Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake AI Chatbot Ads Steal Passwords, MFA Codes
October 7, 2026
Cybersecurity Awareness Month 2026: Protect Your Business from Evolving Threats
October 7, 2026
Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex
October 7, 2026
Home/CyberSecurity News/Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex
CyberSecurity News

Pwn2Own 2026 Sees 32 Zero-Days Exploit Samsung S26, Pixel 10, OpenAI Codex

Key Takeaways The Pwn2Own Ireland 2026 competition saw 32 new zero-day vulnerabilities disclosed on its opening day. Exploits successfully targeted the Samsung Galaxy S26, OpenAI Codex, various smart...

Sarah simpson
Sarah simpson
October 7, 2026 5 Min Read
3 0

Key Takeaways

  • The Pwn2Own Ireland 2026 competition saw 32 new zero-day vulnerabilities disclosed on its opening day.
  • Exploits successfully targeted the Samsung Galaxy S26, OpenAI Codex, various smart home devices, and AI services.
  • Researchers earned a total of $388,500 in prize money for these discoveries.
  • While a Google Pixel 10 attempt failed to execute within the time limit, the event underscored widespread security gaps across modern technology.

Pwn2Own Ireland 2026: A Torrent of Zero-Days on Day One

The inaugural day of Pwn2Own Ireland 2026 witnessed a significant disclosure of 32 distinct zero-day vulnerabilities, leading to payouts totaling $388,500. Elite security researchers showcased working exploits against a diverse array of targets, including the Samsung Galaxy S26 smartphone, OpenAI Codex, various smart home devices, and critical AI services. While a planned exploit against the Google Pixel 10 did not materialize within the competition’s strict time constraints, the event on October 6, 2026, highlighted profound security weaknesses spanning across consumer electronics and advanced artificial intelligence platforms.

Table Of Content

  • Key Takeaways
  • Pwn2Own Ireland 2026: A Torrent of Zero-Days on Day One
  • Samsung Galaxy S26 Exploit Chains Unveiled
  • AI Services Targeted
  • Smart Devices and Printer Flaws Discovered
  • What You Should Do

Day 1 is officially wrapped with quite a pot of gold being awarded across the teams! Checkout a snapshot of where the leaderboard stands as of today – more to come over the next two days so keep following along as we post live updates! #Pwn2Own #Pwn2OwnIreland

For full… pic.twitter.com/b7TNYrOQIK

— TrendAI Zero Day Initiative (@thezdi) October 6, 2026

The initial day’s findings underscore the pervasive nature of security vulnerabilities, impacting devices ranging from personal communication tools to the foundational software powering AI development. The Zero Day Initiative (ZDI), organizers of Pwn2Own, confirmed 21 distinct entries for the first day, with several successful attempts leveraging combinations of newly discovered flaws and bugs already known to vendors.

Samsung Galaxy S26 Exploit Chains Unveiled

The Samsung Galaxy S26 proved to be a vulnerable target, with three separate teams successfully demonstrating exploits. According to ZDI’s official results, each successful attack utilized a chain of four vulnerabilities. The prize money awarded varied based on whether the exploited bugs were entirely new or overlapped with previously reported issues, known as “collisions.”

Nguyen Thanh Dat from Viettel Cyber Security secured $31,250 by employing one novel vulnerability alongside three flaws already known to the vendor. @InterruptLabs received $15,750 for their exploit chain, which included one zero-day and three collisions. Ikotas Labs earned $11,000 for an attack leveraging three new bugs and one vulnerability that Samsung was aware of but had not yet patched.

Another Collision 💥 4 bugs – 3 collisions & 1 zero-day successfully exploit the Samsung Galaxy S26 and Interrupt Labs (@InterruptLabs) takes home $15,750 and 3.25 Master of Pwn points #Pwn2Own pic.twitter.com/DP3KBnrVBd

— TrendAI Zero Day Initiative (@thezdi) October 6, 2026

These varying payouts highlight the distinction between a successful exploit demonstration and the discovery of entirely new vulnerabilities. ZDI’s rules account for “collisions,” where a bug in an exploit chain has been previously reported, leading to adjusted prize amounts while still recognizing the technical achievement of a working attack.

Conversely, the Google Pixel 10 remained unexploited on day one. Researchers Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club were unable to complete their exploit within the allocated timeframe. This outcome does not definitively indicate the absence of vulnerabilities in the device, but rather the challenge of executing a complex exploit under contest conditions.

AI Services Targeted

Artificial intelligence platforms also fell victim to skilled researchers. Ikotas Labs successfully exploited OpenAI Codex using a single argument injection flaw, earning $40,000. While ZDI confirmed the bug type, specific exploit details, affected versions, or a CVE identifier were not immediately released in the day-one summary.

Taisic Yun of Xint demonstrated a significant compromise against LiteLLM, achieving a reverse shell through a combination of improper input validation and code injection. This critical access, which establishes a command-line connection back from the target system, earned the researcher $40,000. Out of Bounds also exploited LiteLLM, chaining four bugs (two previously known) for a $15,000 prize. Additionally, VinSOC successfully chained five vulnerabilities to compromise the Oracle Autonomous AI Database, securing $40,000, though their separate attempt against Chroma was unsuccessful.

Smart Devices and Printer Flaws Discovered

Smart home technology and enterprise printers were also subject to successful attacks. VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin disclosed seven zero-day vulnerabilities in the Philips Hue Bridge Pro, earning $40,000. Other successful attempts against Hue devices involved a higher proportion of known bugs, further illustrating the difference between the total number of exploited flaws and unique discoveries.

McCaulay Hudson secured $50,000 by exploiting the Sonos Era 300, combining an out-of-bounds write with a format string flaw. These vulnerability classes typically involve dangerous memory access or improper handling of formatted text, although specific technical details were withheld by ZDI.

Enterprise printers were not immune, as the Lexmark CX532adwe was successfully attacked by both Thanh Do of Team Confused and Sina Kheirkhah of Summoning Team. Interrupt Labs also earned $20,000 for exploiting the Garmin Index BPM through a chain of out-of-bounds read and write vulnerabilities.

It is important to note that these demonstrations occurred within the controlled environment of the Pwn2Own competition and do not represent active attacks against real-world users. The primary purpose of Pwn2Own is to identify and responsibly disclose vulnerabilities to vendors, enabling them to develop and deploy patches before malicious actors can exploit them.

What You Should Do

  • Apply Vendor Patches Promptly: Keep all software and devices updated with the latest security patches from vendors like Samsung, OpenAI, Oracle, Philips, Sonos, Lexmark, and Garmin.
  • Monitor Vendor Advisories: Stay informed about official security advisories and vulnerability disclosures from affected product manufacturers.
  • Implement Least Privilege: Ensure that AI services and smart devices operate with the minimum necessary permissions to limit the impact of potential exploits.
  • Network Segmentation: Isolate smart home devices and critical AI infrastructure on separate network segments to contain potential breaches.
  • Regular Security Audits: Conduct frequent security audits and penetration testing, especially for AI-driven applications and critical infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical OpenSSH Flaws Allow Plaintext Recovery, File Write, and Injection

Next Post

Cybersecurity Awareness Month 2026: Protect Your Business from Evolving Threats

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Veeam Backup & Replication Vulnerability Lets Attackers Run Malicious Code
October 7, 2026
The Best IAST Tools of 2024: Ranked and Reviewed
October 7, 2026
Google Chrome Update Patches 247 Vulnerabilities, Including 4 Code Execution Flaws
October 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us