A Mammoth of a bug chain of 6 zero days closes out #Pwn2OwnIreland by Chulhan Park, Mingeun Kim, SeokHun Lee, Inhyung Lee, Sehyun Baek, Nayeon Lee, Junseok Kim of Team MAMMOTH targeting Home Assistant Green in the Smart Home category for a total of $7500 and 3 Master of Pwn points #Pwn2Own
#pwn2own — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.
-
Booya! Cens-ational exploit by Dimitrios Valsamaras (@ch0pin), Ken Gannon / 伊藤 剣 (@Yogehi) using http://Djini.ai from Mobile Hacking Lab, Tenia Valsamara (@ir3l14) from CENSUS Labs targeting Google Pixel 10 - Remote in the Mobile Phone category for a total of $112,500 and 22.50 Master of Pwn points with a 2 bug chain, 1 collission and 1 zero-day #Pwn2Own
-
Howdy Buckaroos, the very own BunkyoWesterns (@BunkyoWesterns) succeed in their remote lasso-ing of the Samsung Galaxy S26, with their 2 bug chain, 1 collission + 1 unique, earning them $8250 and 3.75 Master of Pwn points #Pwn2Own #P2OIreland
-
Whew! Chulhan Park, Mingeun Kim, SeokHun Lee, Inhyung Lee, Sehyun Baek, Nayeon Lee, Junseok Kim of Team MAMMOTH needed almost the entire time and 3 attempts to exploit Home Assistant Green. That's the final attempt of #Pwn2Own Ireland 2026. Off to the final disclosure room.
-
Hank Chen (@Hank0438) of InnoEdge Labs successful in their exploit of Philips Hue Bridge Pro in a 5 bug chain with 1 zero day disclosure for a total win of $6,000 and 2.5 Master of Pwn points #Pwn2Own
-
2 unique bugs and down went the Lexmark CX532adwe as Cong Thanh (@ExLuck99), Duc Hieu (@gr4ss341) and Nam Dung (@greengrass19000) earned $5,000 and 2 Master of Pwn points in their successful exploit attempt #Pwn2Own
-
$300,000!!!!! and 30 Master of Pwn points officially makes Ikotas Labs, Inc. the Master of Pwn as they jump to the top of the leader board after they chained multiple issues together to successfully exploit the Google Pixel 10 #Pwn2Own
-
Bye bye bridge @_McCaulay exploited the Philips Hue Bridge Pro winning $5,000 and 2 Master of Pwn points with a 4 bug collision #Pwn2Own
-
$6000 and 2.5 Master of Pwn points secured by Connor Laidlaw & Matthew Keeley of Platform Security for successfully targeting Oracle Autonomous AI Database through a 5 bugs - 4 collisions and 1 unique chain #Pwn2Own
-
Boom chaka laka! Ben Koo (@kiddo_pwn) and Evangelos Daravigkas (@freddo_1337) of Team DDOS exploitted confirmed with a 5 bug chain, including 1 zero-day targeting Home Assistant Green with a pay out in $4,500 and 2 Master of Pwn points #Pwn2Own
-
Results are in and Tim Becker (@tjbecker) and Yves Bieri (@yves_bieri) of Xint (@xint_official) have secured their lead in the race to the Master of Pwn with their successful remote exploit of Google Pixel 10 through a single bug collision, earning them $150,000 and 15 - Master of Pwn points #Pwn2Own
-
Brother what? Brother exploited! Lucas Van Haaren (vhash, @LucasVanHaaren) and Hugo Leclercq (0xnasu) of FuzzingLabs (@FuzzingLabs) exploited Brother MFC-L8970CDW with a single zero-day earning $20,000 and 2 Master of Pwn points #Pwn2Own
-
Sina Kheirkhah (@SinSinology) and Aaron Christophel (@ATC1441) of Summoning Team (@SummoningTeam) collided through the walls of the Philips Hue Bridge Pro with a 5 bug, full collision, securing a $5k payout and 2.5 Master of Pwn Points #Pwn2Own
-
Nice! Sina Kheirkhah and Aaron Christophel of Summoning Team were able to exploit Philips Hue Bridge Pro in short order. They're off to the disclosure room to explain themselves. #Pwn2Own
-
Sweet! Lucas Van Haaren and Hugo Leclercq of FuzzingLabs needed little time to exploit the Brother MFC-L8970CDW printer. They head off to the disclosure room to provide the details to us and the vendor. #Pwn2Own
-
Boom! Day 3 of #Pwn2Own Ireland kicks off with a successful demonstration from Nikolaos Mourousias and Bruno Halltari of OtterSec targeting Oracle Autonomous AI Database. They head off to the disclosure room to dish the deets.
-
Unfortunately, Polina Smirnova (@moe_hw), Mikhail Evdokimov (@konatabrk) and Mate Zombor (@r4bbit_zm) of White Noise Clubm couldn't get their exploit of the Garmin Index BPM working within the time allotted #Pwn2Own
-
Miss any of the highlights from #Pwn2Own Ireland Day Two? Check out the recap at https://youtu.be/o1uNizu47Gk
-
It's the bug of the day for Day Two of #Pwn2Own Ireland! Interrupt Labs shows us how it's done. https://youtube.com/shorts/3pNgJcrzO48?feature=share
-
Never thought to see a cortisol (tagging Agnes Tachyon Gooner) as PoC at #pwn2own :ageblobcat:
-
An impressive disclosure from Alessandro Fanio Gonzalez targeting Chroma with a 2 N-days & 1 collision in the AI Infrastructure category for a net total win of $4,500 and 1 Master of Pwn points #Pwn2Own
-
@_McCaulay strikes again and down goes Home Assistant Green once again! With a 6 bug chain, including 1 collision and 5 zero-days, the net total winnings is $7k & 2.75 Master of Pwn points #Pwn2Own
-
Exploit Confirmed!
