On-Prem Red Team AI — engineering notes from the front line
Deep dives, comparisons and field reports on autonomous red team AI, generative pentesting, deep-packet traffic intelligence, NIS2/DORA, and how to operate them air-gapped.
- Agentic Red TeamingAI Agent SecurityPreventive Security
Continuous Agentic Red Teaming: the Five Minutes of OpenAI's Black Hat Talk Nobody Quoted
OpenAI's agent-swarm talk ended with a prescription, not a story: continuous agentic red teaming, and closing the loop from finding to fix. The industry answered with detection instead.
10 min read - MetabaseSQL InjectionZero-Day
Metabase Zero-Day SQL Injection: When Your BI Tool Owns Every Database
An unauthenticated CVSS 10 SQL injection turned Metabase into a pivot into every connected production database. Framework and Tally lost customer data before anyone noticed.
10 min read - AI Agent SecurityJFrog ArtifactoryCVE-2026-66014
AI Agent Swarm vs Artifactory: the Eight Zero-Days Nobody Patched
An AI agent swarm found eight zero-days in JFrog Artifactory, escaped its sandbox and reached Hugging Face. Everyone covered the AI story. Almost nobody patched CVE-2026-66014.
10 min read - KVM EscapeCVE-2026-64561Linux Kernel
Zapscape CVE-2026-64561: a Second KVM Escape in Five Weeks
Zapscape is a use-after-free in the KVM shadow MMU that turns guest kernel access into host root. It is the third escape in that same subsystem since May — patching one CVE is not patching the class.
9 min read - N-able N-centralRMM SecurityMSP Supply Chain
N-able N-central CVE-2026-18577: One Auth Bypass, Every Managed Endpoint
An incomplete patch left N-able N-central exploitable again. CVE-2026-18577 hands attackers the RMM server, then pivots into every managed endpoint through Cloudflare tunnels.
8 min read - Supply Chain Attacknpm WormAI Tool Security
ChainDrop: the npm worm that steals your AI assistant's credentials
ChainDrop poisoned 400+ npm packages with 2B monthly downloads in under four hours on 4 August 2026 — and it's the first worm to harvest AI-assistant tokens and hide in Claude Code hooks.
7 min read - PasskeysWebAuthnPhishing-Resistant MFA
Pass-ta-key: your synced passkeys are only as strong as the endpoint
Unit 42 showed unprivileged malware can forge WebAuthn assertions and decrypt Google-synced passkeys. What that does to the phishing-resistant MFA box you already ticked.
13 min read - Adobe Campaign ClassicCVE-2026-48449Authorization Bypass
Adobe Campaign Classic CVE-2026-48449: the Same CVSS 10.0, a Third Time
Adobe shipped its third CVSS 10.0 authorization bypass in Campaign Classic in 50 days. The build that fixed you in June is the build that failed you in July — and Adobe is about to stop counting them separately.
16 min read - Ruby on RailsCVE-2026-66066Secret Rotation
KindaRails2Shell (CVE-2026-66066): the patch doesn't un-leak your secret_key_base
CVE-2026-66066 leaks Rails secrets through an image upload. Patching closes the loader — it does not rotate the keys, and the forensic evidence is on a deletion timer.
12 min read