View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Exploit brokers pay $500,000 for a WordPress RCE found using GPT5.6 AI

🚨 ACTIVE EXPLOITATION

  • Exploit brokers pay $500,000 for a WordPress RCE found using GPT5.6 AI — slcyber.io
    Exploit brokers are paying $500,000 for a zero-day WordPress remote code execution exploit discovered using GPT5.6 Sol Ultra AI with multi-agent code analysis over 6 hours.
    • Applies to WordPress instances in typical production deployments with MySQL
    • Vulnerability allows pre-authentication remote code execution (RCE)
    • Independent researchers Calif and Hacktron reproduced the exploit chain before public PoCs

📋 ADVISORIES

  • Google Chrome 150 Update Fixes Seven Critical Memory Safety Vulnerabilities — SecurityWeek
    Google patched seven critical and high-severity memory safety bugs in Chrome 150 on Windows, macOS, and Linux.
    • Fixes three critical use-after-free flaws in CameraCapture, GPU, and Network components
    • Addresses three high-severity use-after-free issues in Cast, Ozone, and Aura components
    • Patches an out-of-bounds read/write flaw in the V8 JavaScript engine discovered by OpenAI Codex Security
    • No evidence of exploitation in the wild reported; vulnerabilities discovered mainly by Google

🔓 CVEs & KEV

  • 21 CVEs reported with the worst scoring 9.4 in severity.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check