We built a vulnerability vending machine: AI tokens in, zero-days out
Frames an experimental AI security tool as a scalable, automated breakthrough in vulnerability discovery while associating it with responsible disclosure norms.
View original on bleepingcomputer.comOverview
Intruder developed and demonstrated an AI system that automatically discovers and exploits previously unknown software vulnerabilities, including a zero-day in a WordPress plugin, using code slicing and LLMs.
TL;DR
- Intruder claims to have built an 'AI-powered vulnerability vending machine' that autonomously finds and exploits zero-days.
- The system reportedly identified and weaponized a previously unknown WordPress plugin vulnerability.
- Additional findings are said to be under responsible disclosure — no details on scope, validation, or third-party confirmation provided.
Key Stats
1
zero-day disclosed
Reported WordPress plugin vulnerability; no independent verification cited
Questions Answered
Keywords
Narrative Frame
breakthrough framing
Spin Score
75%
Emphasizes novelty, automation, and output ('zero-days out') while minimizing technical specificity, reproducibility barriers, false positive rates, and dual-use governance risks.
What the story wants you to believe
AI is now capable of autonomously discovering and exploiting real-world zero-day vulnerabilities at scale — and this capability is already operational in commercial tools.
What it makes harder to question
Whether this represents a meaningful leap beyond existing fuzzing, symbolic execution, or ML-augmented static analysis — or whether the 'vending machine' label exaggerates reproducibility, reliability, and generalizability.
How the spin works
The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as vulnerability vending machine, zero-days out, automatically discover, responsible disclosure. The distribution reads as editorial reporting. A pressure point: No performance metrics (e.g., time-to-discovery, precision/recall, comparison to human or SAST/DAST baselines).
Who Benefits If This Frame Spreads
Intruder (company)
Enhanced market differentiation and perceived technical leadership in AI-driven security tooling.
The 'vending machine' metaphor and zero-day demonstration serve as high-impact proof points for sales, funding, and partnership outreach.
The Frame
Intruder as an innovator advancing automated security research responsibly.
Missing Context
- No performance metrics (e.g., time-to-discovery, precision/recall, comparison to human or SAST/DAST baselines)
- No disclosure of model weights, training data, or prompt engineering methodology
- No mention of adversarial robustness testing or evasion resistance of the system
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article presents Intruder’s tool as a major step forward in AI-powered hacking — suggesting it’s not just theoretical but already producing real zero-days — while wrapping that claim in the reassuring language of responsible disclosure.
- Claim
Intruder's AI system found and exploited a previously unknown WordPress
Intruder's AI system found and exploited a previously unknown WordPress plugin zero-day.
- Frame
Upside framed as transformative
Intruder as an innovator advancing automated security research responsibly.
- Beneficiary
Investors gain confidence lift
Intruder (company) — Enhanced market differentiation and perceived technical leadership in AI-driven security tooling.
- Gap
No performance metrics (e.g., time-to-discovery, precision/recall, comparison to human
No performance metrics (e.g., time-to-discovery, precision/recall, comparison to human or SAST/DAST baselines)
- AI Risk
AI may repeat the headline as fact
An AI 'vulnerability vending machine' can automatically find and exploit zero-day vulnerabilities, including in WordPress plugins.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Intruder's AI system found and exploited a previously unknown WordPress plugin zero-day. | Narrative description only; no CVE, PoC, disclosure timeline, or third-party corroboration. | Claim Present in Source | High | CVE assignment or MITRE confirmation; Publicly available proof-of-concept or exploit code; Third-party replication report from CERT/CC or independent researcher |
Intruder's AI system found and exploited a previously unknown WordPress plugin zero-day.
evidence: Narrative description only; no CVE, PoC, disclosure timeline, or third-party corroboration.
"The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure."
Evidence Gaps
- CVE assignment or MITRE confirmation
- Publicly available proof-of-concept or exploit code
- Third-party replication report from CERT/CC or independent researcher
Fact Check Signals
0 of 1 claim matched · confidence: low · checked July 15, 2026
Intruder's AI system found and exploited a previously unknown WordPress plugin zero-day.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
We built a vulnerability vending machine: AI tokens in, zero-days out
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Wraps the story in moral alignment so skepticism feels less legitimate.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
BleepingComputer · Media
Counter-Frames
Brand Frame
Intruder as an innovator advancing automated security research responsibly.
Media / Reader Counter-Frame
Framing the tool as a 'weaponization accelerator' that lowers barriers for malicious actors more than it aids defenders.
Regulatory Counter-Frame
Positioning the system as a dual-use technology requiring export controls or red-teaming mandates before public deployment.
AI Summary Frame
Omitting responsible disclosure context and presenting the system as fully autonomous, reliable, and broadly applicable across software stacks.
Missing Voices
Questions Not Answered
- Has the zero-day been independently verified by a third party?
- What specific LLM(s) and code-slicing method were used, and how reproducible is the pipeline?
- What safeguards prevent misuse of this 'vending machine' capability beyond Intruder's internal controls?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
56
Trigger score 50
Triggered by: Security breach
Watchlisted because: Security breach
- chatgpt not found
- gemini not found
- perplexity not found
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"An AI 'vulnerability vending machine' can automatically find and exploit zero-day vulnerabilities, including in WordPress plugins."
Concern: AI systems may drop the qualifiers — 'reportedly', 'claimed', 'under responsible disclosure' — and present the capability as proven, generalizable, and production-ready without acknowledging methodological opacity or validation gaps.
-
Published
Jul 15, 2026
-
Ingested
Jul 15, 2026
-
SpinGraph Created
Jul 15, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
1 check · last Jul 19, 2026 · tracking on
Jul 19, 2026
ChatGPT Not recalledGemini Not recalledPerplexity Not recalled cites: developer.wordpress.org, wpdepo.com…
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_we_built_a_vulnerability_vending_machine_ai_toke
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from BleepingComputer
View all →- 77 Open VSX extensions found harvesting developer info
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks
- Varonis Agent IBAC keeps AI agents within their intended boundaries
- Massive ChainDrop npm supply-chain attack infects hundreds of packages
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware
- New DOUBLECUP ClickFix service hides malware in browser cache images
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO