On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Qilin RansomwarePAN-OSRansomware
Qilin ransomware and CVE-2026-0257: the VPN bug is only the front door
Qilin affiliates chain the PAN-OS GlobalProtect bug CVE-2026-0257 into domain-wide encryption. The perimeter breach is silent; the kill chain that follows is loud on the wire.
9 min read - ServiceNowCVE-2026-6875Sandbox Escape
ServiceNow CVE-2026-6875: A Pre-Auth Sandbox Escape Into Your Whole Workflow Platform
ServiceNow CVE-2026-6875 is a CVSS 9.5 pre-auth sandbox escape now exploited in the wild — and the in-the-wild chain bypasses the PoC every defender tuned to.
9 min read - ACR StealerEtherHidingInfostealer
ACR Stealer and EtherHiding: the C2 you cannot take down
Microsoft found ACR Stealer resolving its C2 from a public blockchain. EtherHiding removes the seizable resolver that every takedown and blocklist depends on.
9 min read - WordPress RCEwp2shellPre-Auth RCE
wp2shell: Pre-Auth RCE in WordPress Core — and the Patch Trap
wp2shell (CVE-2026-63030 + CVE-2026-60137) is an unauthenticated RCE in WordPress Core's REST batch API. Why 'we're patched' isn't the same as 'we're safe' — and how to actually validate exposure.
9 min read - FortiSandboxActively ExploitedOS Command Injection
FortiSandbox CVE-2026-25089: Unauth RCE in the Box That Judges Your Malware
Two unauthenticated RCE flaws (CVE-2026-25089, CVE-2026-39808, CVSS 9.8) hand attackers Fortinet FortiSandbox — the appliance that issues malware verdicts to your whole fabric. CISA KEV, exploited in the wild.
8 min read - AD FS Zero-DayGolden SAMLIdentity
AD FS Zero-Day CVE-2026-56155: When 7.8 Buys a Golden SAML
CVE-2026-56155 is rated 7.8, local privilege escalation, Important. On an AD FS server that buys the token-signing key — and the patch does not take it back.
12 min read - SonicWall SMA1000SSRF ChainCISA KEV
SonicWall SMA1000 Zero-Days: CVE-2026-15409 Chains SSRF to Root
SonicWall SMA1000 is under active attack: unauth SSRF CVE-2026-15409 chains with CVE-2026-15410 to reach root — patch to 12.4.3-03453 / 12.5.0-02835, then hunt and rotate.
8 min read - Exploit ValidationExposure ManagementEvidence-Based Security
Exploit Validation: Evidence Beats Estimate, But Whose Cloud Runs the Proof?
In March 2026 Qualys shipped Agent Val, conceding that CVSS scores are guesses. Evidence-based vulnerability management is right — but whose cloud runs the proof?
7 min read - Microsoft DefenderPrivilege EscalationRoguePlanet
RoguePlanet: The Microsoft Defender Zero-Day That Hands Attackers SYSTEM
RoguePlanet (CVE-2026-50656) is a Microsoft Defender race condition that spawns a SYSTEM shell on fully patched Windows. Why the detector becoming the attack surface breaks host-based defence.
8 min read