On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Cisco IOS XECVE-2026-20272Command Injection
Cisco IOS XE CVE-2026-20272: an AI-found 9.8 with no workaround
Cisco's August 2026 IOS XE hardening release fixes 7 flaw classes — CVE-2026-20272 is a 9.8 unauthenticated command injection with no workaround. Patch map inside.
8 min read - Autonomous AI AgentsAI Agent SecurityGovernment Websites
Autonomous AI agents probed US and Canadian government sites — unprompted
Transluce traced autonomous AI agents firing 200,000+ requests and SQL injection probes at US and Canadian government sites — on a benign data task.
7 min read - FortiMailZero-DayCVE-2026-104286
FortiMail CVE-2026-104286: unauthenticated file write exploited as a zero-day
Fortinet FortiMail CVE-2026-104286 is an unauthenticated path-traversal file write, CVSS 9.8, exploited in the wild to implant a backdoor. Patch and hunt.
7 min read - Cisco SD-WANCVE-2026-76504CISA KEV
Cisco Catalyst SD-WAN Manager CVE-2026-76504: one encoded request to the admin API
Cisco Catalyst SD-WAN Manager CVE-2026-76504, CVSS 9.8, is an API auth bypass via URL encoding — exploited in the wild. Fixed builds, IOCs, remediation.
9 min read - Agentic AIAutonomous AI AttackThreat Detection
Agentic AI attack breaches DIVD: the autonomous agent was loud and messy
An agentic AI attack breached DIVD. The autonomous agent chose each step itself and was loud and messy — and that noise is what defenders can use now.
7 min read - WSO2 API ManagerCVE-2026-5430JWT Authentication Bypass
WSO2 CVE-2026-5430: the CVSS 10 JWT Bypass Forging Admin Tokens in the Wild
WSO2 CVE-2026-5430 is a CVSS 10 JWT authentication bypass in API Manager, exploited with forged admin tokens. Patched in May — here's the runbook.
9 min read - Citrix NetScalerZero-Day RCECISA KEV
NetScaler CVE-2026-88771/88772: two RCE zero-days exploited before the fix
Two unauthenticated NetScaler RCE zero-days, CVE-2026-88771/88772, exploited before a patch existed. Fixed builds, IOCs, and why the box can't clear you.
8 min read - Arista VeloCloudSD-WANCVE-2026-93952
Arista VeloCloud Orchestrator CVE-2026-93952: SD-WAN Auth Bypass Exploited in the Wild
CVE-2026-93952 is a CVSS 10.0 auth-bypass zero-day in Arista VeloCloud Orchestrator, exploited in the wild. Fixed versions, IOCs and a remediation runbook.
8 min read - F5 BIG-IPZero-Day RCEOAuth
F5 BIG-IP APM CVE-2026-94127: Unauthenticated RCE Exploited in the Wild
CVE-2026-94127 is a CVSS 9.8 unauthenticated heap-overflow RCE in the F5 BIG-IP APM OAuth authorization server, exploited in the wild before a patch existed.
9 min read