Miggo · July 2026 Every WordPress Site's Nightmare: Pre-Auth RCE via wp2shell A SQL injection in WP_Query (CVE-2026-60137) chained with a REST batch route confusion auth bypass (CVE-2026-63030), turning a single anonymous request into unauthenticated RCE on a stock WordPress install. Miggo · May 2026 The Death of "Patch First": Exploiting and Mitigating Drupal CVE-2026-9082 under 60 Minutes Built a working exploit for a Drupal CVE in under an hour using AI, and what that speed means for modern vulnerability disclosure. Miggo · 2026 Blind the Watcher: Stopping the Unauthenticated Splunk RCE (CVE-2026-20253) Before the Patch Lands Analysis of a critical unauthenticated RCE in Splunk Enterprise via an exposed PostgreSQL sidecar endpoint, with runtime defense strategies. 2nd Place Apart Research · Heron · AI Control Hackathon · March 2026 Detecting LLM Subversion in Vulnerability Patching Settings A weekend research sprint introducing Vul4Control, a framework for detecting subtly malicious security patches proposed by misaligned LLMs.