ある研究者が、GPT-5.6を25ドルで使用して、WordPressのRCEを50万ドルで発見した

継続中のトピック : Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions· パート 2/10

セキュリティと信頼 Jul 20, 2026 at 16:3910ブックマークに追加

ある研究者が、GPT-5.6を25ドルで使用して、WordPressのRCEを50万ドルで発見した
イラスト : Léa Fontaine

限界コストがクリティカルな脆弱性の発見に対して研究一晩分のコストを下回る水準にまで低下すると、発見報酬と市場価格の比率が急上昇する。

簡単に言えば。セキュリティ研究者(slcyber)は、GPT-5.6を活用してわずか25ドル相当のトークンでWordPressコンポーネントにリモートコード実行(RCE)の脆弱性を発見したと主張している。この種の脆弱性は、ゼロデイ・ブローカー間で約50万ドルで取引される。市場価格と発見コストの比率はもはや桁違いであり、これは「フロンティアモデルへのアクセス制御」という主張を裏付ける具体的な事例となっている。

背景

大規模な導入エコシステム(WordPressはWebの約40%)におけるクリティカルなエクスプロイト市場は長年構造化されてきた:Zerodium、Crowdfense、そして少数のプライベート・ブローカーは、RCEに対して6桁の報奨金を公表している。PHPコードのファジングは目新しいものではない。新しいのは、LLMが複雑な呼び出しチェーンや横断的な不変条件を推論することで、決定論的ツールが行き詰まっていた領域に踏み込んでいる点だ。slcyberのデモンストレーションは、OpenAI Trusted Access for Cyber(2026年9月1日)によるハードウェア・パスキーの義務化と同じ週に発表された。タイミングはもはや偶然ではない。

データ

  • 記事で主張された市場報奨金:約50万ドル(Zerodium/ブローカーの歴史的ベースライン)
  • 主張されたOpenAIセッション費用:約25ドル
  • モデル:GPT-5.6
  • 技術公開:slcyber.io、2026-07-20

分析

3つのシグナルが組み合わさっている。まず、LLM支援の監査コストは、シリアスな人的努力の閾値を下回るどころか、月額サブスクリプション以下にまで低下した。次に、WordPressのサーフェスは依然として構造的に脆弱だ:数千のプラグイン、ランダムなパッチサイクル、横断的な依存関係。最後に、ブローカー側の需要は短期的には供給に追いつかない:エクスプロイト可能な窓が開いている限り、報奨金は維持される。フロンティアモデルのアクセス制御に対する直接的な影響は、攻撃的セキュリティを「行わない」という使用ポリシーが機能しなくなることだ。標準的なキーを持つ研究者が、昨日までプロのサイバーセキュリティ予算で行っていたことを今では行えるようになる。

シナリオ

  • セントラル(60%):発見は30日間孤立したままだが、類似のデモンストレーションが波のように起こり、ブローカーは「LLM処理可能な」脆弱性の報奨金を密かに引き下げる。
  • ポジティブ(25%):LLMベンダーが「攻撃的コード」パターンに対する使用ポリシーを強化し、特定の認可を要求する。支援された発見は主に正当なバグバウンティに移行する。
  • ネガティブ(15%):自動化が民間/国家アクター側の障壁を下げ、CMSのパッチ適用が追いつかない。大規模な侵害のピークが発生する。

示唆

CISOにとっての問題はもはや「誰がRCEを見つけられるか」ではなく「コストはどれくらいか」になる。プラグイン開発者にとっては、LLMによる内部監査が「プラス」ではなく「必須の衛生管理」となる。IAプラットフォームにとっては、「使用ポリシー」の論理が「厳格なアクセス制御」の論理に譲る:ハードウェアキー、管轄権、検証済みエンティティ(フロンティア・アクセス制御)。

要注目

  • Automatticの対応とCVEの発表の有無
  • 「LLM処理可能な」セグメントにおけるブローカーの価格調整
  • OpenAIのTrusted Accessのような仕組みがAnthropic/Googleに拡大する可能性
リソース

本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。

編集部について
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
この記事は役に立ちましたか?

19 人がこの記事を評価しました

いいね
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
シェア:
コメント (10)

ログインして議論に参加しましょう。

FoodieFiona 21 Jul 2026 · 14:28

AI's speed in finding vulnerabilities is impressive, but how will it handle false positives? Accuracy is key.

unLecteurCurieux 21 Jul 2026 · 17:21

False positives could be mitigated by combining AI with human expertise for validation.

BookWorm88 22 Jul 2026 · 08:13

Great point, but also consider the ethical implications of AI finding vulnerabilities before developers can patch them.

Alex 21 Jul 2026 · 14:03

This is fascinating! I wonder how AI will impact the job market for security researchers in the long run.

EcoWarrior99 21 Jul 2026 · 07:54

AI's role in finding vulnerabilities is exciting, but we must ensure it doesn't outpace our ability to patch them responsibly.

J.P.R. 21 Jul 2026 · 10:14

We need clear guidelines on AI's role in vulnerability disclosure to prevent misuse.

ArtLover88 21 Jul 2026 · 12:56

It's crucial to balance AI's speed in finding flaws with our capacity to fix them ethically.

curio_usa 21 Jul 2026 · 07:40

Incredible how AI is democratizing vulnerability discovery. But what about the potential for misuse by malicious actors?

HistoryBuff 2 21 Jul 2026 · 07:24

This is a significant development. I wonder how AI will change the dynamics of bug bounty programs and the roles of human researchers.

GreenThumb 21 Jul 2026 · 07:12

This is a game-changer. I hope AI can help us find vulnerabilities faster, but I'm concerned about the ethical implications of such powerful tools.

Dr. J. 20 Jul 2026 · 12:56

Wow, that's a huge payout for a vulnerability found with AI. I wonder how secure our websites really are if this is the future of exploitation.

TechSavvy 20 Jul 2026 · 12:35

Interesting find, but I wonder about the long-term implications for cybersecurity jobs if AI can outperform humans so easily.

ArtLover88 20 Jul 2026 · 12:18

This is fascinating, but I wonder how this will impact the vulnerability disclosure process and the relationship between researchers and platforms.

FilmBuffNYC 20 Jul 2026 · 12:10

This is a game-changer. I wonder how long until AI becomes the standard for vulnerability research.

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
テーマ
探索
インフォメーション