On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- AI RansomwareAgentic AILangflow
JADEPUFFER: Agentic Ransomware That Ran the Whole Attack Itself
JADEPUFFER is the first documented agentic ransomware — an AI agent ran recon, pivot, and encryption end-to-end, fixing a failed login in 31 seconds. Here is the runbook.
8 min read - CitrixBleedNetScalerSession Hijacking
CitrixBleed Again: CVE-2026-8451 and the Token You Already Lost
CVE-2026-8451 is a pre-auth NetScaler memory overread exploited within 24 hours. Patching stops the leak — it does not evict the session tokens attackers already stole.
8 min read - Avalon MalwareCrownX RansomwareEDR Evasion
Avalon and CrownX: the ransomware built to blind every EDR you own
Blackpoint Cyber found Avalon, an AI-assisted modular framework that hides from nine EDR products, then wipes recovery and runs CrownX ransomware. Why the wire still sees what the endpoint can't.
8 min read - Linux KernelPrivilege EscalationBad Epoll
Bad Epoll (CVE-2026-46242): a 6-instruction race that hands any Linux user root
Bad Epoll (CVE-2026-46242) is a Linux kernel use-after-free that gives any unprivileged user root — on servers and Android. A patch existed since April but stayed silent for 70 days. Here is the fix runbook.
7 min read - ColdFusionCVE-2026-48282Data Exfiltration
ColdFusion CVE-2026-48282: Exploited Within Hours of the Patch
Adobe shipped six CVSS 10.0 ColdFusion flaws on July 1. Within hours CVE-2026-48282 was under attack — and the file-read window before you patch is exactly what most defenders never see.
10 min read - SharePointCISA KEVRemote Code Execution
SharePoint CVE-2026-45659: Patched in May, Exploited in July
CVE-2026-45659 is an authenticated RCE in on-prem SharePoint — silently fixed in May 2026, left off the bulletin, and now actively exploited and on the CISA KEV list.
9 min read - Prompt InjectionAI IDE SecurityRemote Code Execution
Cursor DuneSlide (CVE-2026-50548/50549): Prompt Injection Is Now Remote Code Execution
DuneSlide turns two Cursor IDE sandbox flaws into zero-click RCE via prompt injection — a poisoned web result or MCP server takes over a developer's machine. What it means and how to fix it.
8 min read - Oracle E-Business SuiteCVE-2026-46817Data Exfiltration
Oracle E-Business Suite CVE-2026-46817: The Unauthenticated File Read Into Payments
CVE-2026-46817 is a CVSS 9.8 missing-authentication flaw in Oracle E-Business Suite Payments, exploited in the wild six weeks after the patch and before any public PoC — a silent data-read door.
7 min read - SimpleHelpCVE-2026-48558RMM Security
SimpleHelp CVE-2026-48558: a CVSS 10 RMM Bypass That Steals Your Cloud and AI Keys
CVE-2026-48558 is a CVSS 10.0 auth bypass in SimpleHelp RMM, exploited to plant rogue technician accounts and deploy the Djinn stealer that harvests cloud, SSH and AI credentials.
10 min read