Three years ago we launched a bug bounty program to accelerate WordPress security research, and it has been incredibly successful and has since secured the WordPress community against 9,727 vulnerabilities reported through our program. We have thus far awarded a total of $981,251 to researchers around the world to reward the increased security they provide the WordPress community.

A year ago we extrapolated the progress in AI vulnerability research that we were seeing and realized that it would soon overtake human capability. We realized that, rather than allow a threat actor to lead innovation in vulnerability research, we needed to be the leaders. We started work on an AI vulnerability research project called PRISM, which we launched three months ago.

PRISM has produced 88 published vulnerabilities in the past 30 days, or an average of 2.8 vulnerabilities per day, purely autonomously. Wordfence PRISM has become our number 1 researcher in the past 30 days. It’s likely you will see that number continue to climb after we publish this post. To date, PRISM has discovered 202 vulnerabilities with several getting discovered every day.

Due to the volume of vulnerabilities that our Bug Bounty Program produces, we created an AI assisted triage tool called Eclipse, which has also helped us effectively triage output from PRISM. Eclipse triages vulnerabilities submitted by our human researchers, and by PRISM. This has massively accelerated our vulnerability pipeline, allowing for faster confidential disclosure to vendors, and faster release of firewall rules to our customers.

A New Threat Landscape

Our preparations to face this new threat landscape have yielded timely results. In the past weeks we have seen a prompt used for a math breakthrough adapted for use in vulnerability research, and within 10 hours produce one of the worst vulnerabilities in the history of WordPress core, and the first WordPress Core RCE in a decade.

Our team was able to respond as quickly as we did because our vulnerability analysis pipeline is AI assisted. In fact our researchers have become agentic coders. As they use Eclipse for triage, they also submit pull-requests to improve the product itself, thereby accelerating our agentic triage pipeline even further. This kind of massive organizational acceleration is what is needed to respond to the new threat landscape that is emerging.

In the past few days we have also seen Hugging Face compromised by a cybersecurity agent that OpenAI was testing, which broke out of its sandbox and compromised their partner’s systems. Both Anthropic and OpenAI are foundational AI providers, but have, as a side effect of their work, emerged at the forefront of cybersecurity as their models outpace human capabilities.

While the temptation to regulate access to these models exists, in the past week we have seen Chinese models Kimi K3 and Qwen 3.8 both emerge at the forefront of the AI leaderboards, rivaling the best that OpenAI and Anthropic have to offer. The USA does not have the ability to regulate Chinese providers. Furthermore, Kimi K3’s weights will be released on July 27th, making it impossible to regulate because at that point, anyone can download and run or distribute the model. Alibaba have indicated that Qwen 3.8 weights will also be released.

It also turns out that harness engineering can produce spectacular research results from models with modest parameter counts at a modest cost. We’ve seen this in our own research, and have seen it replicated elsewhere. Which means that, even if it was possible for a government to regulate away access to powerful Chinese and American models, the open-weights models that have already been released will continue to make breakthroughs in cybersecurity and other realms.

The process used in the math breakthrough that led to discovering the recent WordPress RCE vulnerability is a significant WordPress security research breakthrough. It was as a result of prompt engineering. It wasn’t just a powerful new model that took it upon itself to make this breakthrough. A researcher recognized a new prompt methodology used in mathematics that produced impressive results, and repurposed that for cybersecurity, leading to the breakthrough. Thus we can say that prompt engineering has now been legitimized as a field for innovation, and that the return on that research investment is clear.

How We’re Responding

So with multiple countries competing to out-innovate each other, open weights models being released at a rapid pace, the impossibility of AI regulation, and the breakthroughs coming from harness engineering and prompt engineering, how can cybersecurity defenders effectively respond in this adversarial environment?

At Defiant Inc, the company that makes Wordfence, we have always valued curiosity. We have assembled a team with the intellectual vigor to operate at the tempo that today’s adversarial environment requires. Our team has produced PRISM, Eclipse and many internal products that have improved efficiency and added new capability. We also spend a lot of time playing, simply because we can and we love it. Keeping this kind of innovation fun is what helps make it sustainable.

