On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- PasskeysWebAuthnPhishing-Resistant MFA
Pass-ta-key: your synced passkeys are only as strong as the endpoint
Unit 42 showed unprivileged malware can forge WebAuthn assertions and decrypt Google-synced passkeys. What that does to the phishing-resistant MFA box you already ticked.
13 min read - Adobe Campaign ClassicCVE-2026-48449Authorization Bypass
Adobe Campaign Classic CVE-2026-48449: the Same CVSS 10.0, a Third Time
Adobe shipped its third CVSS 10.0 authorization bypass in Campaign Classic in 50 days. The build that fixed you in June is the build that failed you in July — and Adobe is about to stop counting them separately.
16 min read - Ruby on RailsCVE-2026-66066Secret Rotation
KindaRails2Shell (CVE-2026-66066): the patch doesn't un-leak your secret_key_base
CVE-2026-66066 leaks Rails secrets through an image upload. Patching closes the loader — it does not rotate the keys, and the forensic evidence is on a deletion timer.
12 min read - TeamCityCI/CD SecuritySupply Chain
TeamCity CVE-2026-63077: pre-auth RCE on the box that ships your code
CVE-2026-63077 is an unauthenticated RCE in every TeamCity On-Premises build. Last time this happened, exposed servers were mass-compromised within 48 hours.
10 min read - AI Agent SecurityMCP SecurityUnauthenticated RCE
Ruflo CVE-2026-59726: an MCP bridge RCE that outlives the patch
Ruflo CVE-2026-59726 (CVSS 10.0) exposed 233 MCP tools with no authentication. The RCE is fixed in 3.16.3 — the poisoned agent memory it left behind is not.
10 min read - Cisco FMCCVE-2026-20316CISA KEV
Cisco FMC CVE-2026-20316: the CVSS 5.3 that CISA put in KEV
Cisco FMC CVE-2026-20316 is a static credential scored 5.3 and exploited as a zero-day. CVSS scores one bug at a time; attackers buy the whole chain.
10 min read - BMC SecurityIPMICVE-2013-4786
24,650 exposed BMCs leak IPMI password hashes — and there is no patch
Two thirds of internet-exposed BMCs hand out IPMI password hashes before login. CVE-2013-4786 is a flaw in the specification itself, so no vendor update will ever close it.
11 min read - Arista VeloCloudCVE-2026-16812SD-WAN
VeloCloud CVE-2026-16812: One SD-WAN Orchestrator, Every Branch
CVE-2026-16812 is a CVSS 10.0 unauthenticated command injection in Arista VeloCloud Orchestrator, exploited as a zero-day. CISA gave it a three-day clock. Here is why, and what to do.
14 min read - FastjsonCVE-2026-16723Java Deserialization
Fastjson CVE-2026-16723: a Gadget-Free RCE With No Patch to Apply
CVE-2026-16723 is a gadget-free RCE in fastjson 1.2.68–1.2.83, exploited in the wild. Turning AutoType off does not help, and Alibaba has shipped no fixed 1.x release.
11 min read