한 연구자가 GPT-5.6을 25달러에 사용하여 워드프레스 RCE를 50만 달러에 발견했습니다

진행 중인 이슈 : Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions· 편 2/10

보안 & 신뢰 Jul 20, 2026 at 16:3910북마크에 추가

한 연구자가 GPT-5.6을 25달러에 사용하여 워드프레스 RCE를 50만 달러에 발견했습니다
삽화 : Léa Fontaine

한계 비용이 한밤의 연구 비용 아래로 떨어졌습니다. 발견 대 시장 보상 비율이 급격히 상승합니다.

간단히 말해.

보안 연구원(슬사이버)이 GPT-5.6을 약 25달러 상당의 토큰으로 구동해 WordPress 구성 요소에서 원격 코드 실행(RCE) 취약점을 발견했다고 주장합니다. 이러한 종류의 취약점은 제로데이 브로커 사이에서 약 50만 달러에 거래됩니다. 시장에서의 프리미엄과 발견 비용의 비율은 이제 과도해졌으며, 이는 ‘프론티어 모델 접근 통제’라는 주장을 뒷받침하는 실제 사례입니다.

배경

WordPress(웹의 약 40%)와 같은 대규모 설치 기반 에코시스템에서critical한 취약점 시장은 수년간 구조화되어 왔습니다. Zerodium, Crowdfense 및 소수의 프라이빗 브로커들은 RCE에 대해 6자릿수 보상을 공개적으로 제시해 왔습니다. PHP 코드에 대한 퍼징은 새로운 것이 아닙니다. 새로운 점은 결정론적 도구가 막히던 복잡한 호출 체인과 교차 불변성에서 LLM이 추론하는 방식입니다. 슬사이버의 시연은 OpenAI Trusted Access for Cyber(2026년 9월 1일)의 하드웨어 패스키 필수 도입과 같은 주에 발표되었습니다. 이 타이밍은 더 이상 우연이 아닙니다.

데이터

  • 기사에서 주장하는 시장 프리미엄: ~50만 달러(WordPress RCE에 대한 Zerodium/브로커의 역사적 기준)
  • 주장된 OpenAI 세션 비용: ~25달러
  • 모델: GPT-5.6
  • 기술 발표: slcyber.io, 2026-07-20

분석

세 가지 신호가 결합됩니다. 첫째, LLM 지원 감사 비용이 serious한 인간의 노력 이하로 떨어졌습니다. 둘째, WordPress 표면은 구조적으로 porous합니다: 수천 개의 플러그인, 무작위 패치 주기, 교차 종속성. 셋째, 브로커 측 수요는 단기간에 공급에 맞춰 조정되지 않습니다. 공격 창이 열려 있는 한 프리미엄은 유지됩니다. 프론티어 접근 통제에 대한 직접적인 결과: ‘offensive security 금지’ 정책은 무용지물이 됩니다. 표준 키 하나로 연구원이 어제 프로급 사이버보안 예산으로 하던 일을 할 수 있게 됩니다.

시나리오

  • 중앙 시나리오(60%): 발견이 30일 동안 고립되지만 유사한 시연의 파동을Trigger합니다. 브로커들은 ‘LLM-처리 가능한’ 취약점에 대한 프리미엄을 은밀히 인하합니다.
  • 긍정 시나리오(25%): LLM 벤더가 ‘공격적 코드’ 패턴에 대한 사용 정책을 강화하고 특정 권한을 요구합니다. LLM 지원 발견은 주로 합법적인 버그 바운티로 전환됩니다.
  • 부정 시나리오(15%): 자동화가 프라이빗/국가 행위자 측 장벽을 낮추고 CMS 패치가 따라가지 못합니다. 대규모 침해 급증이 발생합니다.

시사점

CISO에게 질문은 더 이상 “누가 나에게 RCE를 찾을 수 있는가”가 아니라 “어떤 비용으로 가능한가”입니다. 플러그인 개발자에게는 LLM 내부 감사가 보너스가 아니라 hygiene가 됩니다. AI 플랫폼에게는 ‘사용 정책’ 논리가 ‘강화된 접근 통제’ 논리로 대체됩니다. 하드웨어 키, 관할권, 검증된 엔티티(프론티어 접근 제어).

주시할 사항

  • Automattic의 반응 및 잠재적 CVE 발표
  • ‘LLM-처리 가능한’ 세그먼트에 대한 브로커 요금 조정
  • OpenAI의 Trusted Access와 유사한 장치를 Anthropic/Google로 확장 가능성
Resources

인공지능이 작성하고 사람의 편집 감독하에 검수한 기사입니다.

편집팀
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
이 기사가 도움이 되었나요?

19 명이 이 기사를 좋아합니다

좋아요
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
공유:
댓글 (10)

토론에 참여하려면 로그인하세요.

FoodieFiona 21 Jul 2026 · 14:28

AI's speed in finding vulnerabilities is impressive, but how will it handle false positives? Accuracy is key.

unLecteurCurieux 21 Jul 2026 · 17:21

False positives could be mitigated by combining AI with human expertise for validation.

BookWorm88 22 Jul 2026 · 08:13

Great point, but also consider the ethical implications of AI finding vulnerabilities before developers can patch them.

Alex 21 Jul 2026 · 14:03

This is fascinating! I wonder how AI will impact the job market for security researchers in the long run.

EcoWarrior99 21 Jul 2026 · 07:54

AI's role in finding vulnerabilities is exciting, but we must ensure it doesn't outpace our ability to patch them responsibly.

J.P.R. 21 Jul 2026 · 10:14

We need clear guidelines on AI's role in vulnerability disclosure to prevent misuse.

ArtLover88 21 Jul 2026 · 12:56

It's crucial to balance AI's speed in finding flaws with our capacity to fix them ethically.

curio_usa 21 Jul 2026 · 07:40

Incredible how AI is democratizing vulnerability discovery. But what about the potential for misuse by malicious actors?

HistoryBuff 2 21 Jul 2026 · 07:24

This is a significant development. I wonder how AI will change the dynamics of bug bounty programs and the roles of human researchers.

GreenThumb 21 Jul 2026 · 07:12

This is a game-changer. I hope AI can help us find vulnerabilities faster, but I'm concerned about the ethical implications of such powerful tools.

Dr. J. 20 Jul 2026 · 12:56

Wow, that's a huge payout for a vulnerability found with AI. I wonder how secure our websites really are if this is the future of exploitation.

TechSavvy 20 Jul 2026 · 12:35

Interesting find, but I wonder about the long-term implications for cybersecurity jobs if AI can outperform humans so easily.

ArtLover88 20 Jul 2026 · 12:18

This is fascinating, but I wonder how this will impact the vulnerability disclosure process and the relationship between researchers and platforms.

FilmBuffNYC 20 Jul 2026 · 12:10

This is a game-changer. I wonder how long until AI becomes the standard for vulnerability research.

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
토픽
탐색
정보