home.social

#pwn2own — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pwn2own, aggregated by home.social.

fetched live
  1. On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant.
    Check out the full event agenda, including his session, at:
    brucon.org/

  2. #Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at zerodayinitiative.com/blog/202 #P2OIreland

  3. 🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

    This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

    These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

    → Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  4. Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

    Read: hackread.com/pwn2own-berlin-20

    #CyberSecurity #BugBounty #Vulnerability #AI #0day

  5. @thezdi I wonder if it might be possible at to also check some minor projects, just for fun. 😜

  6. RE: infosec.exchange/@thezdi/11658

    * Seems many of the Browser exploits couldn't be demoed due to bad luck/last-minute fixes. Really sorry for the participants :( great research!
    * No V8 (and Chrome?) submissions for the 2nd year in a row
    * Orange's Edge chain sounds wild, very curious for details!
    Thanks for running #Pwn2Own @thezdi

  7. That's a wrap on Pwn2Own Berlin 2026! 🏆 $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own #P2OBerlin

  8. Collision! While Byung Young Yi (@yibarrack) of Out Of Bounds successfully demonstrated their exploit of Anthropic Claude Code, the bug used had been previously disclosed. They still earn $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin

  9. Mind blown alert 🤯! Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG (@starlabs_sg) used a Memory Corruption bug to exploit VMware ESXi with the Cross-tenant Code Execution add-on, earning a sweeeeeet $200,000 and 20 Master of Pwn points. Full win let's go! #Pwn2Own #P2OBerlin

  10. Booyah it's been confirmed! 🎉 splitline (@_splitline_) of DEVCORE Research Team chained 2 bugs to exploit Microsoft SharePoint, earning $100,000 and 10 Master of Pwn points. Massive aura farming this year at #P2OBerlin. Full win! #Pwn2Own

  11. Wow what a fun way to wrap up the day! With TWO minutes to spare, Byung Young Yi (@yibarrack) of Out Of Bounds was able to exploit Anthropic Claude Code! If confirmed, they win $40,000 and 4 Master of Pwn points. They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin

  12. MASSIVE AURA POINTS! Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG was able to exploit VMware ESXi! If confirmed, they win $200,000 and 20 Master of Pwn points. They're off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own #P2OBerlin

  13. ATE AND LEFT NO CRUMBS! splitline (@_splitline_) of DEVCORE Research Team totally cooked and was able to exploit Microsoft SharePoint! If confirmed, they win $100,000 and 10 Master of Pwn points. They're skeddadling off to the disclosure room now to drop the lore. #Pwn2Own #P2OBerlin

  14. The math is mathing and we are on the brink of a million dollars! Here's the last set of attempts for the day. Stay tuned or stay square #Pwn2Own #P2OBerlin

  15. Confirmed! Hyunwoo Kim (@v4bel) chained a use-after-free and uninitialized memory bug to escalate privileges on Red Hat Enterprise Linux for Workstations in the fourth round, earning $5,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin

  16. Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin

  17. Unfortunately, Giuseppe Calì of Summoning Team (@SummoningTeam) could not get their exploit of VMware ESXi working within the time allotted. #Pwn2Own #P2OBerlin

  18. Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin

  19. Success! Hyunwoo Kim (@v4bel) was able to exploit Red Hat Enterprise Linux for Workstations! If confirmed, they win $20,000 and 2 Master of Pwn points. They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin

  20. Excelsior! Satoki Tsuji of Ikotas Labs, Inc. abused an external control to exploit OpenAI Codex and pop a host of calcs. He earns $20,000 and 4 Master of Pwn points. #Pwn2Own #P2OBerlin

  21. Confirmed! Le Tran Hai Tung, dungnm and hieuvd of Viettel Cyber Security (@vcslab) used an integer overflow to escalate privileges on #Windows 11. Their 5th round win nets them $7,500 and 3 Master of Pwn points. #Pwn2Own #P2OBerlin

  22. We have a collision! Sina Kheirkhah of Summoning Team used two bugs to exploit Red Hat Linux, but one of the bugs was previously known. He still earns $7,000 and 1.5 Master of Pwn points. #Pwn2Own #P2OBerlin

  23. In a video highlight from Day Two, @orange of DEVCORE exploits #Microsoft #Exchange with a little help from AI. He earns $200,000 and 20 Master of Pwn points. youtube.com/shorts/cq0hezWcy_g #Pwn2Own #P2OBerlin