Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. Please patch CVE-2026-64638 as soon as possible!

1,647,376 görüntüleme • 1 ay önce •via X (Twitter)

25 Yorum

Nav Toor profil fotoğrafı
Nav Toor1 ay önce

found by open-source models, not some big lab

NodeArc profil fotoğrafı
NodeArc1 ay önce

Open source models defying closed frontier models in cybersec will never be uncool

|| Ɒraɢσn || profil fotoğrafı
|| Ɒraɢσn ||1 ay önce

.!

LEX profil fotoğrafı
LEX1 ay önce

Morris worm, 1988: 10 percent of the internet, one grad student, one sendmail bug. 38 years later an autonomous agent covers a bigger surface for the price of a compute run. The finder collapsed to zero.

Syed Muhammad Ali Minhal🔻 profil fotoğrafı
Syed Muhammad Ali Minhal🔻1 ay önce

“43 efffng % of the internet !! “

Fiducial.ai profil fotoğrafı
Fiducial.ai1 ay önce

is there a disclosure timeline? preauth rce on core found by a model is a first

安叫兽|Bird🕊️ 🔶 BNB profil fotoğrafı
安叫兽|Bird🕊️ 🔶 BNB1 ay önce

这影响面也太离谱了,赶紧打补丁

Zill | Tech Support & Cybersec profil fotoğrafı
Zill | Tech Support & Cybersec1 ay önce

@HackingDave Pre-auth XSS straight to RCE on core WordPress is wild. The fact that an open-source model chain found this autonomously is huge for AI red teaming. Patching ASAP. 🛡️

icefrog.◎ profil fotoğrafı
icefrog.◎1 ay önce

43% is wild.

Gobena Dache (ጎበና ዳጬ) profil fotoğrafı
Gobena Dache (ጎበና ዳጬ)1 ay önce

This is very huge

cyberfreak999 profil fotoğrafı
cyberfreak9991 ay önce

It's really interesting that the chain was surfaced by open source models. The harder part for most operators will be confirming whether thier auto update path actually pulled the backports to older major versions before the first phishing wave starts.

Hải Ly profil fotoğrafı
Hải Ly1 ay önce

43 percent is a nightmare. manual audits are officially dead, time to automate the defense

Dyu Ninja Lead profil fotoğrafı
Dyu Ninja Lead1 ay önce

đỉnh thiệt, patch gấp đi ae

sutanisurabu profil fotoğrafı
sutanisurabu1 ay önce

Пиздец

⸎Medusa⸎𓆙 ϬɸяϬɸήSS Ϭ⧬đđЗŝŝ ⸎Serpent Ƥя¡ήcεşş𓆙⧪𖤐 profil fotoğrafı
⸎Medusa⸎𓆙 ϬɸяϬɸήSS Ϭ⧬đđЗŝŝ ⸎Serpent Ƥя¡ήcεşş𓆙⧪𖤐1 ay önce

these wordpress breaches have been active for a while and they keep getting worse. good luck LMAO

Life Makers Team🍉🇵🇸 profil fotoğrafı
Life Makers Team🍉🇵🇸1 ay önce

Your donation brings joy and happiness to every child affected 💗🤲💗🤲by trauma in Gaza. Be a support for them and contribute even just one dollar.

Leliu profil fotoğrafı
Leliu1 ay önce

Concerning vulnerability impacting a significant portion of the internet.

snsn profil fotoğrafı
snsn1 ay önce

where did she buy that outfit from

Safwan profil fotoğrafı
Safwan1 ay önce

43% WP claim is huge, patch fast.

Robinhood Whale 🐋 profil fotoğrafı
Robinhood Whale 🐋1 ay önce

ONLY UP FROM HERE MOON IS Programmed 🌒🚀

Dalal 🫎 profil fotoğrafı
Dalal 🫎1 ay önce

still in his prime

Kenneth S. profil fotoğrafı
Kenneth S.1 ay önce

43% of the internet and “patch as soon as possible” in the same sentence is terrifying. AI-assisted security research is moving fast.

Papa Lumi profil fotoğrafı
Papa Lumi1 ay önce

Tôi cũng từng gặp phải lỗ hổng đó 😳, làm cách nào bạn tự động tìm thấy nó?

Jan Grewe profil fotoğrafı
Jan Grewe1 ay önce

If a logged in(!) administrator(!) needs to explicitly click(!) something, is it really a "preauth RCE"? Or are we just making shit up now, as one would expect from somebody with "AI" in their name? Damn clanker wankers...

