home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

  1. And the results are in! Nguyen Thanh Dat (@rewhiles), dungnm (@dungnm_) of Viettel Cyber Security (@vcslab) targeting Sonos Era 300 with 1 collision & 2 zero-days for a total of $10.5K and 4.25 Master of Pwn points

  2. 1 bug wonder! With an Confused Deputy (CWE-441) bug Dimitrios Valsamaras (@ch0pin), Ken Gannon / 伊藤 剣 (@Yogehi) using Djini.ai from Mobile Hacking Lab, Tenia Valsamara (@ir3l14) from CENSUS Labs PwN'ed the Samsung Galaxy S26

  3. Boom! With 3 collisions and 2 unique zero-days Taisic Yun (@taisic_) of Xint (@xint_official) breached Oracle Autonomous AI Database capturing their pot of gold of $14k at and 3 Master of Pwn points

  4. A valiant effort but Shio Kudo (@shiosa1t) of GMO Flatt Security Inc. (@flatt_security) was unsuccessful in their attempts at targeting Home Assistant Green in the Smart Home category

  5. Against the clock in the final round.... Jack Dates of RET2 Systems (@ret2systems) locked in his win against the Sonos Era 300. The pot has been confirmed, with 1 zero day and 1 collision, he will take home $9.5K and 3.75 Master of Pwn points

  6. Confirmed! @_McCaulay used 3 bugs (incl Hard-coded Credentials, Missing Authentication for Critical Function, Command Injection) to exploit the Canon imageFORCE 1643F. His 2nd round win nets him $10,000 and 2 Master of Pwn points.

  7. We have another collision! Yassine Bengana, and Maxence Schmitt of Doyensec used 3 bugs to exploit the Home Assistant Green, but all 3 bugs were previously known. They still earn $7,500 and 1.5 Master of Pwn points.

  8. 🧨 A dynamite takedown of Dynamo in the AI Infrastructure category for a total of $40,000 and 4 Master of Pwn points by HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io)

  9. In the most relaxed manner possible, Jack Dates of RET2 Systems exploited the Sonos Era 300 in under a minute. He heads off to the disclosure room to show us how he managed it.

  10. Very groovy. McCaulay exploited the Canon imageFORCE 1643F in short order. He heads off to the disclosure room to explain himself.

  11. 3 minutes - all it took for Yassine Bengana (
    @cousky_
    ), and Maxence Schmitt (
    @maxenceschmitt
    ) of Doyensec (
    @doyensec
    ) to successfully exploit the Home Assistant Green and off to the disclosure room they go!!

  12. Another one bites the dust - with seconds left on the clock, unfortunately Eugene (
    @k3vg3n
    ) targeting Chroma in the category was unsuccessful in his final attempt

  13. The grass may not be greener but the exploits sure were as Yves Bieri (@yves_bieri) of Xint (@xint_official) just won $30k and 3 Master of Pwn points in his takedown of Home Assistant Green

  14. W00t!! It took three attempts and lots of drama, but HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io) successfully exploited Dynamo in the AI Infrastructure category. Once they regain their breath, they head off to the disclosure room to provide details.

  15. Here's the schedule for today's attempts at Ireland. Lots of good stuff here. All time IST (UTC+1) and are subject to change.

  16. Unfortunately, the printers continue to be a challenge with Thanh Do (@nyanctl) of Team Confused unsuccessful in their targeting of Brother MFC-L8970CDW in the Printers category

  17. Day 2has officially begun! Yves Bieri (@yves_bieri) of Xint (@xint_official) had the first successful exploit of the day targeting Home Assistant Green in the Smart Home category! They are off to the disclosure room to dish all the deets

  18. Unfortunately, Kyeongmin Kim (@hareh4ru) of KAIST Hacking Lab withdrew his attempt targeting the Google Pixel 10 - USB in the Mobile Phone category.

  19. Recapping Day One of Ireland 2026. We saw some amazing research on display as we awarded $388,500 on the first day of the event. youtu.be/24dq8yVPd0c

  20. Day 1 is officially wrapped with quite a pot of gold being awarded across the teams! Checkout a snapshot of where the leaderboard stands as of today - more to come over the next two days so keep following along as we post live updates!

    For full leaderboard & schedule details: pwn2own.zerodayinitiative.com

  21. Ending Day 1 with collisions seems apropos. Joohyun Park of Xint used 5 different bugs in his exploit of the Philips Hue Bridge Pro, but 4 were previously known. His 3rd round success still nets him $6,000 and 2.5 Master of Pwn points.

  22. Confirmed! In the penultimate exploit of Day 1, Cong Thanh, Duc Hieu and Nam Dung of AHNTUD used an OOB Write to exploit Canon imageFORCE 1643F. They win $10,000 and 2 Master of Pwn points.

  23. Verified! The 1st full win the the Wellness category has Interrupt Labs using an OOB Read and an OOB Write to exploit the Garmin Index BPM. They win $20,000 and 2 Master of Pwn points.

  24. Sweet! In the final attempt of the day, Interrupt Labs successfully targeted the Garmin Index BPM in the Wellness category. They head off for the final disclosure of Ireland 2026 Day One.

