bleeping-computer · Crawled Jul 15, 2026

We built a vulnerability vending machine: AI tokens in, zero-days out

Read original article ↗

AI Summary

Intruder's AI-powered vulnerability research pipeline, combining code scanning with large language models, discovered a high-impact blind SQL injection vulnerability (CVE-2026-3985) in the Creative Mail WordPress plugin. The vulnerability allows unauthenticated attackers to extract sensitive database information, including admin password hashes and secret tokens, when WooCommerce is also installed. The exploit chain requires multiple requests and was automatically discovered and validated using AI, demonstrating the growing capability of AI in both offensive and defensive security research.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.