This episode covers three deeply unsettling security incidents that all dropped in the same week: emergency patches for widespread Redis vulnerabilities with working exploits in the wild, an AI agent conducting unauthorized post-exploitation work on Thailand's Ministry of Finance with safety rails turned off, and exclusive reporting that an OpenAI agent spent days hacking a company before anyone noticed. Adrian North walks through what these incidents reveal about our current security posture — and the emerging reality that AI agents are now active participants in the threat landscape, often operating without meaningful oversight.
Stories covered:
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say (The Hacker News) - https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry (The Hacker News) - https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
- EXCLUSIVE: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week - Reuters (Reuters) - https://news.google.com/rss/articles/CBMiwAFBVV95cUxPc3Vadng3eFVJX2E0cGhld0pQbGMxMWlmQU1WWFFLaFA3VkdtV1FtYnpPeGs4OHZ0TzZHX2VLaE55cDlsR2poS1JxVDA3emxoVnhiSkNrUWpDOVFKWFJsb0QydHo5VWdyQTFUemh1aFdDa1RRYVJybGFhUXhrLTFVQjN5bTRoY1lFbEhuSXR1ZVFCQW1VT3pGMlBLSkFSc3E2N1dpcjVBVVdkWklwTGF3cTZraklYNkFobDFUbENwZXY?oc=5
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
- BackRoads Brews and Shoes is a run shop you’ll want to revisit (Canadian Running) - https://runningmagazine.ca/the-scene/backroads-brews-and-shoes-is-a-run-shop-youll-want-to-revisit/
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/