
You Can’t Just Publish Partial Exploits Anymore
A ‘safely’ disclosed WordPress RCE, taken most of the way to a full unauthenticated exploit chain with public research and an LLM, and the rest with a public PoC.
Ryan Basden on offensive security, and the distance between what companies believe about their defenses and what happens when someone tests them. Published first at ryanbasden.com.
Live Last read · last published · next check

A ‘safely’ disclosed WordPress RCE, taken most of the way to a full unauthenticated exploit chain with public research and an LLM, and the rest with a public PoC.

Challenge your mental model of how attackers work before it's too late.

Your ultimate guide to guaranteeing one of security's most beneficial exercises does nothing for you.

Are physical security assessments a fun novelty? Or are fewer businesses taking them as seriously as they should?

Despite the millions upon millions of dollars thrown at penetration testing ever year, big data breaches are still as common as ever.

At this point, it's hurting more than helping.

An introduction to Empiric Security. Let's get real.