HomeArtificial Intelligence (AI)AI Agents Are Now Finding Zero-Day Exploits: Here's What Kimi K3 and...

AI Agents Are Now Finding Zero-Day Exploits: Here’s What Kimi K3 and XBOW Just Proved

Two separate disclosures this week showed AI agents autonomously discovering and weaponizing real software vulnerabilities at a pace that would have been difficult for human researchers to match. Together, they mark a visible shift in how security vulnerabilities are found — and who, or what, is finding them first.

Researcher Chaofan Shou said on X that agents built on Moonshot AI’s Kimi K3 model found 19 Redis zero-day vulnerabilities in roughly 90 minutes, and in a separate run produced a working remote-code-execution exploit for Redis 8.8.0 in 27 minutes.

Redis responded by shipping seven security releases on July 23 after researchers published proof-of-concept exploits affecting four different Redis versions, as The Hacker News reported. The claimed timings and degree of autonomy remain self-reported, though Redis’s own security releases confirm the underlying flaws.

Microsoft’s Bing had a parallel problem

Separately, autonomous offensive-security platform XBOW discovered that a specially crafted image file submitted to Bing’s image search could run commands as SYSTEM on Microsoft’s production servers — and as root on the Linux machines in the same server fleet.

XBOW reproduced the exploit across multiple hosts and network ranges, confirming the flaw sat in Bing’s image-processing tier rather than one misconfigured machine. Microsoft issued two critical CVEs in response, both rated 9.8 out of 10 in severity, and credited XBOW as the finder.

It’s XBOW’s second notable credit from Microsoft this year: the platform was already recognized in March for a critical remote-code-execution flaw in the Microsoft Devices Pricing Program, which put it in the top 10 of Microsoft’s bug bounty leaderboard.

Two more critical Bing RCEs in the same year suggest XBOW’s autonomous approach is finding a consistent, repeatable class of real vulnerabilities rather than a single lucky result.

Why this matters beyond the specific bugs

Both incidents point to the same underlying shift: AI agents built for offensive security research are now finding real, exploitable zero-days in widely deployed infrastructure software faster than traditional human-led research typically allows.

That’s valuable for defenders who can patch faster — but it’s the same capability a malicious actor could point at a target instead of a benchmark. Redis’s flaws required specific commands often left enabled in internal deployments, a reminder that configuration hygiene remains a meaningful defense even against AI-accelerated discovery.

What to watch next

  • Whether Redis and Microsoft’s patch timelines hold up against real-world exploitation attempts now that the technical details are public.
  • How quickly other core infrastructure projects get similar AI-driven security audits, given how much software shares the same open-source dependencies.
  • Whether security teams start budgeting for AI-agent-assisted red-teaming as a standard practice rather than a novelty.

Sources

Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.


Follow us on X, Facebook, Telegram, and  Google News

Solomon Odunayo
Solomon Odunayo
Solomon is a trader, crypto enthusiast, and analyst with over seven years of experience in the industry. He strongly believes that crypto assets and the blockchain will continue to gain prominence. At TimesTabloid.com, he focuses on news, articles with deep analysis of blockchain projects, and technical analysis of crypto trading pairs.
RELATED ARTICLES

Latest News & Articles