On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Linux Kernel LPEContainer EscapePrivilege Escalation
pedit COW and DirtyClone: Two Linux Page-Cache LPEs and Why 'Local' Means Root in 2026
Two Linux page-cache kernel bugs — pedit COW (CVE-2026-46331) and DirtyClone (CVE-2026-43503) — turn a container foothold into root. Why local privilege escalation is the 2026 breakout.
9 min read - PTC WindchillCVE-2026-12569Manufacturing Security
PTC Windchill CVE-2026-12569: A Web Shell on Your Engineering Crown Jewels
PTC Windchill CVE-2026-12569 is a CVSS 9.8 unauthenticated RCE now in CISA's KEV. Attackers are dropping JSP web shells on the PLM systems that hold manufacturing's CAD, BOMs and intellectual property.
9 min read - Cisco Unified CMCVE-2026-20230VoIP Security
Cisco Unified CM CVE-2026-20230: Root on the Phone System Nobody Watches
Cisco patched Unified CM's SSRF flaw CVE-2026-20230 on June 3. Attackers had file-write payloads landing by June 22 and CISA added it to KEV on June 25. The catch: you can't run EDR on the appliance.
6 min read - Ubiquiti UniFiCISA KEVZero-Day
Ubiquiti UniFi CVE-2026-34908: Patching Won't Evict the Intruder
CVE-2026-34908 is a CVSS 10.0 Ubiquiti UniFi auth bypass exploited to plant rogue admin accounts. Patching by the CISA deadline closes the door — not the intruder already inside.
7 min read - Supply Chain AttackWordPressC2 Detection
WordPress supply-chain backdoor: the ShapedPlugin update-channel attack
A backdoor reached 3 ShapedPlugin Pro plugins through the official licensed update channel, stole admin and 2FA secrets, and self-deleted its loader. Why patch dashboards stayed green.
7 min read - Microsoft 365 CopilotPrompt InjectionZero-Click Exfiltration
SearchLeak: the one-click Copilot prompt injection that exfiltrates your mailbox
Varonis' SearchLeak (CVE-2026-42824) turned Microsoft 365 Copilot into a one-click data-theft tool. A year after EchoLeak, the same prompt-injection exfiltration pattern is back — here's why it keeps working.
8 min read - Prinz Eugen RansomwareTraffic AnalysisRansomware Detection
Prinz Eugen Ransomware Leaves No Note — and Encrypts Your Newest Files First
Prinz Eugen ransomware drops no ransom note, zeroes its own key, and encrypts your most recently used files first. Why host-side forensics miss it and wire-speed traffic ML doesn't.
8 min read - Red Team AISovereign AIOn-Premise
Mythos and the Restricted-AI Era: The Case for Sovereign, On-Premise Red-Team AI
Anthropic's Mythos — the most capable offensive AI yet built — was withheld from the public and then blocked by the US government. It proves two things every CISO needs to absorb: frontier offensive AI is now a controlled good, and red-team security is far bigger than source-code assessment. Here's the honest comparison with ZeroHunt Apex Pro on assessment and on-premise defense.
5 min read - NGINXCVE-2026-42530HTTP/3
NGINX CVE-2026-42530: Unauthenticated RCE in the Reverse Proxy in Front of Everything
F5's out-of-band patch fixes two CVSS 9.2 unauthenticated NGINX flaws — CVE-2026-42530 (HTTP/3) and CVE-2026-42055 (HTTP/2 upstream). Why an RCE in your reverse proxy is the worst kind.
7 min read