<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Redis on CuraSec</title><link>https://curasec.metacog.co.kr/tags/redis/</link><description>Recent content in Redis on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 11:54:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/redis/index.xml" rel="self" type="application/rss+xml"/><item><title>TeamPCP Threat Actor Linked to Redis Attacks and Supply Chain Campaign</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-teampcp-linked-to-redis-attacks-dating-back-to-2020-and-late/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-teampcp-linked-to-redis-attacks-dating-back-to-2020-and-late/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The supply chain angle is worth understanding for build pipeline threat modeling, but no specific packages, IOCs, or patching actions are identified in the summary — audit CI/CD pipelines and artifact registries for signs of TeamPCP TTPs once full reporting surfaces.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for Redis-targeting behaviors and review historical logs back to 2020 for overlapping infrastructure indicators; watch for the full IOC list from this report to enable a retroactive hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A supply chain threat actor with multi-year persistence is worth tracking for risk register context, but no specific vendor compromise or board-level event is identified here yet.&lt;/li>
&lt;/ul></description></item><item><title>Redis Patches Seven RCE Flaws After AI Agent Finds Zero-Days with Public PoC</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-r/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public authenticated-RCE PoCs exist for Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0; upgrade to Redis 6.2.23, 7.2.15, or 7.4.10 immediately, and audit whether RESTORE, EVAL, or XGROUP are accessible to untrusted clients in your environment.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No confirmed in-the-wild exploitation yet, but public PoCs accelerate that timeline; build detections for anomalous Redis command sequences involving RESTORE combined with EVAL or XGROUP, and baseline normal Redis command usage now so deviations surface quickly.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Redis is pervasive in enterprise stacks; confirm all internal deployments and any SaaS vendors running Redis are targeting the patched versions (6.2.23/7.2.15/7.4.10), and track remediation completion — the authenticated-only attack surface limits immediate board escalation but warrants this-quarter tracking.&lt;/li>
&lt;/ul></description></item></channel></rss>