AI Briefing
KOSign in

Frontier AI Models Accelerate Vulnerability Discovery, With GPT 5.6 Sol Finding Pre-auth RCE in WordPress Core

·2026.10.09 16:00

Key point

GPT 5.6 Sol independently discovered a critical pre-auth RCE in WordPress Core after 6–10 hours of unsupervised work.

Details

Frontier AI models are significantly accelerating offensive security research, with GPT 5.6 Sol demonstrating the ability to find complex critical bugs with minimal supervision. Released in July 2026, this model identified a pre-auth RCE in WordPress Core (wp2shell) after running for 6–10 hours independently from a prompt adapted from OpenAI's mathematical reasoning tasks.

Evolution of AI in Security Research

Earlier models like Claude Opus 4.6–4.8 allowed researchers to 10x their output, but required careful steering and supervision. A Harvard physicist assessed these earlier iterations as having capability comparable to a second-year graduate student. The release of GPT 5.6 Sol marks a shift toward autonomous discovery of high-severity vulnerabilities.

Implications for Software Security

Security teams are now leveraging these capabilities to hunt for "internet melting bugs" proactively, aiming to patch them before malicious actors can exploit them. The author predicts a period of increased vulnerability disclosures as old software persists and existing bug classes remain relevant. However, there is optimism that new software developed with AI assistance may ultimately prove more secure.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.