Kimi K3 Reportedly Uses 32 Agents to Exploit Redis 0day

Recent social media discussions highlight Kimi K3's breakthrough performance in automated vulnerability discovery. Reports claim the model used 32 agents to find and exploit a 0day in the latest Redis server within a remarkably short time, signaling a major leap in AI-driven cybersecurity capabilities.

Confirmed

Based on various second-hand accounts, the testing details primarily fall into two versions:

Unconfirmed

As these reports are primarily retweets and second-hand accounts, several details conflict. The time taken is reported as both 27 minutes and 1.5 hours; the target software version varies between Redis 8.6.x and Redis 8.8.0; and the number of discovered vulnerabilities differs between 1 and 19. Additionally, @inductionheads mentioned that an open-source version of the model would be released "in a few days," which remains a rumor.

Why it matters

Regardless of the exact numbers, observers like @HanchungLee and @inductionheads agree this marks a qualitative shift in practical AI cybersecurity capabilities. @HanchungLee called it a "Prometheus moment," emphasizing the leap in agent collaboration rather than the vulnerability itself, as a group of agents autonomously completed the full attack chain from discovery to exploitation. Meanwhile, @inductionheads contrasted this with US commercial models still running cybersecurity classifiers, suggesting the open-source community might soon gain access to models with genuinely destructive attack capabilities.

2026-07-23 ~ 2026-07-24 · 5 related posts

Primary sources

1 near-duplicate retellings: teortaxesTex