正在加载视频...

视频加载失败

Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. Please patch CVE-2026-64638 as soon as possible!

1,647,376 次观看 • 1 个月前 •via X (Twitter)

25 条评论

Nav Toor 的头像
Nav Toor1 个月前

found by open-source models, not some big lab

NodeArc 的头像
NodeArc1 个月前

Open source models defying closed frontier models in cybersec will never be uncool

|| Ɒraɢσn || 的头像
|| Ɒraɢσn ||1 个月前

.!

LEX 的头像
LEX1 个月前

Morris worm, 1988: 10 percent of the internet, one grad student, one sendmail bug. 38 years later an autonomous agent covers a bigger surface for the price of a compute run. The finder collapsed to zero.

Syed Muhammad Ali Minhal🔻 的头像
Syed Muhammad Ali Minhal🔻1 个月前

“43 efffng % of the internet !! “

Fiducial.ai 的头像
Fiducial.ai1 个月前

is there a disclosure timeline? preauth rce on core found by a model is a first

安叫兽|Bird🕊️ 🔶 BNB 的头像
安叫兽|Bird🕊️ 🔶 BNB1 个月前

这影响面也太离谱了,赶紧打补丁

Zill | Tech Support & Cybersec 的头像
Zill | Tech Support & Cybersec1 个月前

@HackingDave Pre-auth XSS straight to RCE on core WordPress is wild. The fact that an open-source model chain found this autonomously is huge for AI red teaming. Patching ASAP. 🛡️

icefrog.◎ 的头像
icefrog.◎1 个月前

43% is wild.

Gobena Dache (ጎበና ዳጬ) 的头像
Gobena Dache (ጎበና ዳጬ)1 个月前

This is very huge

cyberfreak999 的头像
cyberfreak9991 个月前

It's really interesting that the chain was surfaced by open source models. The harder part for most operators will be confirming whether thier auto update path actually pulled the backports to older major versions before the first phishing wave starts.

Hải Ly 的头像
Hải Ly1 个月前

43 percent is a nightmare. manual audits are officially dead, time to automate the defense

Dyu Ninja Lead 的头像
Dyu Ninja Lead1 个月前

đỉnh thiệt, patch gấp đi ae

sutanisurabu 的头像
sutanisurabu1 个月前

Пиздец

⸎Medusa⸎𓆙 ϬɸяϬɸήSS Ϭ⧬đđЗŝŝ ⸎Serpent Ƥя¡ήcεşş𓆙⧪𖤐 的头像
⸎Medusa⸎𓆙 ϬɸяϬɸήSS Ϭ⧬đđЗŝŝ ⸎Serpent Ƥя¡ήcεşş𓆙⧪𖤐1 个月前

these wordpress breaches have been active for a while and they keep getting worse. good luck LMAO

Life Makers Team🍉🇵🇸 的头像
Life Makers Team🍉🇵🇸1 个月前

Your donation brings joy and happiness to every child affected 💗🤲💗🤲by trauma in Gaza. Be a support for them and contribute even just one dollar.

Leliu 的头像
Leliu1 个月前

Concerning vulnerability impacting a significant portion of the internet.

snsn 的头像
snsn1 个月前

where did she buy that outfit from

Safwan 的头像
Safwan1 个月前

43% WP claim is huge, patch fast.

Robinhood Whale 🐋 的头像
Robinhood Whale 🐋1 个月前

ONLY UP FROM HERE MOON IS Programmed 🌒🚀

Dalal 🫎 的头像
Dalal 🫎1 个月前

still in his prime

Kenneth S. 的头像
Kenneth S.1 个月前

43% of the internet and “patch as soon as possible” in the same sentence is terrifying. AI-assisted security research is moving fast.

Papa Lumi 的头像
Papa Lumi1 个月前

Tôi cũng từng gặp phải lỗ hổng đó 😳, làm cách nào bạn tự động tìm thấy nó?

Jan Grewe 的头像
Jan Grewe1 个月前

If a logged in(!) administrator(!) needs to explicitly click(!) something, is it really a "preauth RCE"? Or are we just making shit up now, as one would expect from somebody with "AI" in their name? Damn clanker wankers...

