The surprising (and possibly untrue) thing is the high price of canned vulnerabilities. WordPress is known as the remote root shell with a blogging feature.
I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching. I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in…
I found a WordPress RCEs with GPT5.6 and $25
111–120 of 247 posts
Re: I found a WordPress RCEs with GPT5.6 and $25
#112There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.
Re: I found a WordPress RCEs with GPT5.6 and $25
#113Earlier quoted context omitted.
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…
[flagged]
Re: I found a WordPress RCEs with GPT5.6 and $25
#114Re: I found a WordPress RCEs with GPT5.6 and $25
#115This assumes those who'd pay $500k don't have the skill to use GTP5.6 for the same purpose themselves?
I've been using LLMs to find security vulnerabilities and there is no way I can just submit what I found and call it a day (many try).
Re: I found a WordPress RCEs with GPT5.6 and $25
#116There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…
Re: I found a WordPress RCEs with GPT5.6 and $25
#117So they spent the $25. But the real question here is did they get the $500K?
Re: I found a WordPress RCEs with GPT5.6 and $25
#118Re: I found a WordPress RCEs with GPT5.6 and $25
#119Re: I found a WordPress RCEs with GPT5.6 and $25
#120How do you find exploits without risking someone seeing your attempt and reporting you as a hacker? do you register first somewhere?