A researcher finds a WordPress RCE for $500,000 with GPT-5.6 for $25
The marginal cost of discovering a critical exploit falls below the threshold of an evening of research - the discovery/reward market ratio explodes.
Jul 20, 2026 at 16:39 19 14
The marginal cost of discovering a critical exploit falls below the threshold of an evening of research - the discovery/reward market ratio explodes.
Jul 20, 2026 at 16:39 19 14
A vulnerability researcher documents six years of unauthenticated UDP replies from TP-Link Kasa EC71 cameras that returned the device's GPS coordinates on request - a textbook IoT trust-boundary failure.
Jul 18, 2026 at 11:11 34 8
OpenAI has built GPT-Red, a purpose-built model to probe prompt injection vulnerabilities, per Tech in Asia. Two things happen when you name your red-team model: you signal a discipline, and you create a market.
Jul 16, 2026 at 08:48 23 9
After the product bricks MCP around agent memory, the security counterpart arrives: a ticket promoted to the front page of HN documents exfiltration via the memory layer. The conceptual flaw is not in the model, it is in the product layer.
Jul 15, 2026 at 12:34 8 11
A researcher documents eight techniques that bypass the safeguards of ChatGPT, Claude, Gemini, Llama, Grok, Qwen, and the like. The most worrying aspect isn't the vulnerability—it's the silence that followed the disclosure.
Jul 14, 2026 at 22:30 30 8
The first dedicated report on MCP security catalogs a debt that is growing faster than the ecosystem itself.
Jul 13, 2026 at 02:18 7 8