On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Windows DNS ServerCVE-2026-62878Wormable RCE
Windows DNS Server CVE-2026-62878: a Wormable Pre-Auth RCE on Every Domain Controller
CVE-2026-62878 is a wormable, unauthenticated RCE in Windows DNS Server — CVSS 9.8, sitting on every domain controller. Why 'exploitation less likely' is the window, not the all-clear.
9 min read - VMware vCenterCVE-2026-59310RCE
VMware vCenter CVE-2026-59310: Patched July 29, Breached August 3
CVE-2026-59310 is an unauthenticated CVSS 9.8 directory traversal in the vCenter Syslog service. Exploited five days after the patch to plant reverse_ssh. Here's the fix runbook.
8 min read - Progress LoadMasterCVE-2026-8037Command Injection
Progress LoadMaster CVE-2026-8037: A Pre-Auth RCE in the Load Balancer
CVE-2026-8037 is an unauthenticated command injection in Progress Kemp LoadMaster — patched in June, on CISA KEV by August 7 after 792 exploit attempts. What the escape_quotes() bug does and how to remediate it.
8 min read - LangflowUnauthenticated RCECISA KEV
Langflow CVE-2026-9198: Unauthenticated RCE in Your AI Agent Control Plane
CVE-2026-9198 gives unauthenticated attackers full RCE on default Langflow. Exploitation started 11 days before the patch and is still live. Here is the fix runbook.
8 min read - Agentic Red TeamingAI Agent SecurityPreventive Security
Continuous Agentic Red Teaming: the Five Minutes of OpenAI's Black Hat Talk Nobody Quoted
OpenAI's agent-swarm talk ended with a prescription, not a story: continuous agentic red teaming, and closing the loop from finding to fix. The industry answered with detection instead.
10 min read - MetabaseSQL InjectionZero-Day
Metabase Zero-Day SQL Injection: When Your BI Tool Owns Every Database
An unauthenticated CVSS 10 SQL injection turned Metabase into a pivot into every connected production database. Framework and Tally lost customer data before anyone noticed.
10 min read - AI Agent SecurityJFrog ArtifactoryCVE-2026-66014
AI Agent Swarm vs Artifactory: the Eight Zero-Days Nobody Patched
An AI agent swarm found eight zero-days in JFrog Artifactory, escaped its sandbox and reached Hugging Face. Everyone covered the AI story. Almost nobody patched CVE-2026-66014.
10 min read - KVM EscapeCVE-2026-64561Linux Kernel
Zapscape CVE-2026-64561: a Second KVM Escape in Five Weeks
Zapscape is a use-after-free in the KVM shadow MMU that turns guest kernel access into host root. It is the third escape in that same subsystem since May — patching one CVE is not patching the class.
9 min read - N-able N-centralRMM SecurityMSP Supply Chain
N-able N-central CVE-2026-18577: One Auth Bypass, Every Managed Endpoint
An incomplete patch left N-able N-central exploitable again. CVE-2026-18577 hands attackers the RMM server, then pivots into every managed endpoint through Cloudflare tunnels.
8 min read