home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

  1. Hank Chen (@Hank0438) of InnoEdge Labs successful in their exploit of Philips Hue Bridge Pro in a 5 bug chain with 1 zero day disclosure for a total win of $6,000 and 2.5 Master of Pwn points

  2. 2 unique bugs and down went the Lexmark CX532adwe as Cong Thanh (@ExLuck99), Duc Hieu (@gr4ss341) and Nam Dung (@greengrass19000) earned $5,000 and 2 Master of Pwn points in their successful exploit attempt

  3. $300,000!!!!! and 30 Master of Pwn points officially makes Ikotas Labs, Inc. the Master of Pwn as they jump to the top of the leader board after they chained multiple issues together to successfully exploit the Google Pixel 10

  4. Bye bye bridge @_McCaulay exploited the Philips Hue Bridge Pro winning $5,000 and 2 Master of Pwn points with a 4 bug collision

  5. $6000 and 2.5 Master of Pwn points secured by Connor Laidlaw & Matthew Keeley of Platform Security for successfully targeting Oracle Autonomous AI Database through a 5 bugs - 4 collisions and 1 unique chain

  6. Boom chaka laka! Ben Koo (@kiddo_pwn) and Evangelos Daravigkas (@freddo_1337) of Team DDOS exploitted confirmed with a 5 bug chain, including 1 zero-day targeting Home Assistant Green with a pay out in $4,500 and 2 Master of Pwn points

  7. Results are in and Tim Becker (@tjbecker) and Yves Bieri (@yves_bieri) of Xint (@xint_official) have secured their lead in the race to the Master of Pwn with their successful remote exploit of Google Pixel 10 through a single bug collision, earning them $150,000 and 15 - Master of Pwn points

  8. Brother what? Brother exploited! Lucas Van Haaren (vhash, @LucasVanHaaren) and Hugo Leclercq (0xnasu) of FuzzingLabs (@FuzzingLabs) exploited Brother MFC-L8970CDW with a single zero-day earning $20,000 and 2 Master of Pwn points

  9. Sina Kheirkhah (@SinSinology) and Aaron Christophel (@ATC1441) of Summoning Team (@SummoningTeam) collided through the walls of the Philips Hue Bridge Pro with a 5 bug, full collision, securing a $5k payout and 2.5 Master of Pwn Points

  10. Nice! Sina Kheirkhah and Aaron Christophel of Summoning Team were able to exploit Philips Hue Bridge Pro in short order. They're off to the disclosure room to explain themselves.

  11. Sweet! Lucas Van Haaren and Hugo Leclercq of FuzzingLabs needed little time to exploit the Brother MFC-L8970CDW printer. They head off to the disclosure room to provide the details to us and the vendor.

  12. Boom! Day 3 of Ireland kicks off with a successful demonstration from Nikolaos Mourousias and Bruno Halltari of OtterSec targeting Oracle Autonomous AI Database. They head off to the disclosure room to dish the deets.

  13. Unfortunately, Polina Smirnova (@moe_hw), Mikhail Evdokimov (@konatabrk) and Mate Zombor (@r4bbit_zm) of White Noise Clubm couldn't get their exploit of the Garmin Index BPM working within the time allotted

  14. Miss any of the highlights from Ireland Day Two? Check out the recap at youtu.be/o1uNizu47Gk

  15. It's the bug of the day for Day Two of Ireland! Interrupt Labs shows us how it's done. youtube.com/shorts/3pNgJcrzO48

  16. Never thought to see a cortisol (tagging Agnes Tachyon Gooner) as PoC at :ageblobcat:

  17. An impressive disclosure from Alessandro Fanio Gonzalez targeting Chroma with a 2 N-days & 1 collision in the AI Infrastructure category for a net total win of $4,500 and 1 Master of Pwn points

  18. @_McCaulay strikes again and down goes Home Assistant Green once again! With a 6 bug chain, including 1 collision and 5 zero-days, the net total winnings is $7k & 2.75 Master of Pwn points

  19. Exploit Confirmed!
    @BoredPentester
    successfully exploited Lexmark CX532adwe in the Printers category for a net total of $4250 and 1.25 Master of Pwn points

  20. 2 bugs + Sina Kheirkhah (@SinSinology) of Summoning Team = exploited Sonos Era 300 and $12,500 and 5 Master of Pwn points won!

  21. A mammoth win by team MAMMOTH, with Mingeun Kim, Chulhan Park, SeokHun Lee, Inhyung Lee, Sehyun Baek, Nayeon Lee, Junseok Kim of Team MAMMOTH exploiting Chroma in the AI Infrastructure category with 2 collisions and 1 zero-day for a net total win of $12,000 and 1.25 Master of Pwn points

  22. Boom! With 3 bug collisions PetoWorks (@petoworks) successfully accessed the Samsung Galaxy S26 remotely, earning them a net $6250 and 2.5 Master of Pwn points

  23. Another printer bites the dust by Rick de Jager and Filippo Cremonese of @zellic_io/@v12sec earning him $5k and 2 Master of Pwn points in his successful exploit of Lexmark CX532adwe

  24. Confirmed! 1 zero-day & 3 collisions by Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab successfully exploited the Home Assistant Green in the Smart Home category earning him $4,750 and 2 Master of Pwn points

  25. Another printer bites the dust by Adam Hansen of Zellic (@zellic_io) earning him $5k and 2 Master of Pwn points in his successful exploit of Lexmark CX532adwe

  26. @_McCaulay
    climbs the leaderboard with his third target earning another 1.5 master of Pwn points and $6750 for his exploit of Garmin Index BPM with 1 collision and 1 unique bug. Another two entries from
    @_McCaulay
    to come, stay tuned!

