On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- JFrog ArtifactoryCVE-2026-82329Supply Chain
JFrog Artifactory CVE-2026-82329: One Request Away From Admin on Your Build Pipeline
CVE-2026-82329 is a CVSS 9.8 authentication bypass in JFrog Artifactory. A phantom join key lets an unauthenticated attacker forge admin tokens — patched Aug 28, exploited Sep 1.
8 min read - LangflowCVE-2026-0768AI Stack Security
Langflow CVE-2026-0768: One Endpoint Turns Your AI Stack Into an Attacker's Python Shell
CVE-2026-0768 gives unauthenticated attackers root-level Python on exposed Langflow servers — and they are already harvesting OpenAI and AWS keys. Why the AI stack is the soft target.
9 min read - PaperCutCVE-2026-82078Zero-Day RCE
PaperCut CVE-2026-82078: a Pre-Auth RCE Turns the Print Server Into a Ransomware Doorway
Two chained flaws give unauthenticated attackers RCE on PaperCut NG/MF. Exploited as a zero-day since Aug 26, with the first patch already bypassed — the fix and the hunt.
7 min read - GiteaCVE-2026-60004CISA KEV
Gitea CVE-2026-60004: Self-Register, Push a Patch, Own the Git Server
Gitea CVE-2026-60004 is a CVSS 9.8 RCE in the diffpatch endpoint. Open registration turns a self-hosted Git server into a pre-auth shell. CISA KEV, exploited now.
8 min read - NIS2DORAEU AI Act
NIS2, DORA and the AI Act: One Control Set, Three Regulators, One Evidence Problem
The AI Act's transparency rules went live on August 2 while high-risk obligations slipped to December 2027. NIS2, DORA and the AI Act now demand the same evidence — three times over.
8 min read - miniOrange SAML SSOCVE-2026-15981SAML Authentication Bypass
miniOrange SAML SSO CVE-2026-15981: Anyone Can Be Your WordPress Admin
CVE-2026-15981 (CVSS 9.8) and CVE-2026-61979 let an unauthenticated attacker forge a SAML assertion and log into wp-admin as anyone. Already probed in the wild. Here is the fix runbook.
8 min read - Windows IKECVE-2026-33824Autonomous AI Attack
Windows IKE CVE-2026-33824: The AI Ran Recon, a Human Pulled the Trigger
CVE-2026-33824 is a wormable pre-auth RCE in the Windows IKE service, now on CISA KEV. It surfaced inside a DeepSeek-driven autonomous attack campaign. Here is the fix runbook and what the AI tempo really changed.
9 min read - AI-Powered C2npm Supply ChainRedC2
RedC2 4.0: the AI-Powered C2 Framework Hiding in Your npm Dependencies
Trend Micro found 14 trojanized npm packages dropping RedC2 4.0 — a $99 C2 framework whose Red Agent LLM turns plain English into beacon commands. Full remediation runbook.
7 min read - TrueConfCVE-2026-72529CISA KEV
TrueConf CVE-2026-72529: One Open Port, Every Employee Gets Malware
CVE-2026-72529 chains with CVE-2026-72530 to root a TrueConf Server through one default-open port, then swaps the client installer to push PhantomCore to every meeting participant.
7 min read