🚨 ACTIVE EXPLOITATION
- Exploit brokers pay $500,000 for a WordPress RCE found using GPT5.6 AI — slcyber.io
Exploit brokers are paying $500,000 for a zero-day WordPress remote code execution exploit discovered using GPT5.6 Sol Ultra AI with multi-agent code analysis over 6 hours.- Applies to WordPress instances in typical production deployments with MySQL
- Vulnerability allows pre-authentication remote code execution (RCE)
- Independent researchers Calif and Hacktron reproduced the exploit chain before public PoCs
📋 ADVISORIES
- Google Chrome 150 Update Fixes Seven Critical Memory Safety Vulnerabilities — SecurityWeek
Google patched seven critical and high-severity memory safety bugs in Chrome 150 on Windows, macOS, and Linux.- Fixes three critical use-after-free flaws in CameraCapture, GPU, and Network components
- Addresses three high-severity use-after-free issues in Cast, Ozone, and Aura components
- Patches an out-of-bounds read/write flaw in the V8 JavaScript engine discovered by OpenAI Codex Security
- No evidence of exploitation in the wild reported; vulnerabilities discovered mainly by Google
🔓 CVEs & KEV
- 21 CVEs reported with the worst scoring 9.4 in severity.