ovax 的头像
ovax1 个月前

Wp2shell et maintenant xss2shell 🤣🤣🤣

相关视频

Today, we’re thrilled to introduce GAIA, a modular creation engine for the AI age. At its core, GAIA is a multiplayer creation engine designed to bring democratized Generative AI abilities to everyone, hence its name. It abstracts away the complexities of leveraging open-source software, hardware requirements, and technical intricacies, allowing creators to focus solely on creating, together. GAIA has been instrumental in powering the imagination and creative works of our studio, significantly boosting productivity, collaboration, and creativity. It has saved our team thousands of man-days in production work, enabling us to dream bigger, bolder, and execute more swiftly. When used by experienced creators, GAIA, with its ever-growing toolsets built by core contributors, stands to be the best AI creative co-pilot for industry-specific production workflows—from gaming to fashion, and from personal consumption to real estate renderings. GAIA's self-reinforcing flywheel is poised to dramatically enhance the platform's capabilities in both the near and long term: The cost of GPUs and compute will continue to improve. Open-source AI models are becoming increasingly powerful over time, as seen by the evolution from Stable Diffusion 1 to Lightning, alongside other impressive OSS creations like AnimateDiff, LoRAs, and ControlNet. The architecture of AI workflows will become more fine-grained, allowing exponentially increasing control over final outputs. The data and connections that AI workflows can make, both in-app and out-of-app, will grow more sophisticated. GAIA already allows for the chaining of Generative Image AI recipes, grouping complex node-based programs into simple consumer-facing interfaces. Soon, with multi-modality workflows, creators will be able to leverage not only images but also text and sound to create even more complex workflows. Today is the least capable GAIA will ever be. It already provides superpowers unachievable by many creators who know how to harness them. We have an extremely exciting backlog of features lined up, starting with social features. Our mission as Ather Collective core contributors is to get GAIA into the hands of as many creators and businesses as possible. While we believe in e/acc, our north star for Ather Collective remains: Equitable, Accessible, Composable, and Collaborative. If you would like to be a part of the early access users of GAIA, please register using this link: Our team will open up capacity as soon as we are able to. There is only one way AI benefits humanity, and that’s through open AI. Let’s be a part of it. ✌🏻

TIN | Sipher Odyssey & Ather Labs

14,204 次观看 • 2 年前

Alexandr Wang, Meta's Chief AI Officer, on why Meta can no longer simply open-source its frontier model: As part of standing up Meta Superintelligence Labs, the team rewrote its internal risk doctrine. "One of the things that we did as part of Meta Superintelligence Labs is we updated our what we call our advanced AI scaling framework which is really our view of what are the risks that we see in developing these very powerful models and how do we want to handle those risks as we see them in early testing." They then ran their frontier model through it, and published what came back. "We published a lot of what we saw in the process of training Muark in our preparedness report and some of the things that we saw is that it actually triggered some high risk areas in the course of early training particularly around biorisk but also a number of the risks were elevated." The trigger came during early training, well before launch or red-teaming. Biorisk was the standout, with several other categories rising alongside it. Alexandr Wang is clear this isn't specific to Meta: "This is something I think the entire industry has seen as the models have improved pretty dramatically over the past year so we certainly aren't the only ones to see a host of these risks show up as we scaled up the models and as we sort of kept pushing the frontier of research." Which brings him to the real fork in the road: the difference between shipping a model inside a product and handing out the weights. "When we launched a model like New Spark in a product, we have a lot of ways to mitigate some of these risks and ensure that we're able to launch it in a safe and responsible way. It's much harder to do that when you open source a model and people can use that model in all sorts of contexts that we may not have full understanding of." A product is a controlled surface. You can filter, monitor, rate-limit, patch and revoke. An open-weights release is a one-way door: once the file is out, the deployment context and the mitigations both stop being yours. So Meta is building something different for release: "So we're in the process right now of developing models that we believe are fit and safe to be open source while still maintaining as much of the performance capabilities as possible."

Big Brain AI

16,374 次观看 • 1 个月前

David Sacks Predicts the Regulatory Capture Playbook to Ban Open Source AI, Step by Step: David Sacks: “I got bad news for you, Chamath, an open source ban is coming. They're not going to call it that. They're going to say that we simply have to apply the same standards to open models that we apply to closed ones. Here's how they do it step by step, let me explain how regulatory capture actually works. So first of all, you have to get this regulatory apparatus. Dario wants an FDA for AI, but he doesn't have enough political support for that, so instead they do this Trojan horse of a FINRA for AI. They call it self-regulating, it's not really, but anyway, that gets them off the ground. Now they've created the standard-setting organization. Now they've got pre-release model testing. Then the pressure grows to codify that in law, so that happens next. And then what they do is they say, ‘Look, all these standards need to apply equally to all models.’ But here's the problem with that. Open models and closed models are technologically different. Once you release an open model into the world, you can't roll it back and you can't monitor exactly how people are using it because they run it on their own hardware. Dario says this is what makes open models dangerous. So what they're going to do is they're going to have the standard-setting body say, ‘Well, we have to set the standards for AI safety.’ By the way, Dario and OpenAI, they're going to fund the whole thing. They're going to contribute all the compute. They're going to be behind it. They're going to be the ones coordinating with the government officials because frankly, people in government have no idea how to monitor and control and set standards for AI safety. Technologically, this is way beyond them. So they're going to go to these companies and say, ‘Tell us how to do it.’ And so what will happen is the standards will get set, and then it'll be a very simple matter of fairness to say that the standards need to apply to open as well as closed models. The open models cannot comply in the same way, and gradually they will be shut out of the market.”

The All-In Podcast

299,023 次观看 • 1 个月前