Threat Brief — 2026-07-24 — AI finds bugs, bridges burn
AI agents are now discovering real, exploitable vulnerabilities at speed — Kimi K3 autonomously found Redis zero-days and built working RCE chains, while Aikido's AI pentest agents surfaced eight high-severity flaws in NodeBB in six hours. Meanwhile, Clop ransomware pivots to enterprise PLM platforms and two cross-chain bridges lost $31.6M in a single day. Western intelligence has formally corroborated the ongoing Russian APT Zimbra campaign with new attribution detail.
Top items
- Redis authenticated RCE zero-days found and exploited by AI agent. Kimi K3 AI agents independently discovered zero-day vulnerabilities in stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0, then built working authenticated RCE PoCs. Redis shipped seven security releases on July 23. All four exploit chains require the RESTORE command; the Streams chains also need EVAL and XGROUP. Any deployment exposing Redis with authenticated access on an attacker-reachable network should patch immediately. (src: thehackernews)
- Oracle patches critical vulnerability alongside 1,448 other issues. Oracle's latest CPU addressed one critical flaw plus 1,449 total problems across its product portfolio. organisations running Oracle middleware, database, or applications should review the patch advisory and prioritise the critical item. (src: securitylab-ru)
- NodeBB patches eight AI-discovered flaws exposing admin access and private chats. Aikido Security's AI pentest agents found eight high-severity vulnerabilities in the NodeBB forum software during a six-hour source-code review. Public PoC code was released alongside the disclosure. Forum admins should upgrade immediately and audit for evidence of prior exploitation. (src: thehackernews)
- Clop ransomware targets PTC Windchill and FlexPLM in data-theft extortion. The Clop gang is actively scanning Internet-exposed Windchill and FlexPLM instances for data theft and extortion, mirroring their earlier MOVEit and Cleo campaign playbook. Organisations running these PLM platforms should verify exposure and enable available mitigations. (src: bleepingcomputer-main)
- Two cross-chain bridges lose $31.6M in same-day attacks. Unknown attackers stole over $31.6 million by exploiting the AFX DEX bridge and the Verus protocol bridge within hours of each other, underscoring continued fragility of cross-chain infrastructure. (src: xakep)
- Western intelligence agencies formally warn of Russian-speaking APT targeting Zimbra. Western government agencies have corroborated the ongoing Zimbra zero-click campaign, warning that malicious JavaScript executes on message view and exfiltrates 90 days of mailbox data. This follows the initial disclosure by Unit42 on 2026-07-23. (Developing — first reported 2026-07-23 by Unit42; new development: securitylab-ru)
- Fake Notepad++ plugin delivers MATCHBOIL.V2 in UAC-0099 campaign. CERT-UA attributes a new campaign using a trojanised Notepad++ plugin to the UAC-0099 threat group, delivering the MATCHBOIL.V2 payload against Ukrainian targets. This is a distinct campaign from the LunchPoke plugin activity reported on 2026-07-23, using the same infection vector but a different payload and actor attribution. (Developing — first reported 2026-07-23 by bleepingcomputer-main; new development: thehackernews)
- Claude jailbreak commercialised as attack-as-a-service. Cybercriminal communities are now testing and distributing a method to bypass Claude's safety guardrails, offering it as a commercial service for generating attack content. This demonstrates AI jailbreaks transitioning from research curiosities to monetised offensive tooling. (src: securitylab-ru)
- seunshare CVEs allow local file deletion and process kill. CVE-2026-59676 enables local file deletion via rm_rf() in seunshare, and CVE-2026-59677 allows process kill via killall(). Both are local privilege-abuse vectors on affected systems. (src: msrc-security-updates · msrc-security-updates)
- Rental car hijacking via internet-exposed vulnerability. A security flaw in rental car telematics systems allowed remote attackers to lock doors and kill engines of rented vehicles, exposing drivers to unauthorised commands from the Internet. (src: securitylab-ru)
Themes
AI as both sword and shield. Today's brief shows AI agents autonomously discovering real vulnerabilities (Redis RCE chains by Kimi K3, NodeBB flaws by Aikido's agents) while simultaneously being weaponised (Claude jailbreaks sold as a service, AI multilingual guardrail gaps exploited). The asymmetry is narrowing — offensive and defensive AI capabilities are advancing in lockstep, and defenders should treat AI-discovered bugs as production-grade threats with realistic exploit timelines.
Cross-chain bridge attrition continues. The same-day compromise of the AFX and Verus bridges for $31.6M reinforces that cross-chain infrastructure remains a top-tier target. Organisations with DeFi exposure should audit bridge contracts and monitor for rapid exploit replication across protocols.
