home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

fetched live
  1. We have hit our limit of registrations for #Pwn2Own Ireland. It looks like it will be an amazing contest (with multiple phone entries!). Stand by for further details.... #P2OIreland

  2. We have hit our limit of registrations for #Pwn2Own Ireland. It looks like it will be an amazing contest (with multiple phone entries!). Stand by for further details.... #P2OIreland

  3. We have hit our limit of registrations for #Pwn2Own Ireland. It looks like it will be an amazing contest (with multiple phone entries!). Stand by for further details.... #P2OIreland

  4. We have hit our limit of registrations for #Pwn2Own Ireland. It looks like it will be an amazing contest (with multiple phone entries!). Stand by for further details.... #P2OIreland

  5. We have hit our limit of registrations for #Pwn2Own Ireland. It looks like it will be an amazing contest (with multiple phone entries!). Stand by for further details.... #P2OIreland

  6. CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  7. CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  8. CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  9. CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  10. CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  11. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  12. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  13. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  14. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  15. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  16. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  17. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  18. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  19. BBC News | Champion ethical hacker warns AI tools like Mythos will make competing harder

    AI generated summary, Read the full article for complete information.

    Champion ethical hacker Valentina Palmiotti, known as “Chompie,” won the 2024 Pwn2Own Berlin competition by exploiting systems for prize money, but she warns that powerful new AI tools such as Anthropic’s Claude Mythos could soon make human‑only hacking contests impractical. While AI assistants like Claude Code currently help her and other researchers work faster, the emergence of more advanced models promises to automate many “lower‑hanging‑fruit” bugs, leaving only the very best hackers able to discover novel vulnerabilities. Fellow champion Orange Tsai sees AI as a useful research aid that can free up time but believes human creativity will still be essential. Both experts agree that if AI‑driven tools are responsibly released to defenders, they could tilt the balance against offensive hackers, though criminals are already experimenting with AI to accelerate attacks. The overall sentiment is that AI will raise the bar for security research, benefitting defenders while making traditional bug‑bounty hunting increasingly challenging.

    Read more: bbc.com/news/articles/c3r2zjpr

    #ValentinaPalmiotti #ClaudeMythos #Pwn2Own #OrangeTsai #AI

  20. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  21. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  22. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  23. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  24. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  25. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

  26. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  27. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  28. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  29. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  30. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  31. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  32. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  33. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  34. 📰 Pwn2Own Berlin 2026 Concludes with $1.3M Awarded for 47 Zero-Days in Enterprise Software

    🏆 Pwn2Own Berlin 2026 ends with nearly $1.3M paid for 47 zero-days! DEVCORE crowned 'Master of Pwn' after epic exploits against Exchange & SharePoint. Patches from major vendors are on the way. #Pwn2Own #ZeroDay #CyberSecurity #Hacking

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/pw

  35. 📰 Pwn2Own Berlin 2026 Concludes with $1.3M Awarded for 47 Zero-Days in Enterprise Software

    🏆 Pwn2Own Berlin 2026 ends with nearly $1.3M paid for 47 zero-days! DEVCORE crowned 'Master of Pwn' after epic exploits against Exchange & SharePoint. Patches from major vendors are on the way. #Pwn2Own #ZeroDay #CyberSecurity #Hacking

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/pw

  36. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  37. @thezdi I wonder if it might be possible at to also check some minor projects, just for fun. 😜

  38. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  39. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  40. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber

  41. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber

  42. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber