home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

fetched live
  1. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  2. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  3. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  4. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  5. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  6. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  7. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  8. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  9. BBC News | Champion ethical hacker warns AI tools like Mythos will make competing harder

    AI generated summary, Read the full article for complete information.

    Champion ethical hacker Valentina Palmiotti, known as “Chompie,” won the 2024 Pwn2Own Berlin competition by exploiting systems for prize money, but she warns that powerful new AI tools such as Anthropic’s Claude Mythos could soon make human‑only hacking contests impractical. While AI assistants like Claude Code currently help her and other researchers work faster, the emergence of more advanced models promises to automate many “lower‑hanging‑fruit” bugs, leaving only the very best hackers able to discover novel vulnerabilities. Fellow champion Orange Tsai sees AI as a useful research aid that can free up time but believes human creativity will still be essential. Both experts agree that if AI‑driven tools are responsibly released to defenders, they could tilt the balance against offensive hackers, though criminals are already experimenting with AI to accelerate attacks. The overall sentiment is that AI will raise the bar for security research, benefitting defenders while making traditional bug‑bounty hunting increasingly challenging.

    Read more: bbc.com/news/articles/c3r2zjpr

    #ValentinaPalmiotti #ClaudeMythos #Pwn2Own #OrangeTsai #AI

  10. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  11. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  12. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  13. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  14. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  15. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

  16. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  17. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  18. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  19. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  20. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  21. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  22. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  23. 🔥 Pwn2Own Berlin 2026 ends with:
    💰 $1.29M awarded
    ⚠️ 47 zero-days exploited
    🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
    Enterprise + AI attack surfaces keep expanding.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for more.

    #InfoSec #Pwn2Own #ZeroDay

  24. 📰 Pwn2Own Berlin 2026 Concludes with $1.3M Awarded for 47 Zero-Days in Enterprise Software

    🏆 Pwn2Own Berlin 2026 ends with nearly $1.3M paid for 47 zero-days! DEVCORE crowned 'Master of Pwn' after epic exploits against Exchange & SharePoint. Patches from major vendors are on the way. #Pwn2Own #ZeroDay #CyberSecurity #Hacking

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/pw

  25. 📰 Pwn2Own Berlin 2026 Concludes with $1.3M Awarded for 47 Zero-Days in Enterprise Software

    🏆 Pwn2Own Berlin 2026 ends with nearly $1.3M paid for 47 zero-days! DEVCORE crowned 'Master of Pwn' after epic exploits against Exchange & SharePoint. Patches from major vendors are on the way. #Pwn2Own #ZeroDay #CyberSecurity #Hacking

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/pw

  26. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  27. @thezdi I wonder if it might be possible at to also check some minor projects, just for fun. 😜

  28. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  29. @thezdi I wonder if it might be possible at #Pwn2Own to also check some minor #FOSS projects, just for fun. 😜

  30. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber

  31. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber

  32. 🛡️ Pwn2Own Berlino si chiude con 47 falle scoperte: un promemoria sul costo della sicurezza e sul valore della ricerca etica. #Cybersecurity #Pwn2Own

    🔗 tomshw.it/hardware/pwn2own-ber

  33. Pwn2Own Berlin 2026: 47 MEDIUM severity exploits demoed on Windows, Linux, VMware, Nvidia & AI platforms 🛡️. Highlights: Microsoft Exchange RCE, VMware ESX cross-tenant code exec. No active wild exploitation yet. Monitor vendor patches. radar.offseq.com/threat/hacker #OffSeq #Pwn2Own #Infosec

  34. Pwn2Own Berlin 2026: 47 MEDIUM severity exploits demoed on Windows, Linux, VMware, Nvidia & AI platforms 🛡️. Highlights: Microsoft Exchange RCE, VMware ESX cross-tenant code exec. No active wild exploitation yet. Monitor vendor patches. radar.offseq.com/threat/hacker #OffSeq #Pwn2Own #Infosec

  35. Pwn2Own Berlin 2026: 47 MEDIUM severity exploits demoed on Windows, Linux, VMware, Nvidia & AI platforms 🛡️. Highlights: Microsoft Exchange RCE, VMware ESX cross-tenant code exec. No active wild exploitation yet. Monitor vendor patches. radar.offseq.com/threat/hacker #OffSeq #Pwn2Own #Infosec

  36. Pwn2Own Berlin 2026: 47 MEDIUM severity exploits demoed on Windows, Linux, VMware, Nvidia & AI platforms 🛡️. Highlights: Microsoft Exchange RCE, VMware ESX cross-tenant code exec. No active wild exploitation yet. Monitor vendor patches. radar.offseq.com/threat/hacker #OffSeq #Pwn2Own #Infosec

  37. RE: infosec.exchange/@thezdi/11658

    * Seems many of the Browser exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
    * No V8 (and Chrome?) submissions for the 2nd year in a row
    * Orange's Edge chain sounds wild, very curious for details!
    Thanks for running #Pwn2Own @thezdi

  38. RE: infosec.exchange/@thezdi/11658

    * Seems many of the Browser exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
    * No V8 (and Chrome?) submissions for the 2nd year in a row
    * Orange's Edge chain sounds wild, very curious for details!
    Thanks for running #Pwn2Own @thezdi

  39. RE: infosec.exchange/@thezdi/11658

    * Seems many of the Browser exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
    * No V8 (and Chrome?) submissions for the 2nd year in a row
    * Orange's Edge chain sounds wild, very curious for details!
    Thanks for running #Pwn2Own @thezdi

  40. RE: infosec.exchange/@thezdi/11658

    * Seems many of the Browser exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
    * No V8 (and Chrome?) submissions for the 2nd year in a row
    * Orange's Edge chain sounds wild, very curious for details!
    Thanks for running #Pwn2Own @thezdi