ovax profil fotoğrafı
ovax1 ay önce

Wp2shell et maintenant xss2shell 🤣🤣🤣

Benzer Videolar

Today, we’re thrilled to introduce GAIA, a modular creation engine for the AI age. At its core, GAIA is a multiplayer creation engine designed to bring democratized Generative AI abilities to everyone, hence its name. It abstracts away the complexities of leveraging open-source software, hardware requirements, and technical intricacies, allowing creators to focus solely on creating, together. GAIA has been instrumental in powering the imagination and creative works of our studio, significantly boosting productivity, collaboration, and creativity. It has saved our team thousands of man-days in production work, enabling us to dream bigger, bolder, and execute more swiftly. When used by experienced creators, GAIA, with its ever-growing toolsets built by core contributors, stands to be the best AI creative co-pilot for industry-specific production workflows—from gaming to fashion, and from personal consumption to real estate renderings. GAIA's self-reinforcing flywheel is poised to dramatically enhance the platform's capabilities in both the near and long term: The cost of GPUs and compute will continue to improve. Open-source AI models are becoming increasingly powerful over time, as seen by the evolution from Stable Diffusion 1 to Lightning, alongside other impressive OSS creations like AnimateDiff, LoRAs, and ControlNet. The architecture of AI workflows will become more fine-grained, allowing exponentially increasing control over final outputs. The data and connections that AI workflows can make, both in-app and out-of-app, will grow more sophisticated. GAIA already allows for the chaining of Generative Image AI recipes, grouping complex node-based programs into simple consumer-facing interfaces. Soon, with multi-modality workflows, creators will be able to leverage not only images but also text and sound to create even more complex workflows. Today is the least capable GAIA will ever be. It already provides superpowers unachievable by many creators who know how to harness them. We have an extremely exciting backlog of features lined up, starting with social features. Our mission as Ather Collective core contributors is to get GAIA into the hands of as many creators and businesses as possible. While we believe in e/acc, our north star for Ather Collective remains: Equitable, Accessible, Composable, and Collaborative. If you would like to be a part of the early access users of GAIA, please register using this link: Our team will open up capacity as soon as we are able to. There is only one way AI benefits humanity, and that’s through open AI. Let’s be a part of it. ✌🏻

TIN | Sipher Odyssey & Ather Labs

14,204 görüntüleme • 2 yıl önce

Alexandr Wang, Meta's Chief AI Officer, on why Meta can no longer simply open-source its frontier model: As part of standing up Meta Superintelligence Labs, the team rewrote its internal risk doctrine. "One of the things that we did as part of Meta Superintelligence Labs is we updated our what we call our advanced AI scaling framework which is really our view of what are the risks that we see in developing these very powerful models and how do we want to handle those risks as we see them in early testing." They then ran their frontier model through it, and published what came back. "We published a lot of what we saw in the process of training Muark in our preparedness report and some of the things that we saw is that it actually triggered some high risk areas in the course of early training particularly around biorisk but also a number of the risks were elevated." The trigger came during early training, well before launch or red-teaming. Biorisk was the standout, with several other categories rising alongside it. Alexandr Wang is clear this isn't specific to Meta: "This is something I think the entire industry has seen as the models have improved pretty dramatically over the past year so we certainly aren't the only ones to see a host of these risks show up as we scaled up the models and as we sort of kept pushing the frontier of research." Which brings him to the real fork in the road: the difference between shipping a model inside a product and handing out the weights. "When we launched a model like New Spark in a product, we have a lot of ways to mitigate some of these risks and ensure that we're able to launch it in a safe and responsible way. It's much harder to do that when you open source a model and people can use that model in all sorts of contexts that we may not have full understanding of." A product is a controlled surface. You can filter, monitor, rate-limit, patch and revoke. An open-weights release is a one-way door: once the file is out, the deployment context and the mitigations both stop being yours. So Meta is building something different for release: "So we're in the process right now of developing models that we believe are fit and safe to be open source while still maintaining as much of the performance capabilities as possible."

Big Brain AI

16,374 görüntüleme • 1 ay önce

David Sacks Predicts the Regulatory Capture Playbook to Ban Open Source AI, Step by Step: David Sacks: “I got bad news for you, Chamath, an open source ban is coming. They're not going to call it that. They're going to say that we simply have to apply the same standards to open models that we apply to closed ones. Here's how they do it step by step, let me explain how regulatory capture actually works. So first of all, you have to get this regulatory apparatus. Dario wants an FDA for AI, but he doesn't have enough political support for that, so instead they do this Trojan horse of a FINRA for AI. They call it self-regulating, it's not really, but anyway, that gets them off the ground. Now they've created the standard-setting organization. Now they've got pre-release model testing. Then the pressure grows to codify that in law, so that happens next. And then what they do is they say, ‘Look, all these standards need to apply equally to all models.’ But here's the problem with that. Open models and closed models are technologically different. Once you release an open model into the world, you can't roll it back and you can't monitor exactly how people are using it because they run it on their own hardware. Dario says this is what makes open models dangerous. So what they're going to do is they're going to have the standard-setting body say, ‘Well, we have to set the standards for AI safety.’ By the way, Dario and OpenAI, they're going to fund the whole thing. They're going to contribute all the compute. They're going to be behind it. They're going to be the ones coordinating with the government officials because frankly, people in government have no idea how to monitor and control and set standards for AI safety. Technologically, this is way beyond them. So they're going to go to these companies and say, ‘Tell us how to do it.’ And so what will happen is the standards will get set, and then it'll be a very simple matter of fairness to say that the standards need to apply to open as well as closed models. The open models cannot comply in the same way, and gradually they will be shut out of the market.”

The All-In Podcast

299,023 görüntüleme • 1 ay önce