Security

Security Researchers Uncover 32 Zero-Day Flaws, Earn Nearly $400,000 on First Day of Pwn2Own Ireland

By

DUBLIN, IRELAND – Security researchers have collectively earned $388,500 and uncovered 32 zero-day vulnerabilities on the opening day of Pwn2Own Ireland 2026, a prominent ethical hacking competition. The event, which began on October 6 and is scheduled to run until October 9, 2026, showcases the discovery of previously unknown software flaws in popular consumer and enterprise products. As of October 7, Day Two of the competition is underway.

Among the most targeted devices on Day One was Samsung's Galaxy S26 smartphone, which was successfully exploited three times. Nguyen Thanh Dat of Viettel Cyber Security managed to breach the device using four bugs, three of which were already known to Samsung, earning $31,250 and 3.25 Master of Pwn points, as reported by Bleeping Computer on October 6, 2026. Interrupt Labs also successfully exploited the Galaxy S26 with four bugs, including three collisions and one zero-day, receiving $15,750 and 3.25 Master of Pwn points. A third successful attempt by Ikotas Labs combined four bugs, one of which was known but unpatched, earning them $11,000 and 4.5 Master of Pwn points.

In contrast, Google's Pixel 10 smartphone proved more resilient against a high-stakes remote exploit attempt. Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Pixel 10 in an attempt valued at $300,000 and 30 Master of Pwn points. However, their exploit did not work within the allotted time, as detailed by Bleeping Computer on October 6, 2026, and Zero Day Initiative on October 5, 2026. The Pixel 10 is slated for another attempt on Day Two, with KAIST Hacking Lab's Kyeongmin Kim scheduled to target the device over USB for a potential prize of $75,000 and 7.5 Master of Pwn points, according to Zero Day Initiative on October 5, 2026.

Beyond mobile devices, researchers successfully breached a range of other software and hardware targets. Taisic Yun of Xint successfully obtained a reverse shell on LiteLLM by using an improper input validation bug along with code injection. This exploit earned Yun $40,000 and 4 Master of Pwn points, a fact confirmed by CyberInsider on October 6, 2026, and Infosecurity Magazine on October 7, 2026.

Smart home and enterprise systems were also vulnerable. McCaulay Hudson exploited the Sonos Era 300, earning $50,000 and five points. Another team from VinSOC, linhlhq and Son Dinh, also exploited the Sonos Era 300, adding $17,500 and 3.5 points to their team's tally. VinSOC's Vũ Chí Thành and Huỳnh Đức Tin earned $40,000 for a seven-zero-day exploit against the Philips Hue Bridge Pro. The VinSOC team further demonstrated their prowess by earning another $40,000 for an exploit involving five vulnerabilities targeting Oracle's Autonomous AI Database. These successes were widely reported by outlets including CyberInsider and atlabyte on October 6, 2026.

OpenAI Codex, an artificial intelligence system, was also successfully breached. Ikotas Labs, Inc. exploited OpenAI Codex using a single argument-injection bug, adding another significant target to the list of compromised systems on Day One. This was noted by CyberInsider and Bleeping Computer on October 6, 2026.

VinSOC currently leads the competition's leaderboard, having accumulated $97,500 in earnings from Day One. Their total includes the $40,000 for the Philips Hue Bridge Pro, $40,000 for the Oracle Autonomous AI Database, and $17,500 for one of the Sonos exploits, according to CyberInsider and Pwn2Own Ireland 2026 - Day One Results on October 6, 2026.

The Pwn2Own competition serves a critical role in cybersecurity by encouraging the responsible disclosure of vulnerabilities. Vendors whose products are successfully exploited are given 90 days to develop and release security updates before the Zero Day Initiative publicly discloses the details of the vulnerabilities. The specific technical details, such as CVE IDs, tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and actionable defense guidance, are not publicly disclosed during the live competition.

As Day Two unfolds, the final total prize money and the complete count of zero-days discovered for the entire Pwn2Own Ireland 2026 competition remain unknown. The outcome of KAIST's scheduled attempt to hack the Pixel 10 over USB is also yet to be determined, as is the ultimate winner of the coveted "Master of Pwn" title for the competition.