  25. Unfortunately, the team of Nam Nguyen and Thai Son Dinh and Hoang Tien Minh of VinSOC couldn't get their exploit of Chroma working within the time allotted.

  26. Nice! Cong Thanh, Duc Hieu and Nam Dung successfully exploited the Canon imageFORCE 1643F. The ANHTUD team heads to the disclosure room to explain what they did.

  27. Confirmed! Ikotas Labs, Inc. used a single argument injection bug to exploit OpenAI Codex. They win $40,000 and 4 more Master of Pwn points. More outstanding research on display.

  28. Sweet! Joohyun Park of Xint successfully exploited the Philips Hue Bridge Pro on his first attempt. He's off to the disclosure room with all of the details of his exploit.

  29. Verified! Nam Nguyen, Thanh Vu, and Tin Huynh of VinSOC combined 5 bugs to exploit the #Oracle Autonomous AI Database. They win $40,000 and 4 Master of Pwn points. Outstanding work! #Pwn2Own #P2OIreland

  30. Confirmed! Sina Kheirkhah of Summoning Team used a single bug to exploit the Lexmark CX532adwe printer. The second round win nets him $10,000 and 2 Master of Pwn points.

  31. It seems to be a day for collisions. ByungYoung Yi, and KeunHo Kim of Out of Bounds used 5 bugs to exploit the Phillips Hue Bridge Pro, but 4 of those bugs were previously known. They still earn $12,000 and 2.5 Master of Pwn points.

  32. Unfortunately, Mikhail Evdokimov, Polina Smirnova and Mate Zombor of White Noise Club could not get their exploit of the Google Pixel 10 working within the time allotted.

  33. Confirmed (w/ a collision)! Ikotas Labs, Inc. used 4 bugs to exploit the Galaxy S26, but one was already known to the vendor (yet unpatched). They still earn $11,000 and 4.5 Master of Pwn points.

  34. Very nice! Sina Kheirkhah of Summoning Team needed no time at all to exploit the Lexmark CX532adwe. He's off to the disclosure room to go over all the details.

  35. Confirmed! Thanh Do of Team Confused showed no confusion at all as he used a single use-after-free on the Lexmark CX532adwe to win $20,000 and 2 Master of Pwn points.

  36. Boomshakalaka! 🏀🗑️ ByungYoung Yi, and KeunHo Kim of Out of Bounds needed little time exploiting the Philips Hue Bridge Pro. They head off to the disclosure room to see if their bug(s) is unique.

  37. My oh my! Nam Nguyen, Thanh Vu, and Tin Huynh of VinSOC wasted no time exploiting the Oracle Autonomous AI Database. They're heading to the disclosure room to explain themselves.

  38. A slam dunk success with 7 zero-days bugs disclosed from Vũ Chí Thành and Huỳnh Đức Tin of VinSOC during their exploit of Philips Hue Bridge Pro in the Smart Home category, taking home a total of $40,000 and 4 Master of Pwn points

  39. The Garmin Index BPM withstood Aaron Christophel of Summoning Team targeting as exploit attempts were unsuccessful before the clock ran out

  40. Another Collision 💥 4 bugs - 3 collisions & 1 zero-day successfully exploit the Samsung Galaxy S26 and Interrupt Labs takes home $15,750 and 3.25 Master of Pwn points

  41. Out of Bounds results are confirmed as a Collision! They'll take home $15k and 3 Master of Pwn points in their exploit of LiteLLM in the category.

  42. Wow - the setup took a while (and included Starlink!), but Interrupt Labs successfully exploited the Galaxy S26. They're off to the disclosure room to provide the details.

  43. Another bug collision! linhlhq and Son Dinh of VinSOC exploited the Era 300 with 2 bugs, but one was publicly known. They still earn $17,500 and 3.5 Master of Pwn points.

  44. We have a collision! Nguyen Thanh Dat of Viettel Cyber Security used 4 bugs to exploit the Galaxy S26, but 3 were known by the vendor. They still earn 31,250 and 3.25 Master of Pwn points.

  45. The disclosure rooms are full! With Interrupt Labs off to their own to discuss their exploit of the Samsung Galaxy S26 in the hopes of confirming their win of $50,000 and 5 Master of Pwn points!

  46. Off to the disclosure room VinSOC after successfully exploiting the @Sonos Era 300, pending confirmation - $50,000 and 5 Master of Pwn points will be theirs!

  47. And with a cheer of success, Out of Bounds is heading off to the disclosure room, stay tuned for the confirmation of the win!

  48. Tik tic ⏰ Printers continue to prove to be a time challenge as unfortunately T-X Lab team hit the time limit on their exploit attempt of Lexmark CX532adwe in the Printers category

  49. Verified! Taisic Yun of Xint used a Improper Input Validation bug along with code injection to get his reverse shell on LiteLLM. He earns $40,000 and 4 Master of Pwn points.

  50. We have our first confirmation of Ireland 2026! @_McCaulay combined an OOB Write and a format string(!) bug to exploit the Era 300. He earns $50,000 and 5 Master of Pwn points.

Share on Mastodon

Enter the server where you have an account.