LIVE · cybersecurity feed
Live wire
vulnerability

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

ZeroDay News ·

Source: BleepingComputer

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

Ikotas Labs emerged as the top contender, securing 42.5 Master of Pwn points and $361,000 in prize money. Their successful exploits included the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database. On the final day of the competition, Ikotas Labs also claimed the highest single reward of $300,000 by chaining multiple zero-days to compromise the Google Pixel 10.

Xint placed second with $240,000 and 27.5 Master of Pwn points, while Team ZyGoat took third, earning $125,000 and 27.5 Master of Pwn points.

The first day of the contest saw competitors disclose 32 zero-day flaws, resulting in $388,500 in rewards. Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully exploited the Samsung Galaxy S26. However, Samsung had prior knowledge of some of the vulnerabilities used in these initial exploits.

On the second day, 45 unique zero-day vulnerabilities were demonstrated, with researchers collecting $232,500. Notably, PetoWorks, Kyeongmin Kim from KAIST Hacking Lab, and a team comprising Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs, successfully compromised the Galaxy S26 an additional three times.

The final day of the event was the most lucrative, with 21 zero-days exploited for $641,000 in cash. This included further successful attacks on the Samsung Galaxy S26 and three instances of the Google Pixel 10 being rooted.

This year's competition featured target categories such as mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding applications, messaging applications, smart home devices, printers, and a new category for wellness healthcare devices. Although Apple's iPhone 17 was a potential target with a $300,000 reward for a remote hack, no teams registered to attempt an exploit.

The Pwn2Own competition mandates that all targeted devices run the latest firmware versions and requires contestants to achieve arbitrary code execution. The disclosed zero-day vulnerabilities are reported to the respective vendors, who are then given 90 days to release patches before ZDI publicly releases the details.

The 2026 event surpassed the previous year's Pwn2Own Ireland, where hackers demonstrated 73 zero-day flaws and earned $1,024,750. In 2025, Summoning Team won the contest, collecting $187,500 for exploits against the Samsung Galaxy S25, Home Assistant Green, QNAP TS-453E NAS, and various Synology devices.

vulnerabilityzero-daycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

security

Co-creator of Empire Market dark web marketplace given 40-year sentence

Raheim Hamilton, a co-creator of the dark web marketplace Empire Market, has been sentenced to 40 years in federal prison for his role in operating the platform. The 30-year-old Virginia native pleaded guilty earlier this year to a drug conspiracy charge and was ordered by U.S. District Judge Steven Seeger to forfeit over $100 million in Bitcoin and several properties in Virginia, in addition…

breach

Thousands of wind and solar park systems sit exposed on the internet across Europe

A recent report by Modat and the Dutch government's cybersecurity center, NCSC-NL, has revealed that 8,547 industrial control systems at wind and solar energy facilities across 35 countries in and around the European Union are directly accessible from the internet. These systems, which should be isolated from public networks, range from basic login portals to turbine control interfaces…

ai

PCI SSC calls for human approval of AI agent actions involving cardholder data

The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of…

security

ICE Agent at NYC Shooting Has History of Alleged Violence and Illegal Arrests

An Immigration and Customs Enforcement (ICE) supervisor, Brenden Cuni, has been identified as an agent present at a shooting in New York City's Marble Hill neighborhood, near the Bronx, on Thursday. Cuni, who was seen brandishing a modified AR-15-style rifle at the scene, has a history of allegations of unlawful arrests and excessive force in federal court cases across New York and Minneapolis.

ai

Companies want autonomous IT operations but hesitate to let AI act alone

Ninety percent of companies anticipate a shift toward autonomous IT operations within the next two years, envisioning agentic AI systems that independently plan and execute multi-step tasks. However, a significant majority, 77 percent, express hesitation in allowing AI to make operational decisions without human approval. This suggests that most organizations currently aim for a model where a…