@BoredPentester
successfully exploited Lexmark CX532adwe in the Printers category for a net total of $4250 and 1.25 Master of Pwn points #Pwn2Own -
2 bugs + Sina Kheirkhah (@SinSinology) of Summoning Team = exploited Sonos Era 300 and $12,500 and 5 Master of Pwn points won! #Pwn2Own
-
A mammoth win by team MAMMOTH, with Mingeun Kim, Chulhan Park, SeokHun Lee, Inhyung Lee, Sehyun Baek, Nayeon Lee, Junseok Kim of Team MAMMOTH exploiting Chroma in the AI Infrastructure category with 2 collisions and 1 zero-day for a net total win of $12,000 and 1.25 Master of Pwn points #Pwn2Own
-
Boom! With 3 bug collisions PetoWorks (@petoworks) successfully accessed the Samsung Galaxy S26 remotely, earning them a net $6250 and 2.5 Master of Pwn points #Pwn2Own
-
Another printer bites the dust by Rick de Jager and Filippo Cremonese of @zellic_io/@v12sec earning him $5k and 2 Master of Pwn points in his successful exploit of Lexmark CX532adwe #Pwn2Own
-
-
Another printer bites the dust by Adam Hansen of Zellic (@zellic_io) earning him $5k and 2 Master of Pwn points in his successful exploit of Lexmark CX532adwe #Pwn2Own
-
@_McCaulay
climbs the leaderboard with his third target earning another 1.5 master of Pwn points and $6750 for his exploit of Garmin Index BPM with 1 collision and 1 unique bug. Another two entries from
@_McCaulay
to come, stay tuned! #Pwn2Own -
Confused? Well Ikotas Labs, Inc. sure wasn't as they unleased a 7-chain bug ending with a Use-After-Free and a Type Confusion on Oracle Autonomous AI Database securing a win of $10,000 and 4 Master of Pwn points #Pwn2Own
-
Congratulations to Maxence and Yassine on successfully using their three bugs 🤯 to exploit Home Assistant Green (cc: @homeassistant). Tough break that they were previously known - we'll get 'em next time!
-
-
Green means go!🟢 And boy did PetoWorks (@petoworks) go straight into the Home Assistant Green with a chain of 5 bugs including 2 collisions and 3 unique, securing $12k and 2.5 Master of Pwn points in the Smart Home category #Pwn2Own
-
And the results are in! Nguyen Thanh Dat (@rewhiles), dungnm (@dungnm_) of Viettel Cyber Security (@vcslab) targeting Sonos Era 300 with 1 collision & 2 zero-days for a total of $10.5K and 4.25 Master of Pwn points #Pwn2Own
-
Boom! With 3 collisions and 2 unique zero-days Taisic Yun (@taisic_) of Xint (@xint_official) breached Oracle Autonomous AI Database capturing their pot of gold of $14k at #Pwn2OwnIreland and 3 Master of Pwn points #Pwn2Own
-
A valiant effort but Shio Kudo (@shiosa1t) of GMO Flatt Security Inc. (@flatt_security) was unsuccessful in their attempts at targeting Home Assistant Green in the Smart Home category #Pwn2Own
-
Against the clock in the final round.... Jack Dates of RET2 Systems (@ret2systems) locked in his win against the Sonos Era 300. The pot has been confirmed, with 1 zero day and 1 collision, he will take home $9.5K and 3.75 Master of Pwn points #Pwn2Own
-
Confirmed! @_McCaulay used 3 bugs (incl Hard-coded Credentials, Missing Authentication for Critical Function, Command Injection) to exploit the Canon imageFORCE 1643F. His 2nd round win nets him $10,000 and 2 Master of Pwn points. #Pwn2Own
-
We have another collision! Yassine Bengana, and Maxence Schmitt of Doyensec used 3 bugs to exploit the Home Assistant Green, but all 3 bugs were previously known. They still earn $7,500 and 1.5 Master of Pwn points. #Pwn2Own
-
🧨 A dynamite takedown of Dynamo in the AI Infrastructure category for a total of $40,000 and 4 Master of Pwn points by HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io) #Pwn2Own
-
In the most relaxed manner possible, Jack Dates of RET2 Systems exploited the Sonos Era 300 in under a minute. He heads off to the disclosure room to show us how he managed it. #Pwn2Own
-
Very groovy. McCaulay exploited the Canon imageFORCE 1643F in short order. He heads off to the disclosure room to explain himself. #Pwn2Own #P2OIreland
-
-
Another one bites the dust - with seconds left on the clock, unfortunately Eugene (
@k3vg3n
) targeting Chroma in the #AIInfrastructure category was unsuccessful in his final attempt #Pwn2Own -
The grass may not be greener but the exploits sure were as Yves Bieri (@yves_bieri) of Xint (@xint_official) just won $30k and 3 Master of Pwn points in his takedown of Home Assistant Green #Pwn2Own
-
W00t!! It took three attempts and lots of drama, but HaeJung Yang (@haehaeYang) of Out of Bounds (@oobs_io) successfully exploited Dynamo in the AI Infrastructure category. Once they regain their breath, they head off to the disclosure room to provide details. #Pwn2Own
-
Here's the schedule for today's attempts at #Pwn2Own Ireland. Lots of good stuff here. All time IST (UTC+1) and are subject to change.