home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

  1. A slam dunk success with 7 zero-days bugs disclosed from Vũ Chí Thành and Huỳnh Đức Tin of VinSOC during their exploit of Philips Hue Bridge Pro in the Smart Home category, taking home a total of $40,000 and 4 Master of Pwn points

  2. The Garmin Index BPM withstood Aaron Christophel of Summoning Team targeting as exploit attempts were unsuccessful before the clock ran out

  3. Another Collision 💥 4 bugs - 3 collisions & 1 zero-day successfully exploit the Samsung Galaxy S26 and Interrupt Labs takes home $15,750 and 3.25 Master of Pwn points

  4. Out of Bounds results are confirmed as a Collision! They'll take home $15k and 3 Master of Pwn points in their exploit of LiteLLM in the category.

  5. Wow - the setup took a while (and included Starlink!), but Interrupt Labs successfully exploited the Galaxy S26. They're off to the disclosure room to provide the details.

  6. Another bug collision! linhlhq and Son Dinh of VinSOC exploited the Era 300 with 2 bugs, but one was publicly known. They still earn $17,500 and 3.5 Master of Pwn points.

  7. We have a collision! Nguyen Thanh Dat of Viettel Cyber Security used 4 bugs to exploit the Galaxy S26, but 3 were known by the vendor. They still earn 31,250 and 3.25 Master of Pwn points.

  8. The disclosure rooms are full! With Interrupt Labs off to their own to discuss their exploit of the Samsung Galaxy S26 in the hopes of confirming their win of $50,000 and 5 Master of Pwn points!

  9. Off to the disclosure room VinSOC after successfully exploiting the @Sonos Era 300, pending confirmation - $50,000 and 5 Master of Pwn points will be theirs!

  10. And with a cheer of success, Out of Bounds is heading off to the disclosure room, stay tuned for the confirmation of the win!

  11. Tik tic ⏰ Printers continue to prove to be a time challenge as unfortunately T-X Lab team hit the time limit on their exploit attempt of Lexmark CX532adwe in the Printers category

  12. Verified! Taisic Yun of Xint used a Improper Input Validation bug along with code injection to get his reverse shell on LiteLLM. He earns $40,000 and 4 Master of Pwn points.

  13. We have our first confirmation of Ireland 2026! @_McCaulay combined an OOB Write and a format string(!) bug to exploit the Era 300. He earns $50,000 and 5 Master of Pwn points.

  14. Whew! It took some reconfiguring and tweaking, but Taisic Yun of Xint successfully got his reverse shell on LiteLLM in the AI category. After exhaling, they head off to the disclosure room to dish the deets.

  15. Boom! Nguyen Thanh Dat of Viettel Cyber Security kicks things off by successfully exploiting the Galaxy S26. He's off to the disclosure room to provide the details.

  16. Unfortunately, Ikotas Labs, Inc. could not get their exploit of the Brother MFC-L8970CDWworking within the time allotted.

  17. Here's what's on tap for the beginning of Ireland

  18. Excited to share that 🇫🇷 Yassine Bengana & Maxence Schmitt 🇫🇷 will be representing at Ireland - targeting the Smart Home category for a total of $30,000 and 3 Master of Pwn points, Wed. Oct. 7 @ 11:15AM

    zerodayinitiative.com/blog/202

  19. Ireland schedule is finalized.
    Team Xint attempts (Ireland time):
    LiteLLM - Tuesday 9:30
    Philipps Hue - Tuesday 18:30
    Home Assistant - Wednesday 9:30
    Oracle AI Database - Wednesday 11:45
    Pixel 10 - Thursday 11:15

    zerodayinitiative.com/blog/202

  20. The full schedule for Ireland 2026 is now live! You can find it at zerodayinitiative.com/blog/202. And check out pwn2own.zerodayinitiative.com/ for live leaderboard updates throughout the day.

Share on Mastodon

Enter the server where you have an account.