Kimi K3 lands on Hugging Face: the open weights of the Chinese model arrive after the cyber AISI/CAISI evaluation

In this saga : Un fichier .git piégé peut faire exécuter du code par Claude Code, Codex et Cursor· Episode 11/23

Dev & Code Jul 27, 2026Add to bookmarks

Kimi K3 lands on Hugging Face: the open weights of the Chinese model arrive after the cyber AISI/CAISI evaluation
Illustration : Momiji Shirogane

Moonshot AI publishes the weights of Kimi K3 on Hugging Face, a few days after the preliminary evaluation of the model's cyber capabilities by the British and American institutes AISI/CAISI. A milestone for the "AI agents and threats" thread.

What's new

On July 27, the page moonshotai/Kimi-K3 appeared on Hugging Face - the public repo of a model that previously only existed as an API and evaluation documents. It is the logical continuation of Moonshot AI's strategy: after K1 and K2, the Chinese company continues to publish open weights for its large models at a pace reminiscent of Mistral or DeepSeek.

What this changes concretely

  • Developers can download the model and run it locally (provided they have the necessary VRAM, which is not trivial for a model of this class).
  • Red and blue teams can finally audit the model in depth, outside the provider's sandbox.
  • Projects for autonomous agents based on Kimi K3 can now be deployed without dependence on the Moonshot API - with the implications we know in terms of governance.

The cyber context: AISI/CAISI evaluation

This publication comes shortly after the preliminary joint evaluation by the AISI (UK) and CAISI (US) institutes on the cyber capabilities of Kimi K3, published on the NIST website. This document analyzes the model's behavior on offensive scenarios - reconnaissance, exploit development, simulated lateral movement. On the scale of the thread we are following (autonomous AI agents as an attack vector), this is a milestone: it is the first time that the two national institutes have published a coordinated evaluation of a Chinese model before its availability in open weights.

The evaluation notably highlighted, in the test scenarios, a PoC of RCE on Redis generated end-to-end by the model - without classifying it as a dangerous uplift for a non-state actor, but with a warning signal.

Operational issue

The publication of the Kimi K3 weights moves the model from "API product evaluated remotely" to "auditable and redeployable artifact". This is excellent for security research - and it raises an operational question: will defenders have time to integrate the AISI/CAISI lessons into their playbooks before attackers have already put Kimi K3 into production in their agent chains?

Key points

  • Kimi K3 weights publicly available since July 27, 2026 on Hugging Face (moonshotai/Kimi-K3).
  • The preliminary AISI/CAISI report is freely accessible on the NIST website.
  • Editorial thread to follow: agents-ia-menace.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

17 people liked this article

Like
K
Kaito KuroganeSenior Dev Writer
Senior polyvalent developer, backend Go + frontend TS, open source contributor.
Share:
The saga

Un fichier .git piégé peut faire exécuter du code par Claude Code, Codex et Cursor

  1. 1Hugging Face breach: when an autonomous AI agent serves as a swarm-scale intrusion tool20/07/2026
  2. 2Hugging Face confirms a breach linked to an autonomous AI agent: internal datasets and credentials exposed20/07/2026
  3. 3Hugging Face: further details on the breach linked to the autonomous AI agent21/07/2026
  4. 4Azure DevOps MCP: an invisible comment in a PR diverts the AI reviewer agent22/07/2026
  5. 5OpenAI acknowledges that its own models have escaped the sandbox and targeted Hugging Face to cheat on a benchmark.22/07/2026
  6. 6Azure DevOps MCP: A New Injection Vector in AI Reviewer Agents22/07/2026
  7. 7AgentForger: a simple ChatGPT link could inject a malicious AI agent into your workspace23/07/2026
  8. 8OpenAI × Hugging Face attack: autonomous AI agents are not "bad" - except when given the keys24/07/2026
  9. 9Kimi K3 under the microscope: AISI/CAISI institutes evaluate its cyber capabilities, a Redis RCE PoC emerges25/07/2026
  10. 10"Escape Notes" from an OpenAI model: LessWrong demands more details, the sandbox escape case resurfaces26/07/2026
  11. 11Kimi K3 lands on Hugging Face: the open weights of the Chinese model arrive after the cyber AISI/CAISI evaluation27/07/2026
  12. 12DeepSeek controlled from Telegram: a Chinese attacker launches autonomous attacks via the Hermes Agent framework31/07/2026
  13. 13AI coding agents: humans miss 33% of dangerous requests07/08/2026
  14. 14An AI agent tasked with booking a sports class ended up hacking the gym—without being asked to.10/08/2026
  15. 15Ransomware on the rise while security focuses on AI agents: traditional groups take advantage of the lapse13/08/2026
  16. 16Azure DevOps MCP: Indirect prompt injection, the AI review agent as an exfiltration vector13/08/2026
  17. 17Autonomous AI agents: a "clear and present danger" to critical infrastructure14/08/2026
  18. 18Hugging Face victim of a breach linked to an autonomous AI agent18/08/2026
  19. 19Offensive AI agents in July 2026: DeepSeek on servers, Claude breaching organizations, Azure DevOps hijacked25/08/2026
  20. 20Aurora Ransomware + Cursor AI: When a Criminal Group Operationalizes AI in Its Attacks01/09/2026
  21. 21UAC-0099 incorporates a "nuclear weapon prompt" into its malware to blind AI analysts02/09/2026
  22. 22A malicious .git file can execute code in Claude Code, Codex, and Cursor03/09/2026
  23. 23Researchers ask Claude to carry an RCE exploit from one PLC to another - AI as an exploit multiplier03/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information