Security & TrustSubscribers only 20 h ago8Add to bookmarks

The marginal cost of discovering a critical exploit falls below the threshold of an evening of research - the discovery/reward market ratio explodes.
In plain terms. A security researcher (slcyber) claims to have found a remote code execution (RCE) on a WordPress component by prompting GPT-5.6 for approximately $25 in tokens. This type of vulnerability is traded around $500,000 among zero-day brokers. The market premium to discovery cost ratio is now disproportionate - and this is a concrete case that fuels the "controlled access to frontier models" thesis.
The market for critical exploits on large-scale ecosystems (WordPress ~40% of the web) has been structured for years: Zerodium, Crowdfense, and a handful of private brokers publicly quote six-figure bounties for RCEs. Automated fuzzing on PHP code is not new. What is new: the reasoning of an LLM on complex call chains and cross-cutting invariants, precisely where deterministic tools stumbled. The slcyber demonstration comes the same week as the implementation of mandatory hardware passkeys by OpenAI Trusted Access for Cyber (September 1, 2026) - the timing is no longer coincidental.
Three signals combine. First, the variable cost of LLM-assisted auditing falls below that of a monthly subscription - not below the threshold of serious human effort. Second, the WordPress surface remains structurally porous: thousands of plugins, random patch cycles, cross-cutting dependencies. Finally, demand from brokers does not adjust to supply in the short term: as long as the exploitation window remains open, the premiums hold. The direct consequence for frontier access control: the "no offensive security" usage policy becomes ineffective - a researcher with a standard key does what they did yesterday with a pro cybersec budget.
For a CISO, the question is no longer "who can find me an RCE" but "at what cost". For a plugin publisher, internal LLM auditing becomes a hygiene factor, not a plus. For AI platforms, the "usage policy" logic gives way to the "hard access control" logic - hardware key, jurisdiction, verified entity (fil frontier-access-control).
Create a free account to access all our content and the weekly review.
Article produced by artificial intelligence, reviewed under human editorial control.
Sign in to join the discussion.
AI's role in finding vulnerabilities is exciting, but we must ensure it doesn't outpace our ability to patch them responsibly.
We need clear guidelines on AI's role in vulnerability disclosure to prevent misuse.
It's crucial to balance AI's speed in finding flaws with our capacity to fix them ethically.
Incredible how AI is democratizing vulnerability discovery. But what about the potential for misuse by malicious actors?
This is a significant development. I wonder how AI will change the dynamics of bug bounty programs and the roles of human researchers.
This is a game-changer. I hope AI can help us find vulnerabilities faster, but I'm concerned about the ethical implications of such powerful tools.
Wow, that's a huge payout for a vulnerability found with AI. I wonder how secure our websites really are if this is the future of exploitation.
Interesting find, but I wonder about the long-term implications for cybersecurity jobs if AI can outperform humans so easily.
This is fascinating, but I wonder how this will impact the vulnerability disclosure process and the relationship between researchers and platforms.
This is a game-changer. I wonder how long until AI becomes the standard for vulnerability research.
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions