home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

  1. Day 1 is officially wrapped with quite a pot of gold being awarded across the teams! Checkout a snapshot of where the leaderboard stands as of today - more to come over the next two days so keep following along as we post live updates!

    For full leaderboard & schedule details: pwn2own.zerodayinitiative.com

  2. Ending Day 1 with collisions seems apropos. Joohyun Park of Xint used 5 different bugs in his exploit of the Philips Hue Bridge Pro, but 4 were previously known. His 3rd round success still nets him $6,000 and 2.5 Master of Pwn points.

  3. Confirmed! In the penultimate exploit of Day 1, Cong Thanh, Duc Hieu and Nam Dung of AHNTUD used an OOB Write to exploit Canon imageFORCE 1643F. They win $10,000 and 2 Master of Pwn points.

  4. Verified! The 1st full win the the Wellness category has Interrupt Labs using an OOB Read and an OOB Write to exploit the Garmin Index BPM. They win $20,000 and 2 Master of Pwn points.

  5. Sweet! In the final attempt of the day, Interrupt Labs successfully targeted the Garmin Index BPM in the Wellness category. They head off for the final disclosure of Ireland 2026 Day One.

  6. Unfortunately, the team of Nam Nguyen and Thai Son Dinh and Hoang Tien Minh of VinSOC couldn't get their exploit of Chroma working within the time allotted.

  7. Nice! Cong Thanh, Duc Hieu and Nam Dung successfully exploited the Canon imageFORCE 1643F. The ANHTUD team heads to the disclosure room to explain what they did.

  8. Confirmed! Ikotas Labs, Inc. used a single argument injection bug to exploit OpenAI Codex. They win $40,000 and 4 more Master of Pwn points. More outstanding research on display.

  9. Sweet! Joohyun Park of Xint successfully exploited the Philips Hue Bridge Pro on his first attempt. He's off to the disclosure room with all of the details of his exploit.

  10. Verified! Nam Nguyen, Thanh Vu, and Tin Huynh of VinSOC combined 5 bugs to exploit the #Oracle Autonomous AI Database. They win $40,000 and 4 Master of Pwn points. Outstanding work! #Pwn2Own #P2OIreland

  11. Confirmed! Sina Kheirkhah of Summoning Team used a single bug to exploit the Lexmark CX532adwe printer. The second round win nets him $10,000 and 2 Master of Pwn points.

  12. It seems to be a day for collisions. ByungYoung Yi, and KeunHo Kim of Out of Bounds used 5 bugs to exploit the Phillips Hue Bridge Pro, but 4 of those bugs were previously known. They still earn $12,000 and 2.5 Master of Pwn points.

  13. Unfortunately, Mikhail Evdokimov, Polina Smirnova and Mate Zombor of White Noise Club could not get their exploit of the Google Pixel 10 working within the time allotted.

  14. Confirmed (w/ a collision)! Ikotas Labs, Inc. used 4 bugs to exploit the Galaxy S26, but one was already known to the vendor (yet unpatched). They still earn $11,000 and 4.5 Master of Pwn points.

  15. Very nice! Sina Kheirkhah of Summoning Team needed no time at all to exploit the Lexmark CX532adwe. He's off to the disclosure room to go over all the details.

  16. Confirmed! Thanh Do of Team Confused showed no confusion at all as he used a single use-after-free on the Lexmark CX532adwe to win $20,000 and 2 Master of Pwn points.

  17. Boomshakalaka! 🏀🗑️ ByungYoung Yi, and KeunHo Kim of Out of Bounds needed little time exploiting the Philips Hue Bridge Pro. They head off to the disclosure room to see if their bug(s) is unique.

  18. My oh my! Nam Nguyen, Thanh Vu, and Tin Huynh of VinSOC wasted no time exploiting the Oracle Autonomous AI Database. They're heading to the disclosure room to explain themselves.

  19. A slam dunk success with 7 zero-days bugs disclosed from Vũ Chí Thành and Huỳnh Đức Tin of VinSOC during their exploit of Philips Hue Bridge Pro in the Smart Home category, taking home a total of $40,000 and 4 Master of Pwn points

  20. The Garmin Index BPM withstood Aaron Christophel of Summoning Team targeting as exploit attempts were unsuccessful before the clock ran out

  21. Another Collision 💥 4 bugs - 3 collisions & 1 zero-day successfully exploit the Samsung Galaxy S26 and Interrupt Labs takes home $15,750 and 3.25 Master of Pwn points

  22. Out of Bounds results are confirmed as a Collision! They'll take home $15k and 3 Master of Pwn points in their exploit of LiteLLM in the category.

  23. Wow - the setup took a while (and included Starlink!), but Interrupt Labs successfully exploited the Galaxy S26. They're off to the disclosure room to provide the details.

  24. Another bug collision! linhlhq and Son Dinh of VinSOC exploited the Era 300 with 2 bugs, but one was publicly known. They still earn $17,500 and 3.5 Master of Pwn points.

  25. We have a collision! Nguyen Thanh Dat of Viettel Cyber Security used 4 bugs to exploit the Galaxy S26, but 3 were known by the vendor. They still earn 31,250 and 3.25 Master of Pwn points.

  26. The disclosure rooms are full! With Interrupt Labs off to their own to discuss their exploit of the Samsung Galaxy S26 in the hopes of confirming their win of $50,000 and 5 Master of Pwn points!

  27. Off to the disclosure room VinSOC after successfully exploiting the @Sonos Era 300, pending confirmation - $50,000 and 5 Master of Pwn points will be theirs!

  28. And with a cheer of success, Out of Bounds is heading off to the disclosure room, stay tuned for the confirmation of the win!

  29. Tik tic ⏰ Printers continue to prove to be a time challenge as unfortunately T-X Lab team hit the time limit on their exploit attempt of Lexmark CX532adwe in the Printers category

  30. Verified! Taisic Yun of Xint used a Improper Input Validation bug along with code injection to get his reverse shell on LiteLLM. He earns $40,000 and 4 Master of Pwn points.

  31. We have our first confirmation of Ireland 2026! @_McCaulay combined an OOB Write and a format string(!) bug to exploit the Era 300. He earns $50,000 and 5 Master of Pwn points.

  32. Whew! It took some reconfiguring and tweaking, but Taisic Yun of Xint successfully got his reverse shell on LiteLLM in the AI category. After exhaling, they head off to the disclosure room to dish the deets.

  33. Boom! Nguyen Thanh Dat of Viettel Cyber Security kicks things off by successfully exploiting the Galaxy S26. He's off to the disclosure room to provide the details.

  34. Unfortunately, Ikotas Labs, Inc. could not get their exploit of the Brother MFC-L8970CDWworking within the time allotted.

  35. Here's what's on tap for the beginning of Ireland

  36. Excited to share that 🇫🇷 Yassine Bengana & Maxence Schmitt 🇫🇷 will be representing at Ireland - targeting the Smart Home category for a total of $30,000 and 3 Master of Pwn points, Wed. Oct. 7 @ 11:15AM

    zerodayinitiative.com/blog/202

  37. Ireland schedule is finalized.
    Team Xint attempts (Ireland time):
    LiteLLM - Tuesday 9:30
    Philipps Hue - Tuesday 18:30
    Home Assistant - Wednesday 9:30
    Oracle AI Database - Wednesday 11:45
    Pixel 10 - Thursday 11:15

    zerodayinitiative.com/blog/202

  38. The full schedule for Ireland 2026 is now live! You can find it at zerodayinitiative.com/blog/202. And check out pwn2own.zerodayinitiative.com/ for live leaderboard updates throughout the day.

Share on Mastodon

Enter the server where you have an account.