Top
Best
New

Posted by infosecau 1 day ago

I found a WordPress RCEs with GPT5.6 and $25(slcyber.io)
389 points | 213 commentspage 2
ifdefdebug 1 day ago|
> Is GPT5.6 Sol Superhuman?

This is not a simple y/n question. Computers have been superhuman at playing chess for decades now. Reading this article, I guess they are superhuman at understanding code now as well.

chrisjj 1 day ago|
> Computers have been superhuman at playing chess for decades now.

And at doing arithmetic for even longer /i

dzonga 1 day ago||
wordpress is so shitty - though it runs the majority of the web.

people think PHP is shitty cz of Wordpress.

at a certain point in time - people need to move to better ecosystems painful as that may be.

f311a 20 hours ago|
Historically, a lot vulnerabilities in PHP projects were because of PHP itself. Things like register_globals, remote includes/reads using functions that supposed to read local data and so on.
barbazoo 18 hours ago||
I'd expect the amount of money paid for exploits to go down then. It's inefficient to pay >$25 for an exploit that took $25 to make.
cadamsdotcom 1 day ago||
That was an incredible writeup! Chapeau to the author - thanks for taking the time to do a writeup.

When Anthropic claimed Mythos chained 4 or 5 bugs to achieve sandbox escape and found bugs in core software, it sounded like bs. But here we are 2 months later seeing what they meant.

Cybersecurity was always a hard sell; security flaws were invisible - by contrast a fence with a hole is visible to everyone - anyone can ignore the locked gate and walk through the fence hole. With cybersecurity a hole in the fence may go unnoticed for years, maybe forever.

LLMs level the field. We will all benefit from more secure systems, a few people will get a lot of egg on their faces, and it will end the malpractice of underinvesting in software security to get a product out the door.

alienbaby 1 day ago|
| We will all benefit from more secure systems

the people that can afford it, sure.

s3p 1 day ago||
Can some people not afford open source software?
vavkamil 1 day ago||
This one is both awesome and scary. We are living in a black mirror episode, where one well-crafted LLM prompt can get you $500k or the ability to hack into 500M websites :)
wongarsu 1 day ago||
The market will quickly adjust to the point where spending $50 on tokens will on average give you a vulnerability valued at $50. Maybe $100 to account for your edge in having a better prompt and the risk of prison time you take in selling the exploit

In fact that may well be true today. OP didn't try to sell it to discover the true price the market is willing to pay. And we all know that "somebody paid $$$ for something similar in the past" is no guarantee that somebody else is willing to pay any significant sum for your thing today. If it was, startups would be a lot easier

hoppp 1 day ago|||
I don't think OP got $500k , it's only clickbait in the title.
Philip-J-Fry 1 day ago|||
One LLM prompt can't get you $500K. Why would someone spend $500k instead of just prompting themselves?
inigyou 1 day ago||
Because they don't know you can
muldvarp 21 hours ago||
I think anyone willing to pay $500k is well aware that LLMs can be used to find vulnerabilities.
cbg0 1 day ago||
Don't get all starry-eyed, the people owning those sites also have access to LLMs, so both the hacks and paydays are rare.
throwitaway222 20 hours ago||
Seems like exploit brokers can just buy a codex license and put the 500k towards finding all bugs in all software for the price of one bug
_superposition_ 1 day ago||
The cost of business nowadays? At what point does it become apparent that in today's world software needs continuous pen testing and scanning? If you don't your attackers will.
alienbaby 1 day ago|
| in today's world software needs continuous pen testing and scanning

points to a bigger problem perhaps; software design, construction and distribution is fundamentally flawed.

tantalor 1 day ago||
Is this real? Or did they concoct this vulnerability just to write a blog post?

I'm not seeing any mention where they report this to WP or the patch.

testplzignore 1 day ago|
https://github.com/WordPress/WordPress/commit/c474dc6051dd60...
r1ch 1 day ago|
Does Sol allow this kind of research by default or is this a "look at me I'm on the cyber research allowlist" post?
More comments...