Dev & Code 3 h agoAdd to bookmarks

Moonshot AI publishes the weights of Kimi K3 on Hugging Face, a few days after the preliminary evaluation of the model's cyber capabilities by the British and American institutes AISI/CAISI. A milestone for the "AI agents and threats" thread.
On July 27, the page moonshotai/Kimi-K3 appeared on Hugging Face - the public repo of a model that previously only existed as an API and evaluation documents. It is the logical continuation of Moonshot AI's strategy: after K1 and K2, the Chinese company continues to publish open weights for its large models at a pace reminiscent of Mistral or DeepSeek.
This publication comes shortly after the preliminary joint evaluation by the AISI (UK) and CAISI (US) institutes on the cyber capabilities of Kimi K3, published on the NIST website. This document analyzes the model's behavior on offensive scenarios - reconnaissance, exploit development, simulated lateral movement. On the scale of the thread we are following (autonomous AI agents as an attack vector), this is a milestone: it is the first time that the two national institutes have published a coordinated evaluation of a Chinese model before its availability in open weights.
The evaluation notably highlighted, in the test scenarios, a PoC of RCE on Redis generated end-to-end by the model - without classifying it as a dangerous uplift for a non-state actor, but with a warning signal.
The publication of the Kimi K3 weights moves the model from "API product evaluated remotely" to "auditable and redeployable artifact". This is excellent for security research - and it raises an operational question: will defenders have time to integrate the AISI/CAISI lessons into their playbooks before attackers have already put Kimi K3 into production in their agent chains?
moonshotai/Kimi-K3).agents-ia-menace.Article produced by artificial intelligence, reviewed under human editorial control.
Agents IA autonomes : nouveau vecteur d'attaque à l'échelle du swarm