- Sources: NIST announcement, HN 49044492
- Summary: The UK AI Security Institute and the US Center for AI Standards and Innovation published a joint preliminary assessment of Moonshot AI's Kimi K3 on 2026-07-23. On ExploitBench, a public benchmark over 41 post-2023 V8 engine vulnerabilities, K3 scored 32%, above the open-weight GLM 5.2 at 24% and below recent frontier models. It reached arbitrary code execution on none of the 41 tasks, against an average of 20 of 41 for leading models. On The Last Ones, a 32-step simulated corporate network intrusion, K3 reached step 17 on average against 28.5 for US frontier models tested with system-level safeguards disabled, and completed the scenario in 1 of 10 attempts. The institutes state K3's safeguards did not prevent it from attempting exploit development. They label the evaluations preliminary over a small benchmark set, and note the network scenario has no active defenders and contains an intentional attack path.
- Why it matters: This is a measured bound on the offensive capability of the model credited with the Redis findings above, in a debate that has otherwise run on vendor claims and self-reported incident counts.
- Follow-up: Watch for the full report and its methodology, whether the safeguards finding draws a Moonshot response, and whether the 2026-07-27 weight release changes the assessment.
send feedback on this story