  27. Confused? Well Ikotas Labs, Inc. sure wasn't as they unleased a 7-chain bug ending with a Use-After-Free and a Type Confusion on Oracle Autonomous AI Database securing a win of $10,000 and 4 Master of Pwn points

  28. Congratulations to Maxence and Yassine on successfully using their three bugs 🤯 to exploit Home Assistant Green (cc: @homeassistant). Tough break that they were previously known - we'll get 'em next time!

    #doyensec #appsec #security #pwn2own #pwn2ownIreland

  29. Direct connection - NOT needed for Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab who remotely breached the Samsung Galaxy S26 with 1 unique bug and 2 collision winning $8.5k and 3.5 Master of Pwn points

  30. Green means go!🟢 And boy did PetoWorks (@petoworks) go straight into the Home Assistant Green with a chain of 5 bugs including 2 collisions and 3 unique, securing $12k and 2.5 Master of Pwn points in the Smart Home category

  31. It was DOOMsday for the Lexmark CX532adwe printer as Interrupt Labs (@InterruptLabs) claimed victory and earned $5k & 2 Master of Pwn points!

  32. And the results are in! Nguyen Thanh Dat (@rewhiles), dungnm (@dungnm_) of Viettel Cyber Security (@vcslab) targeting Sonos Era 300 with 1 collision & 2 zero-days for a total of $10.5K and 4.25 Master of Pwn points

  33. 1 bug wonder! With an Confused Deputy (CWE-441) bug Dimitrios Valsamaras (@ch0pin), Ken Gannon / 伊藤 剣 (@Yogehi) using Djini.ai from Mobile Hacking Lab, Tenia Valsamara (@ir3l14) from CENSUS Labs PwN'ed the Samsung Galaxy S26

  34. Boom! With 3 collisions and 2 unique zero-days Taisic Yun (@taisic_) of Xint (@xint_official) breached Oracle Autonomous AI Database capturing their pot of gold of $14k at #Pwn2OwnIreland and 3 Master of Pwn points #Pwn2Own

  35. A valiant effort but Shio Kudo (@shiosa1t) of GMO Flatt Security Inc. (@flatt_security) was unsuccessful in their attempts at targeting Home Assistant Green in the Smart Home category

  36. Against the clock in the final round.... Jack Dates of RET2 Systems (@ret2systems) locked in his win against the Sonos Era 300. The pot has been confirmed, with 1 zero day and 1 collision, he will take home $9.5K and 3.75 Master of Pwn points

  37. Confirmed! @_McCaulay used 3 bugs (incl Hard-coded Credentials, Missing Authentication for Critical Function, Command Injection) to exploit the Canon imageFORCE 1643F. His 2nd round win nets him $10,000 and 2 Master of Pwn points.

  38. We have another collision! Yassine Bengana, and Maxence Schmitt of Doyensec used 3 bugs to exploit the Home Assistant Green, but all 3 bugs were previously known. They still earn $7,500 and 1.5 Master of Pwn points.

  39. 🧨 A dynamite takedown of Dynamo in the AI Infrastructure category for a total of $40,000 and 4 Master of Pwn points by HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io)

  40. In the most relaxed manner possible, Jack Dates of RET2 Systems exploited the Sonos Era 300 in under a minute. He heads off to the disclosure room to show us how he managed it.

  41. Very groovy. McCaulay exploited the Canon imageFORCE 1643F in short order. He heads off to the disclosure room to explain himself.

  42. 3 minutes - all it took for Yassine Bengana (
    @cousky_
    ), and Maxence Schmitt (
    @maxenceschmitt
    ) of Doyensec (
    @doyensec
    ) to successfully exploit the Home Assistant Green and off to the disclosure room they go!!

  43. Another one bites the dust - with seconds left on the clock, unfortunately Eugene (
    @k3vg3n
    ) targeting Chroma in the category was unsuccessful in his final attempt

  44. The grass may not be greener but the exploits sure were as Yves Bieri (@yves_bieri) of Xint (@xint_official) just won $30k and 3 Master of Pwn points in his takedown of Home Assistant Green

  45. W00t!! It took three attempts and lots of drama, but HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io) successfully exploited Dynamo in the AI Infrastructure category. Once they regain their breath, they head off to the disclosure room to provide details.

  46. Here's the schedule for today's attempts at Ireland. Lots of good stuff here. All time IST (UTC+1) and are subject to change.

  47. Unfortunately, the printers continue to be a challenge with Thanh Do (@nyanctl) of Team Confused unsuccessful in their targeting of Brother MFC-L8970CDW in the Printers category

  48. Day 2has officially begun! Yves Bieri (@yves_bieri) of Xint (@xint_official) had the first successful exploit of the day targeting Home Assistant Green in the Smart Home category! They are off to the disclosure room to dish all the deets

  49. Unfortunately, Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab withdrew his attempt targeting the Google Pixel 10 - USB in the Mobile Phone category.

  50. Recapping Day One of Ireland 2026. We saw some amazing research on display as we awarded $388,500 on the first day of the event. youtu.be/24dq8yVPd0c

Share on Mastodon

Enter the server where you have an account.