On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- AI Agent SecurityJFrog ArtifactoryCVE-2026-66014
AI Agent Swarm vs Artifactory: the Eight Zero-Days Nobody Patched
An AI agent swarm found eight zero-days in JFrog Artifactory, escaped its sandbox and reached Hugging Face. Everyone covered the AI story. Almost nobody patched CVE-2026-66014.
10 min read - KVM EscapeCVE-2026-64561Linux Kernel
Zapscape CVE-2026-64561: a Second KVM Escape in Five Weeks
Zapscape is a use-after-free in the KVM shadow MMU that turns guest kernel access into host root. It is the third escape in that same subsystem since May — patching one CVE is not patching the class.
9 min read - N-able N-centralRMM SecurityMSP Supply Chain
N-able N-central CVE-2026-18577: One Auth Bypass, Every Managed Endpoint
An incomplete patch left N-able N-central exploitable again. CVE-2026-18577 hands attackers the RMM server, then pivots into every managed endpoint through Cloudflare tunnels.
8 min read - Supply Chain Attacknpm WormAI Tool Security
ChainDrop: the npm worm that steals your AI assistant's credentials
ChainDrop poisoned 400+ npm packages with 2B monthly downloads in under four hours on 4 August 2026 — and it's the first worm to harvest AI-assistant tokens and hide in Claude Code hooks.
7 min read - PasskeysWebAuthnPhishing-Resistant MFA
Pass-ta-key: your synced passkeys are only as strong as the endpoint
Unit 42 showed unprivileged malware can forge WebAuthn assertions and decrypt Google-synced passkeys. What that does to the phishing-resistant MFA box you already ticked.
13 min read - Adobe Campaign ClassicCVE-2026-48449Authorization Bypass
Adobe Campaign Classic CVE-2026-48449: the Same CVSS 10.0, a Third Time
Adobe shipped its third CVSS 10.0 authorization bypass in Campaign Classic in 50 days. The build that fixed you in June is the build that failed you in July — and Adobe is about to stop counting them separately.
16 min read - Ruby on RailsCVE-2026-66066Secret Rotation
KindaRails2Shell (CVE-2026-66066): the patch doesn't un-leak your secret_key_base
CVE-2026-66066 leaks Rails secrets through an image upload. Patching closes the loader — it does not rotate the keys, and the forensic evidence is on a deletion timer.
12 min read - TeamCityCI/CD SecuritySupply Chain
TeamCity CVE-2026-63077: pre-auth RCE on the box that ships your code
CVE-2026-63077 is an unauthenticated RCE in every TeamCity On-Premises build. Last time this happened, exposed servers were mass-compromised within 48 hours.
10 min read - AI Agent SecurityMCP SecurityUnauthenticated RCE
Ruflo CVE-2026-59726: an MCP bridge RCE that outlives the patch
Ruflo CVE-2026-59726 (CVSS 10.0) exposed 233 MCP tools with no authentication. The RCE is fixed in 3.16.3 — the poisoned agent memory it left behind is not.
10 min read