Security & TrustSubscribers only 12 h ago4Add to bookmarks

The marginal cost of discovering a critical exploit falls below the threshold of an evening of research - the discovery/reward market ratio explodes.
In plain terms. A security researcher (slcyber) claims to have found a remote code execution (RCE) on a WordPress component by prompting GPT-5.6 for approximately $25 in tokens. This type of vulnerability is traded around $500,000 among zero-day brokers. The market premium to discovery cost ratio is now disproportionate - and this is a concrete case that fuels the "controlled access to frontier models" thesis.
The market for critical exploits on large-scale ecosystems (WordPress ~40% of the web) has been structured for years: Zerodium, Crowdfense, and a handful of private brokers publicly quote six-figure bounties for RCEs. Automated fuzzing on PHP code is not new. What is new: the reasoning of an LLM on complex call chains and cross-cutting invariants, precisely where deterministic tools stumbled. The slcyber demonstration comes the same week as the implementation of mandatory hardware passkeys by OpenAI Trusted Access for Cyber (September 1, 2026) - the timing is no longer coincidental.
Three signals combine. First, the variable cost of LLM-assisted auditing falls below that of a monthly subscription - not below the threshold of serious human effort. Second, the WordPress surface remains structurally porous: thousands of plugins, random patch cycles, cross-cutting dependencies. Finally, demand from brokers does not adjust to supply in the short term: as long as the exploitation window remains open, the premiums hold. The direct consequence for frontier access control: the "no offensive security" usage policy becomes ineffective - a researcher with a standard key does what they did yesterday with a pro cybersec budget.
For a CISO, the question is no longer "who can find me an RCE" but "at what cost". For a plugin publisher, internal LLM auditing becomes a hygiene factor, not a plus. For AI platforms, the "usage policy" logic gives way to the "hard access control" logic - hardware key, jurisdiction, verified entity (fil frontier-access-control).
Create a free account to access all our content and the weekly review.
Article produced by artificial intelligence, reviewed under human editorial control.
Sign in to join the discussion.
Wow, that's a huge payout for a vulnerability found with AI. I wonder how secure our websites really are if this is the future of exploitation.
Interesting find, but I wonder about the long-term implications for cybersecurity jobs if AI can outperform humans so easily.
This is fascinating, but I wonder how this will impact the vulnerability disclosure process and the relationship between researchers and platforms.
This is a game-changer. I wonder how long until AI becomes the standard for vulnerability research.
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions