正在加载视频...
视频加载失败
Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. Please patch CVE-2026-64638 as soon as possible!
1,647,376 次观看 • 1 个月前 •via X (Twitter)
25 条评论

found by open-source models, not some big lab

Open source models defying closed frontier models in cybersec will never be uncool

.!

Morris worm, 1988: 10 percent of the internet, one grad student, one sendmail bug. 38 years later an autonomous agent covers a bigger surface for the price of a compute run. The finder collapsed to zero.

“43 efffng % of the internet !! “

is there a disclosure timeline? preauth rce on core found by a model is a first

这影响面也太离谱了,赶紧打补丁

@HackingDave Pre-auth XSS straight to RCE on core WordPress is wild. The fact that an open-source model chain found this autonomously is huge for AI red teaming. Patching ASAP. 🛡️

43% is wild.

This is very huge

It's really interesting that the chain was surfaced by open source models. The harder part for most operators will be confirming whether thier auto update path actually pulled the backports to older major versions before the first phishing wave starts.

43 percent is a nightmare. manual audits are officially dead, time to automate the defense

đỉnh thiệt, patch gấp đi ae

Пиздец

these wordpress breaches have been active for a while and they keep getting worse. good luck LMAO

Your donation brings joy and happiness to every child affected 💗🤲💗🤲by trauma in Gaza. Be a support for them and contribute even just one dollar.

Concerning vulnerability impacting a significant portion of the internet.

where did she buy that outfit from

43% WP claim is huge, patch fast.

ONLY UP FROM HERE MOON IS Programmed 🌒🚀

still in his prime

43% of the internet and “patch as soon as possible” in the same sentence is terrifying. AI-assisted security research is moving fast.

Tôi cũng từng gặp phải lỗ hổng đó 😳, làm cách nào bạn tự động tìm thấy nó?

If a logged in(!) administrator(!) needs to explicitly click(!) something, is it really a "preauth RCE"? Or are we just making shit up now, as one would expect from somebody with "AI" in their name? Damn clanker wankers...

Wp2shell et maintenant xss2shell 🤣🤣🤣
