On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- GDPRArticle 32Compliance
GDPR Article 32: The Fine for the Security Test You Didn't Run
Sweden fined Miljödata under GDPR Article 32 for skipping software testing and real-time monitoring — not for the breach. Why 'appropriate measures' now bites.
6 min read - Zyxel GS1900CVE-2026-7273Actively Exploited
Zyxel GS1900 CVE-2026-7273: Unauthenticated RCE, Now Exploited in the Wild
Zyxel GS1900 switch flaw CVE-2026-7273 lets a LAN-adjacent, unauthenticated attacker run OS commands with one HTTP request. Patched in June, added to CISA KEV in September.
10 min read - Linux KernelPrivilege EscalationCVE-2026-53266
Linux Kernel Privilege Escalation: 3 KEV Flaws, 4 Public Root Exploits, One Week
Linux kernel privilege escalation is spiking: three flaws are in CISA's KEV with a federal deadline today, and four public root exploits just dropped. How to fix it.
8 min read - Cisco ISECVE-2026-76460Authentication Bypass
Cisco ISE CVE-2026-76460: Auth Bypass to Root on the Identity Authority
Cisco ISE CVE-2026-76460 (CVSS 10.0) is an unauthenticated API auth bypass to root, exploited in the wild. Why the identity authority's own logs can't be trusted.
8 min read - Check PointCVE-2026-91843Firewall Security
Check Point CVE-2026-91843: Pre-Auth Root on the Firewall Management Server
CVE-2026-91843 is a CVSS 9.8 pre-auth stack overflow that gives root on Check Point's Security Management Server. The real question is whether it's reachable from where an attacker lands.
8 min read - Acronis BackupCVE-2026-87886Ransomware Recovery
Acronis Backup Plugin CVE-2026-87886: One Tenant, Root on the Whole cPanel Host
CVE-2026-87886 is an actively exploited privilege escalation in the Acronis Backup plugin for cPanel/WHM: a low-priv tenant reaches root via the recovery tool.
8 min read - AI Exploit FoundryZero-DaySecurity Appliances
AI Exploit Foundries: a Zero-Day Assembly Line Aimed at Your Appliances
AI exploit foundries now run scheduled, unattended zero-day research against security appliances — Anthropic's Sept 2026 report found 12+ per month. The defense.
8 min read - Cisco Secure Email GatewayCVE-2026-76461Email Security
Cisco Secure Email Gateway CVE-2026-76461: an inbound email gets root
A crafted email injects SQL into Cisco AsyncOS mail parsing and lands root — no login, no click. CVSS 9.8, KEV, federal deadline 17 Sept. Patch, then hunt the wire.
9 min read - GitLabCVE-2026-85706CI/CD Security
GitLab CVE-2026-85706: Unauthenticated File Read Empties Your CI/CD Secrets
A CVSS 10 path-traversal in GitLab's commits API lets anyone read secrets.yml, deploy tokens and CI/CD variables — no login, no auth log. Patch, then rotate.
8 min read