Redis Streams and RedisBloom/TDigest security release bundle
Security Patch Release
Summary
Hide ▲
Show ▼
Redis shipped a July 23 security release bundle that fixes Streams and RedisBloom/TDigest memory flaws across supported branches, reducing authenticated remote code execution risk for deployed servers.
Related Happenings
Ivanti Sentry patch release for CVE-2026-10520 and CVE-2026-10523
Security Patch Release
H score54
First: 10.06.2026 09:26
Last: 10.06.2026 09:26
Sources 1
About this happening:
Ivanti released a patch bundle for Sentry after identifying two critical vulnerabilities in the secure mobile gateway appliance, including CVE-2026-10520 and *...
Ivanti Sentry patch release for CVE-2026-10520 and CVE-2026-10523
Security Patch ReleaseAbout this happening: Ivanti released a patch bundle for Sentry after identifying two critical vulnerabilities in the secure mobile gateway appliance, including CVE-2026-10520 and *...
Redis security patch release for CVE-2026-23479
Security Patch Release
H score24
First: 03.06.2026 16:47
Last: 03.06.2026 16:47
Sources 1
About this happening:
Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
Redis security patch release for CVE-2026-23479
Security Patch ReleaseAbout this happening: Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
Anthropic launches Project Glasswing with Claude Mythos for vulnerability discovery
Security Tool/Service
H score58
First: 08.04.2026 12:16
Last: 08.04.2026 12:16
Sources 1
About this happening:
Anthropic’s Project Glasswing is now showing measurable results: since launching last month, the Claude Mythos Preview-based initiative has uncovered more than 10,000...
Anthropic launches Project Glasswing with Claude Mythos for vulnerability discovery
Security Tool/ServiceAbout this happening: Anthropic’s Project Glasswing is now showing measurable results: since launching last month, the Claude Mythos Preview-based initiative has uncovered more than 10,000...
Latest development: 03.06.2026 14:00
President Donald Trump signed a June 2 executive order that sets up a voluntary framework for developers of covered frontier models to give the US government access for cybersecurity review for up to 30 days before release, while expressly rejecting any mandatory licensing or preclearance requirement. The order directs NSA, CISA, and NIST to build a classified benchmark for determining which models cross the covered threshold and creates an AI cybersecurity clearinghouse led by the Treasury Department. The framework closely echoes Anthropic's Project Glasswing, which gives vetted partners early access to Claude Mythos Preview to scan critical software for vulnerabilities.
Timeline
-
24.07.2026 09:58 2 articles · 12h ago
Redis ships seven security releases for Streams and RedisBloom/TDigest flaws
Mitigation Patch UpdateRedis shipped seven security releases on July 23, 2026, fixing a Streams shared-NACK use-after-free and RedisBloom/TDigest memory corruption across supported branches. The release set includes Redis 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1.
Show sources
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — thehackernews.com — 24.07.2026 09:58
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — thehackernews.com — 24.07.2026 09:58
-
24.07.2026 09:58 1 articles · 12h ago
Authenticated RCE chains target stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0
Technical Analysis UpdateAuthenticated proof-of-concept chains targeted stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0 by combining RESTORE with EVAL, XGROUP, and the bundled RedisBloom module to turn the Streams shared-NACK bug and RedisBloom TDigest loader flaw into system() execution. As of July 24, 2026, no in-the-wild exploitation had been reported.
Show sources
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — thehackernews.com — 24.07.2026 09:58