In 2016, I made a post to Reddit that #WordPress (and other CMSs) need a proper vulnerability management tool and an effective way to prevent attacks against vulnerabilities in plugins. Here's what happened 馃У1/6
We're living through a double-slit experiment at @patchstackapp. We recently made a decision to put our entire focus on web hosting partnerships. As a result, our direct SaaS sign-ups (from where we took the attention away) monthly volume have grown 2X in the past 3 months. 馃槄
If you only test an AI pentesting agent once, you are standing right on the edge of a cliff, completely blind to the drop below. 馃憖
Because LLMs are probabilistic, their outputs change from run to run. In complex agentic pentesting, small shifts in early exploration multiply,
鈿★笍WordPress #wp2shell got exploited fast! We also uncovered industry wide WAF bypass which we reported to security vendors and to the WordPress security team to coordinate the fixes. As of publishing this analysis, this bypass is now being actively used.
So a frontier lab accidentally hacked a company with one of their models. Meanwhile the company can鈥檛 even do forensics with the same models because of safety guardrails. Open source models are the only option for defenders to fight against AI.