Key Points
Welcome to issue #9 of The Vulnerabulletin — a care package of security research, Intruder news and curated headlines delivered right to your desk.
This month we're asking the questions that matter most about AI pentesting — and actually answering them. Our Chief Security Technologist Andy Hornegold is tackling everything you've wondered about using AI pentesting for web apps. Meanwhile, our CEO Chris Wallis is making the case in teiss that the real opportunity isn't always to "scan more often" — it's rethinking when and why testing happens in the first place. And in between all the big picture thinking, our security team got stuck in with wp2shell, a pre-auth RCE chain in WordPress core that Cloudflare's own WAF rule was accidentally hiding from scanners — making vulnerable servers look patched when they weren't. All that, plus memes, stories and features hotter than the summer weather.
We answer your burning questions about AI pentesting 🔥
Does AI pentesting hallucinate? Is is safe to run? Is it better than a human pentester?
Pentests are expensive, slow to procure, and most teams can only justify one a year. AI pentesting changes all of that — but it raises a lot of questions too. Ever wondered what's actually happening under the hood, or what vulns AI pentesting can actually find?
Ponder no longer! Our Chief Security Technologist Andy Hornegold has all the answers and we've compiled them for easy reading.

wp2shell: the flaw hiding in plain sight 💀
A WAF can make a vulnerable server look patched. That's exactly what happened this month.
wp2shell is a pre-auth RCE chain in WordPress core that was disclosed just over a week ago. Cloudflare pushed a rule to block it, but that same rule also stopped scanners from seeing the flaw sitting behind it — this meant plenty of vulnerable servers were reading as safe.
Our security team found a workaround: one tweak to the payload and we bypass the WAF, flagging vulnerable servers even with Cloudflare in front.
Dive into our full write-up below to learn more, including why we ended up shipping three separate checks for this one vulnerability.

AI pentesting: a step towards continuous security 🤖
"If you remove the human from a penetration test, what you have is a very smart scan. The more interesting question is what sits between the two?” — that's the question our CEO Chris Wallis explores in a new piece for teiss.
When vulnerabilities get weaponized in hours, a test that happens once a year tells you what was exploitable on one day out of 365. But the answer isn’t simply “scan more often”, it’s rethinking when and why testing happens.
Read Chris’ piece in teiss below.

The Vulnerabulletin Board 📌
What our security team has been reading (and meme-ing) this month...
👨💻 The teenager who caused chaos for Transport For London (London Centric) - The wild story of how one food delivery took down the infamous millionaire teen hacker who honed his craft playing Roblox.
🔓 Are there covert encoding signals inside Claude Code? (International Cyber Digest) - Allegations that recent versions of Claude Code were covertly encoding signals about users' network setup into system prompts, by hiding environmental metadata in places users can't easily inspect.
📒 Critics of MSG's facial recognition tech documented by venue (404 Media) - The revelation that critics who publicly opposed Madison Square Garden's use of facial recognition technology were complied into an internal dossier by the venue which was then shared amongst staff.
🏆 Our meme of the month:

What's new in Intruder 💡
🚀 AI pentesting for web apps - Find what manual pentests miss. We built on-demand AI pentesting to help you keep up — launch a test in minutes and get an audit-ready report the same day.
✨ Free Plan - You can now use Intruder for free. Forever. Find real exposures, validate fixes, and keep an eye on the basics without adding another line to the budget.
Hot off the keypress 🗞️