We know that to successfully defend against AI enabled attackers who are themselves engaging in sophisticated prompt and harness engineering, using the latest models, we must do so ourselves, and do it better and at scale.

This mirrors the environment we have always faced, with attackers and defenders having access to powerful technologies that allow both to operate at scale, with those capabilities and that scale constantly increasing. With AI we have seen a stair step up in capability for both attackers and defenders, and the only viable path for defenders is to step up. Then do it again, and again, responding to short term threats, but with long-range planning.

What You Can Do

These are times of great change, great innovation, but also anxiety and uncertainty. Our approach is to build. To innovate. And to have fun doing it. That has worked very well for us as the pace of innovation has increased, as has the volume of weekly reading material. I’ve built a software defined radio that is GPU accelerated, a flight planning agent, and a high frequency trading platform. These are all fields of research I have no business being in, because I lack the formal training one would normally need. And yet I’ve allowed myself to dream big and it has produced results I still find hard to believe.

Our team has built music software, software for the film industry, video games, and other projects, just for fun. When you have to read three new AI articles in a single morning just to stay ahead, it’s not that fun. When you’re reading them to figure out how to make Santa’s Sleigh explode into a shower of presents for a video game for your kids – well that’s a lot more fun and sustainable. (Hat tip Nick for that one)

So keep it fun, but dream big, and that will lead you to the jagged edge of this incredibly exciting time we find ourselves in, and empower with an understanding of the risks and opportunities. And it sure makes conversations at parties a lot more interesting.

What About the Humans?

I coined a term for a skilled agentic innovator in our organization about 18 months ago: Operator. An Operator is someone who can dream big, and manifest those dreams into reality using agentic coding, prompt engineering and harness engineering. Every member of our team today is an Operator. I could walk up to any Defiant Inc employee and ask them to build me a CUDA application in Rust to process network traffic, and they’d figure out how to make it happen, starting with asking their favorite agent what the heck the CTO is talking about, why they want it, and what success on the project looks like.

So what differentiates one Operator from another? It’s the fundamental non-coding and non-AI knowledge that the Operator brings to the task. Chloe Chamberland is one of the most credentialed security researchers in the world, which is how she was able to conceptualize and supervise the building of PRISM. Marco Wotschka is a very experienced security analyst, which is how he’s able to improve Eclipse as it triages vulnerabilities at scale, and submit PRs back to the team. Brad Osborne is an incredibly smart and creative marketer who has a clear vision of the outcomes he is working to produce, and Brad has built an entire marketing platform to accomplish those goals. Scott Miller heads our customer service, and knows the outcomes he wants to produce for our customers, and is able to create software to accomplish those goals.

Even our teams experiments with music production and other fun projects have fed innovation back into the business in the form of new agentic coding techniques and approaches.

A tragic outcome of this AI revolution is companies that naively thought that AI will be a drop-in replacement for humans, and then proceeded to lay off thousands. I wonder how many Operators they lost: People with a lifetime of specific knowledge that could have been put to work supervising a team of agents to produce valuable business outcomes and innovation that benefited customers.

The researchers that contribute to our bug bounty program are also becoming operators, and putting AI to work in ways that we have not thought of. They may build a more effective harness, or, as happened last week, engineer a new prompt that produces profound new security breakthroughs. We’re optimistic that the security community will embrace this new way of working, and will continue to produce breakthroughs that help secure the WordPress community.

Looking Forward

The future may be uncertain, but the rapid pace of change and innovation is a certainty. We choose to embrace that with a sense of curiosity, excitement and optimism. We’re going to continue having fun, and feeding our research and breakthroughs into products and processes that secure the WordPress Community.

And when it comes to WordPress security in this uncertain world: Wordfence and the team at Defiant Inc has your back.

Mark Maunder – Wordfence Founder and Chief Technology Officer

The post A New Threat Landscape Meets A New Kind of Defender appeared first on Wordfence.