8 ms·
There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they ar
by Zsfe510asG 2mo ago
There is no evidence that $500k has been paid or would be paid for an exploit like this one.
Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k.
The author works for https://www.assetnote.io/ https://www.assetnote.io/ , which has AI products for automated scanning.
- functionmouse 2mo ago[flagged]
- kuroguro 2mo agoLikely referencing https://www.crowdfense.com/exploit-acquisition-program/ https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zerodium_WordPress_exploit.png https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.
- tptacek 2mo ago[flagged]
- StrauXX 2mo agoOf course it is. It just no longer exists.
- tptacek 2mo agoOh, you've done business with them then? Know someone who has?
- jnbcxdrun 2mo ago[dead]
- cmeacham98 2mo agoYes actually, I know someone who did business with them many years ago (before the advent of LLMs), although for a smaller sum than the advertised top payouts (the vulnerability they had was much less important). Why post these random unsubstantiated claims on HN?
- close04 2mo ago> Why post these random unsubstantiated claims on HN? To show everyone the Gell-Mann amnesia effect in action. When HN top karma poster and security professional posts something like this, doubles down, and can’t even be bothered to support it in any way (I’m open to learning and changing my opinion) it completely blurs the line going into social media influencer. Quantity over quality.
- StrauXX 2mo agoI do, as a matter of fact.
- monster_truck 2mo agoMy lawyer says I can't answer that
- parl_match 2mo agoYes, I have briefly done business with them as well. We also worked with Bekrar and Vupen briefly. Albeit, it was done through a broker. The second time around, we exited negotiations. Just because they're exclusive about their clients doesn't mean they're not real. Their impact and effectiveness is a separate topic though. I don't think they're still actively operating or taking new clients, at least. btw: "Oh, so you've done x?" What a snarky and confrontational way to ask someone something. Especially when it's asserting a well documented company and person is "not real".
- 2mo ago
- ofjcihen 2mo agoWhy would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist? I’m just baffled.
- dadrian 2mo agoThe pricelist was a marketing stunt.
- intheitmines 2mo agoIs there anywhere currently buying that you can approach without a pre-existing relationship?
- StrauXX 2mo agoMaybe the MEA brokers still are. But don't if you live in the west.
- Hizonner 2mo agoWhy would anybody trust criminals to pay them over time?
- idiotsecant 2mo agoBecause if they don't other people will hear they don't pay and won't sell them 0days
- nativeit 2mo agoHow long do you figure a criminal reputation typically needs/wants to last? I have always been skeptical of “black market credit ratings”. If you happen to build one up, it’s likely only in order to rip someone off at a higher price and cash in the value of it. It’s not like you’ll need that good rep for your retirement.
- applfanboysbgon 2mo agoShinyHunters has been "in business" since 2019 and it is their reputation that resulted in eg. Canvas paying their ransom this year. Without that reputation, it is unlikely a large-scale ransom would have been paid, because the reputation is what gives them credibility that paying the ransom will actually result in the promise being upheld.
- bink 2mo agoI work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).
- apercu 2mo ago>There's absolutely nothing of value on any Word Press site. I would hope not, but I’d be surprised if that were true across the millions(?) of Wordpress sites?
- tedggh 2mo agoI currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.
- soulofmischief 2mo agoAnd never underestimate the competence of others.
- kulahan 2mo agolol, a big part of security is being smart enough to never challenge the bored…
- marysol5 2mo agoSurprising amount of gov use WP as a CMS on their websites. So it's not that far off.
- madaxe_again 2mo ago
- T3RMINATED 2mo ago[dead]
- nativeit 2mo ago> modified like they are holy scripture So never modified at all, even if plainly contradictory and/or ethically and morally compromised?
- stellamariesays 2mo ago[flagged]
- trollbridge 2mo ago"People paid $5,000 for a Macintosh computer when they were new. I found one at a yard sale for $25."
- grugq 2mo agothis is the most accurate summary.
- trollbridge 2mo agoI actually found a 1999 iMac set out for a special rubbish pick up day. The owner of the house was there so I chatted a bit, asked her if she minded if I took it. It had last been booted on it, complete with working hard drive an; MacOS X 10.3. So $1.299 -> $0.
- SoftTalker 2mo agoThat's just typical for computer hardware though. Depreciation is 3-5 years normally, after which it's considered worthless.
- sgerenser 2mo agoPre-1990s Macs (Mac Plus, SE, etc.) in good condition are actually worth a decent amount nowadays as collectors items. Not $5000, but quite a bit more than $25.
- monster_truck 2mo agoWhat do you think the venn diagram looks like for people willing and able to find things like that prior to LLMs and also sell them to a broker, and are also stupid enough to flaunt a massive flashing "arrest me!!!" sign Closest you're going to get is something like those kids in florida who just got wrapped for putting malware into steam games and draining peoples accounts. They were going to get caught anyways but it would have taken a lot longer to build a case against them if they weren't flaunting it on socials
- nickff 2mo agoIs this comment pure speculation, or do you have knowledge (or anecdotal evidence) of a similar exploit being sold for $500k?
- monster_truck 2mo agoI can't answer that, did you have something you'd like to sell?
- deleted 2mo ago[deleted]
- dang 2mo agoOk, we've taken $500k out of the title above.