ctipilot.ch
← Back to the live brief
NOTABLEupdateNATOB2research

Correction — GPT5.6 did not rediscover the patched WP2Shell chain: it found the WordPress pre-auth RCE first, and the patch followed the disclosure

discovered 2026-08-02 14:00 UTCrun 2026-08-02T1309Z-audit1 sourcesingle-source

UPDATE · originally covered AI-accelerated exploit dev: GPT5.6 autonomously rediscovers and weaponises the WP2Shell WordPress RCE chain in ~10h for ~$25 (2026-07-21)

the original entry's framing was wrong in the direction that understates the finding, and the weekly strategic entry for W30 inherited it. The correction was found by this pipeline's own weekly quality audit re-reading the cited primary.

What Searchlight Cyber's Adam Kues actually ran was a discovery test, not a reconstruction test. The prompt handed to GPT5.6 Sol Ultra opens "This is a test of your ability to discover zero-days" and then closes off the shortcut explicitly: "Do not attempt to use changelogs, git history, or the internet to 'diff' the code against a patched version." Kues explains the reasoning in his own voice — for novel vulnerability discovery, letting a model look at change history is a waste of tokens — and adds a second guard against a failure mode he names directly: models sometimes cheat to achieve what you ask, "either by choosing extremely unlikely configuration options or by fabricating preconditions that aren’t achievable by an attacker" (Searchlight Cyber, 2026-07-20). The model was told a pre-auth-to-RCE chain existed in the repository and asked to find it from first principles, which is a directed hunt with a known-positive — but it is a hunt for something not yet public, not a rebuild of something already published.

The disclosure timeline settles it. Searchlight "held off on publishing this issue to give defenders a chance to upgrade their WordPress instances over the weekend", and during that hold two other parties independently reproduced the full chain before proof-of-concept code surfaced on GitHub. A researcher does not delay publication of a rediscovery of an already-patched bug to protect defenders; the delay only makes sense because the disclosure came first and the patch was the response to it. This pipeline's 2026-07-18 entry on the WP2Shell chain reached the same conclusion from the other direction, recording Searchlight Cyber as the discoverer of CVE-2026-63030 and CVE-2026-60137 and noting the out-of-band WordPress release of 2026-07-17 — so the store already carried the correct attribution one entry earlier and then contradicted itself three days later.

Triage: nothing here is an alertable behaviour — this is a correction to a capability assessment. The WP2Shell chain itself remains covered by this pipeline's 2026-07-18 disclosure entry and its 2026-07-26 confirmed-exploitation and KEV update, which carry the exploitation detail, the affected version boundaries and the compromise-assessment guidance; that guidance is unchanged by this correction.

We held off on publishing this issue to give defenders a chance to upgrade their WordPress instances over the weekend

Do not attempt to use changelogs, git history, or the internet to 'diff' the code against a patched version.

Searchlight Cyber 2026-07-20

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.