LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

ZeroDay News ·

Source: BleepingComputer

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

A significant highlight of the first day involved successful attacks against the Samsung Galaxy S26 flagship smartphone, which was compromised twice. Teams from Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security were responsible for these exploits. It was noted that some of the vulnerabilities used in these challenges were already known to the vendor.

The competition features seven distinct categories: mobile phones (including the Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category for wellness healthcare devices.

V Ch Th nh and Hu nh c Tin of VinSOC topped the leaderboard, securing $40,000 for chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub. They earned an additional $40,000 by using a five zero-day exploit chain against the Oracle Autonomous AI Database.

Other successful exploits included demonstrating LiteLLM zero-days, compromising Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, and taking down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug. Researchers also exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker.

Not all attempts were successful; Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Google Pixel 10 but were unable to execute their exploit within the allocated time.

Following the disclosure of these flaws at Pwn2Own, affected vendors are given a 90-day window to release security updates before Trend Micro's ZDI publicly discloses the vulnerabilities.

The competition is scheduled to continue, with hackers targeting devices in the AI infrastructure, printers, smart home, and wellness categories on the second day, alongside further attempts on the Samsung Galaxy S26 and Google Pixel 10. The third day will see additional attempts against the Google Pixel 10 and Samsung Galaxy S26, as well as various smart home, AI infrastructure, and printer devices.

Last year's Pwn2Own Ireland event saw security researchers earn $1,024,750 for uncovering 73 zero-day flaws. The Summoning Team, for instance, collected $187,500 after successfully hacking the Samsung Galaxy S25, Synology DiskStation DS925+ NAS, Home Assistant Green, Synology ActiveProtect Appliance DP320 NAS drive, Synology CC400W camera, and QNAP TS-453E NAS.

zero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

security

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

ai

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.