<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — ai</title><link>https://exploit-intel.com/blog/tags/ai/</link><description>EIP research articles tagged ai.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/ai/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Thu, 13 Aug 2026 20:23:48 -0400</lastBuildDate><item><title>EIP v3: The Exploit Database We Meant to Build</title><link>https://exploit-intel.com/blog/posts/eip-v3-the-exploit-database-we-meant-to-build/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/eip-v3-the-exploit-database-we-meant-to-build/</guid><description>EIP v3 is a rebuilt exploit intelligence system with searchable PoC code, a public read-only API, CLI and MCP, and a review-gated Kimi/Ollama pipeline that publishes CVE labs into the corpus.</description><pubDate>Thu, 13 Aug 2026 19:53:09 -0400</pubDate></item><item><title>WP Google Map Plugin - Three Weak Links, One Critical Chain</title><link>https://exploit-intel.com/blog/posts/wp-google-map-plugin/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/wp-google-map-plugin/</guid><description>Line 781 says $query_to_run is safe. It isn't. An autonomous pipeline found a CVSS 9.8 unauthenticated SQL injection in WP Google Map Plugin v4.9.1 -- a three-link chain of individually harmless components that, together, give any visitor full database access. Then we kept reading and found the plugin deserializes update-check responses from an external server with maybe_unserialize(). 200,000+ active installs. 35 minutes. $8.97.</description><pubDate>Sun, 29 Mar 2026 00:00:00 -0400</pubDate></item><item><title>CVE-2026-4105: systemd-machined Privilege Escalation - 72 Minutes from Drop to Bypass</title><link>https://exploit-intel.com/blog/posts/cve-2026-4105-systemd-machined-privilege-escalation/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-4105-systemd-machined-privilege-escalation/</guid><description>CVE-2026-4105 dropped this morning - local privilege escalation to root on desktop Linux via systemd-machined. Two D-Bus calls, no authentication. We fed it to CVEForge before the advisory was an hour old. Seventy-two minutes later: confirmed exploit, Docker labs for vulnerable and patched builds, and a bypass proving the vendor's fix is incomplete. The analysis agent said the fix was thorough. The bypass agent proved it wrong.</description><pubDate>Fri, 13 Mar 2026 22:00:00 -0400</pubDate></item><item><title>CVE-2026-28391: OpenClaw Command Injection - The Day I Hacked Myself</title><link>https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</guid><description>CVE-2026-28391 is a CVSS 9.8 command injection in OpenClaw &lt; 2026.2.2, caused by a POSIX vs cmd.exe shell-parsing mismatch. Our own suggestion algorithm ranked it as the most interesting CVEForge target. 8/8 bypass vectors confirmed, code execution verified. This is the story of the day our orchestration layer dispatched a full vulnerability assessment against itself.</description><pubDate>Mon, 09 Mar 2026 12:00:00 -0400</pubDate></item><item><title>Introducing FuzzForge: Autonomous Source-Code Fuzzing - Finding Bugs in nginx in 112 Minutes</title><link>https://exploit-intel.com/blog/posts/introducing-fuzzforge-autonomous-source-fuzzing-nginx/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/introducing-fuzzforge-autonomous-source-fuzzing-nginx/</guid><description>We forked Shannon a third time. Seven AI agents, source code as the starting point, sanitizer-instrumented builds, and a pipeline that read 259 C files, built its own fuzzing harnesses, ran 18,000 iterations, and found a previously unknown FastCGI protocol desynchronization bug in nginx. Two hours. Twenty-five dollars.</description><pubDate>Sun, 08 Mar 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-68670 Part 2: From Crash to RCE - The One That Fought Back (and Lost)</title><link>https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-from-crash-to-rce-the-one-that-fought-back/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-from-crash-to-rce-the-one-that-fought-back/</guid><description>The first post ended with 'not a shell.' This one ends with uid=0(root) - with an asterisk. Ten context windows. A UTF-8 encoding barrier that blocks every libc address. A PLT mapping that lied. A stack alignment problem solved by a NULL pointer and a filename that shouldn't exist. The story of how a pre-auth xrdp overflow became (almost) pure-network RCE - through the most absurd gadget chain we've ever built.</description><pubDate>Wed, 04 Mar 2026 22:00:00 -0400</pubDate></item><item><title>CVE-2025-68670: Pre-Auth xrdp Overflow - The One Where the Protocol Fought Back</title><link>https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-pre-auth-overflow-the-hard-one/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-pre-auth-overflow-the-hard-one/</guid><description>xrdp. Pre-authentication. A full RDP handshake implemented from scratch. UTF-8 encoding constraints that break your ROP chain. A false crash path that wasted hours. And a 3-byte partial overwrite technique that reaches any address in the binary. Stackforge's hardest target yet - and the most honest result.