Top AI Product

Every day, hundreds of new AI tools launch across Product Hunt, Hacker News, and GitHub. We dig through the noise so you don't have to — surfacing only the ones worth your attention with honest, no-fluff reviews. Explore our latest picks, deep dives, and curated collections to find your next favorite AI tool.


Kimi K3 agents found 19 Redis zero-days in 90 minutes — and built a working RCE

Researcher Chaofan Shou says he pointed an agent swarm powered by Moonshot’s Kimi K3 at Redis and walked away with 19 zero-days in about 90 minutes. A second run took 27 minutes to produce a working remote code execution exploit against Redis 8.8.0. No product to buy here — this is a security demo, and it’s the reason the AI crowd is losing it.

What the agents actually did

Kimi K3 orchestrated 32 specialized agents: clone the source, generate fuzzers, instrument the build, debug crashes in GDB, then chain the crash into an exploit. The headline bugs are a Stream NACK double-free (hits 6.2.22, 7.4.9, 8.6.4) that hands an authenticated client stable code execution, and a TDigest heap overflow shipping by default in 8.8.0 — a fresh instance is enough to pop. Both ride EVAL, RESTORE and XGROUP, commands that sit open on internal networks.

Why it matters

Autonomous bug-hunting keeps getting cheaper. An open-weights model going crash-to-RCE in under half an hour is a different threat model than last year’s fuzzers.

One caveat worth keeping: the counts, timings and how independently the agents worked are all self-reported. Redis’s July 23 fixes confirm the flaws exist; they don’t confirm the stopwatch.


You Might Also Like


Discover more from Top AI Product

Subscribe to get the latest posts sent to your email.



Leave a comment