On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Cisco FMCCVE-2026-20316CISA KEV
Cisco FMC CVE-2026-20316: the CVSS 5.3 that CISA put in KEV
Cisco FMC CVE-2026-20316 is a static credential scored 5.3 and exploited as a zero-day. CVSS scores one bug at a time; attackers buy the whole chain.
10 min read - BMC SecurityIPMICVE-2013-4786
24,650 exposed BMCs leak IPMI password hashes — and there is no patch
Two thirds of internet-exposed BMCs hand out IPMI password hashes before login. CVE-2013-4786 is a flaw in the specification itself, so no vendor update will ever close it.
11 min read - Arista VeloCloudCVE-2026-16812SD-WAN
VeloCloud CVE-2026-16812: One SD-WAN Orchestrator, Every Branch
CVE-2026-16812 is a CVSS 10.0 unauthenticated command injection in Arista VeloCloud Orchestrator, exploited as a zero-day. CISA gave it a three-day clock. Here is why, and what to do.
14 min read - FastjsonCVE-2026-16723Java Deserialization
Fastjson CVE-2026-16723: a Gadget-Free RCE With No Patch to Apply
CVE-2026-16723 is a gadget-free RCE in fastjson 1.2.68–1.2.83, exploited in the wild. Turning AutoType off does not help, and Alibaba has shipped no fixed 1.x release.
11 min read - Browser-Assembled MalwareMalvertisingAI Traffic Analysis
Browser-Assembled Malware: SourTrade Breaks Hash Detection
Confiant's SourTrade campaign ships malware in pieces and lets the browser build the executable in memory. Browser-assembled malware gives every victim a unique hash.
10 min read - Linux KernelPrivilege EscalationAI Vulnerability Research
RefluXFS (CVE-2026-64600): an AI Found the Linux Kernel Root Bug Nine Years of Humans Missed
RefluXFS (CVE-2026-64600) is an XFS reflink race that hands local users root on ~16.4M RHEL systems, below SELinux and KASLR — and Claude found it, not a human.
9 min read - Check PointSmartConsoleAuthentication Bypass
Check Point SmartConsole CVE-2026-16232: One Token to Rewrite Every Firewall Rule
CVE-2026-16232 is a CVSS 9.3 authentication bypass in Check Point SmartConsole — an unauthenticated attacker takes an admin login token and rewrites your firewall policy. Exploited in the wild, KEV-listed.
9 min read - SharePointCVE-2026-50522CISA KEV
SharePoint CVE-2026-50522: the machine keys outlive the patch
CVE-2026-50522 is the fourth SharePoint flaw added to CISA KEV in 22 days. Attackers pull the ASP.NET machine keys in one request — and keep code execution after you patch.
12 min read - Qilin RansomwarePAN-OSRansomware
Qilin ransomware and CVE-2026-0257: the VPN bug is only the front door
Qilin affiliates chain the PAN-OS GlobalProtect bug CVE-2026-0257 into domain-wide encryption. The perimeter breach is silent; the kill chain that follows is loud on the wire.
9 min read