulled the Trigger
CVE-2026-33824 is a wormable pre-auth RCE in the Windows IKE service, now on CISA KEV. It surfaced inside a DeepSeek-driven autonomous attack campaign. Here is the fix runbook and what the AI tempo really changed.
9 min read - AI-Powered C2npm Supply ChainRedC2
RedC2 4.0: the AI-Powered C2 Framework Hiding in Your npm Dependencies
Trend Micro found 14 trojanized npm packages dropping RedC2 4.0 — a $99 C2 framework whose Red Agent LLM turns plain English into beacon commands. Full remediation runbook.
7 min read - TrueConfCVE-2026-72529CISA KEV
TrueConf CVE-2026-72529: One Open Port, Every Employee Gets Malware
CVE-2026-72529 chains with CVE-2026-72530 to root a TrueConf Server through one default-open port, then swaps the client installer to push PhantomCore to every meeting participant.
7 min read - OT SecurityCritical InfrastructureAI-Generated Exploits
AI-Generated Exploits vs Siemens S7 PLCs: Reading AA26-231A
Five US agencies warn attackers now use AI to write S7comm exploit scripts against internet-exposed Siemens S7 PLCs in water and energy. What advisory AA26-231A means for OT defenders.
9 min read - MLflowCVE-2026-64849CISA KEV
MLflow CVE-2026-64849: an Unauthenticated SSRF That Steals Your Cloud Keys
MLflow's unauthenticated SSRF (CVE-2026-64849, CVSS 9.3) was exploited within hours to reach cloud metadata endpoints and lift IAM credentials. What broke, and the fix runbook.
9 min read - GitLabCVE-2026-19478GraphQL
GitLab CVE-2026-19478: An Unauthenticated GraphQL Directive Can Delete Your Repos
GitLab's out-of-band patch fixes CVE-2026-19478 (CVSS 9.4): an unauthenticated GraphQL directive that can modify or delete public projects and user data. Who is affected, and how to fix it.
9 min read - Windows DNS ServerCVE-2026-62878Wormable RCE
Windows DNS Server CVE-2026-62878: a Wormable Pre-Auth RCE on Every Domain Controller
CVE-2026-62878 is a wormable, unauthenticated RCE in Windows DNS Server — CVSS 9.8, sitting on every domain controller. Why 'exploitation less likely' is the window, not the all-clear.
9 min read