On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Browser-Assembled MalwareMalvertisingAI Traffic Analysis
Browser-Assembled Malware: SourTrade Breaks Hash Detection
Confiant's SourTrade campaign ships malware in pieces and lets the browser build the executable in memory. Browser-assembled malware gives every victim a unique hash.
10 min read - Linux KernelPrivilege EscalationAI Vulnerability Research
RefluXFS (CVE-2026-64600): an AI Found the Linux Kernel Root Bug Nine Years of Humans Missed
RefluXFS (CVE-2026-64600) is an XFS reflink race that hands local users root on ~16.4M RHEL systems, below SELinux and KASLR — and Claude found it, not a human.
9 min read - Check PointSmartConsoleAuthentication Bypass
Check Point SmartConsole CVE-2026-16232: One Token to Rewrite Every Firewall Rule
CVE-2026-16232 is a CVSS 9.3 authentication bypass in Check Point SmartConsole — an unauthenticated attacker takes an admin login token and rewrites your firewall policy. Exploited in the wild, KEV-listed.
9 min read - SharePointCVE-2026-50522CISA KEV
SharePoint CVE-2026-50522: the machine keys outlive the patch
CVE-2026-50522 is the fourth SharePoint flaw added to CISA KEV in 22 days. Attackers pull the ASP.NET machine keys in one request — and keep code execution after you patch.
12 min read - Qilin RansomwarePAN-OSRansomware
Qilin ransomware and CVE-2026-0257: the VPN bug is only the front door
Qilin affiliates chain the PAN-OS GlobalProtect bug CVE-2026-0257 into domain-wide encryption. The perimeter breach is silent; the kill chain that follows is loud on the wire.
9 min read - ServiceNowCVE-2026-6875Sandbox Escape
ServiceNow CVE-2026-6875: A Pre-Auth Sandbox Escape Into Your Whole Workflow Platform
ServiceNow CVE-2026-6875 is a CVSS 9.5 pre-auth sandbox escape now exploited in the wild — and the in-the-wild chain bypasses the PoC every defender tuned to.
9 min read - ACR StealerEtherHidingInfostealer
ACR Stealer and EtherHiding: the C2 you cannot take down
Microsoft found ACR Stealer resolving its C2 from a public blockchain. EtherHiding removes the seizable resolver that every takedown and blocklist depends on.
9 min read - WordPress RCEwp2shellPre-Auth RCE
wp2shell: Pre-Auth RCE in WordPress Core — and the Patch Trap
wp2shell (CVE-2026-63030 + CVE-2026-60137) is an unauthenticated RCE in WordPress Core's REST batch API. Why 'we're patched' isn't the same as 'we're safe' — and how to actually validate exposure.
9 min read - FortiSandboxActively ExploitedOS Command Injection
FortiSandbox CVE-2026-25089: Unauth RCE in the Box That Judges Your Malware
Two unauthenticated RCE flaws (CVE-2026-25089, CVE-2026-39808, CVSS 9.8) hand attackers Fortinet FortiSandbox — the appliance that issues malware verdicts to your whole fabric. CISA KEV, exploited in the wild.
8 min read