I think the most accurate phrase for the time we live in right now in offensive security, bug bounties, and vulnerability research is "the age of collisions" - what an exciting time, well, not really for those who had a monopoly on certain bugs
Things are getting weird (or interesting?) in the vulnerability research space. I published some of my personal thoughts on what we're seeing and what our broad strategy is here:
v12 has been finding some pretty good bugs. a good product with a team that understands offensive security. i’m sure many more fun disclosures to come.
Note on WordPress pre-auth RCE (CVE-2026-63030). There are SQLi poc's out there, but RCE PoC has not yet been exploited in the wild. Will only release our technical post if we have proof of exploitation. Our RCE payload does NOT require poorly configured MySQL.