</description><pubDate>Wed, 04 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-62507: Redis Stack Overflow to RCE in 68 Minutes  -  Then We Turned ASLR On</title><link>https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</guid><description>The public material available during this CVE-2025-62507 run was a crash PoC. StackForge pursued RCE, then repeated the work with ASLR enabled.</description><pubDate>Tue, 03 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-15467: From OpenSSL Stack Overflow to Three ROP Chains in 64 Minutes  -  Introducing Stackforge</title><link>https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</guid><description>We forked Shannon again  -  this time for binary exploit development. Nine AI agents, GDB as an MCP tool, packet capture via SharkMCP, and a pipeline that turned an OpenSSL stack buffer overflow into three independent ROP chains with GDB-verified RCE. Eighty-five minutes. Twenty-five dollars. Here's how Stackforge works.</description><pubDate>Tue, 03 Mar 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-26866: From Undocumented Binary Protocol to Root Shell - AI Agent Meets Java Deserialization</title><link>https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</guid><description>CVE-2025-26866 is a Hessian deserialization RCE in Apache HugeGraph PD. Our autonomous exploit pipeline CVEForge - which had completed 56 consecutive CVEs - hit a wall: an undocumented binary protocol, a non-standard serialization format, and a class blacklist blocking every known gadget chain. The agent spent $49 and four hours reverse-engineering SOFABolt, mapping sofa-hessian byte by byte, and finding a JDK-only gadget chain to bypass the blacklist. Then we took over to turn file creation into a proper root shell - navigating JNDI hardening, CC library defenses, and a gadget chain that silently dies on modern JDK. The result: a full Metasploit module.</description><pubDate>Sun, 01 Mar 2026 18:00:00 -0400</pubDate></item><item><title>72 Hours, 24 CVE Proof of Concept Exploits, and 8 Disclosure Submissions: The CVEForge Stress Test</title><link>https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</guid><description>We left CVEForge running for three days. Twenty-four CVEs went in. All twenty-four produced working PoCs. Ten incomplete fixes triggered eight responsible disclosure submissions - six GitHub issues, one MITRE report, one HackerOne 0-day. Here's the full accounting.</description><pubDate>Sat, 28 Feb 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-60355 (OneBlog): CVEForge Finds 3 Bypass/Incomplete Fixes in 5 CVE Runs</title><link>https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</guid><description>In this CVEForge patch-validation run, we analyze CVE-2025-60355 in OneBlog (Java/FreeMarker) and compare outcomes across five CVEs. Three of five runs ended in confirmed bypass or incomplete-fix results.</description><pubDate>Fri, 27 Feb 2026 12:00:00 -0400</pubDate></item><item><title>Zero to RCE: Autonomous Exploit Development Across Three Vulnerability Classes</title><link>https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</guid><description>After CVEForge's first successful run, we needed to know if it was luck or a pattern. Two more CVEs, zero hand-holding, and an AI agent that found a fix bypass the developers missed.</description><pubDate>Thu, 26 Feb 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-53833: Autonomous PoC Generation with CVEForge - From CVE Number to Root Shell in 32 Minutes</title><link>https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</guid><description>We forked Shannon - the open-source AI pentesting framework - and wired it to the EIP MCP server. Six AI agents, one CVE number, 32 minutes: a working RCE PoC for a CVSS 10.0 vulnerability with zero existing public exploits. Here's how it happened.</description><pubDate>Wed, 25 Feb 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2026-28296: From CRLF Injection PoC to Fix Bypass - One Prompt, One AI Agent</title><link>https://exploit-intel.com/blog/posts/from-cve-to-bypass-with-mcp/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/from-cve-to-bypass-with-mcp/</guid><description>One prompt kicked off an AI agent that built a full PoC lab for CVE-2026-28296 - and discovered the GVFS CRLF injection fix was incomplete. Here's how it happened.</description><pubDate>Tue, 24 Feb 2026 12:00:00 -0400</pubDate></item><item><title>Introducing the EIP MCP Server - Vulnerability Intelligence for AI Assistants</title><link>https://exploit-intel.com/blog/posts/introducing-eip-mcp-server/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/introducing-eip-mcp-server/</guid><description>The story behind EIP MCP, with current setup guidance: tell your agent to connect to the hosted endpoint, or install the optional local eip-mcp package through pipx.</description><pubDate>Fri, 20 Feb 2026 12:00:00 -0400</pubDate></item><item><title>Anatomy of a Trojan Exploit - How We Detect Backdoored PoCs with AI</title><link>https://exploit-intel.com/blog/posts/anatomy-of-a-trojan-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/anatomy-of-a-trojan-exploit/</guid><description>Concrete examples of credential stealers, obfuscated backdoors, and destructive payloads found in public PoC material, with model interpretation kept separate from EIP safety claims.</description><pubDate>Sun, 15 Feb 2026 12:00:00 -0400</pubDate></item></channel></rss>
