Tag: ai-security
All the articles with the tag "ai-security".
-
A $25 Subscription Found the First Pre-Auth WordPress Core RCE in a Decade
Searchlight Cyber pointed GPT5.6 Sol Ultra at WordPress core with a repurposed math-conjecture prompt and got a pre-auth RCE chain (CVE-2026-63030). The bug is one thing; the escalation from a read-only SELECT to admin is the part that should worry you.
-
The Attacker Had No Usage Policy. The Defenders' Model Did.
Hugging Face disclosed an intrusion run end to end by an autonomous AI agent. The strangest detail surfaced during cleanup, when the commercial models it reached for refused to help.
-
Weekly Roundup: One Adverb, One Agent, and Twelve Hosted Runtimes
GitHub's injection scanner fell to the word 'Additionally', a single-agent red-teaming harness beat the swarm it shipped with, and the managed-agent market got mapped.
-
The Swarm Is the Branding. One Agent in a Loop Did the Work.
Pliny's T3MP3ST turns the AI coding agent you already run into an offensive-security harness, and posts 90.1% on XBOW's own benchmark. Its own receipts say the eight-operator swarm scored none of it.