Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Yesterday marked a significant day for cybersecurity researchers and vendors alike as the Pwn2Own Ireland 2026 competition kicked off. The event, organized by the Zero Day Initiative (ZDI), brings together some of the world’s top security experts to identify zero-day vulnerabilities in various devices before malicious actors can exploit them.

The first day of the competition saw an impressive display of hacking prowess as teams competed to find and exploit flaws in a range of devices. The highlight was undoubtedly the Samsung Galaxy S26, which was successfully hacked not once but twice by different teams. One team, Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security, demonstrated their skills by exploiting 32 zero-days on the flagship device, earning a whopping $388,500 in the process.

However, it’s worth noting that some of the bugs exploited during the challenge were already known to the vendor. This raises important questions about the relationship between vendors and security researchers. While vendors often publicly disclose vulnerabilities and patch them before they can be exploited by attackers, this approach may not always prioritize the speed at which patches are released.

The competition also saw other notable exploits, including a demonstration of LiteLLM zero-days on the Samsung Galaxy S26, as well as hacks targeting printers from Lexmark and Canon. Additionally, security researchers were able to take down the OpenAI Codex cloud-based AI coding agent with just a single argument-injection bug.

As we move into the second day of the competition, hackers will again target devices in various categories, including AI infrastructure, smart home devices, and printers. Vendors have 90 days to release security updates before Trend Micro’s ZDI publicly discloses them. The pressure is on for vendors to prioritize patching these vulnerabilities quickly to prevent attackers from exploiting them.

The Pwn2Own Ireland competition serves as a stark reminder of the importance of prioritizing cybersecurity in our increasingly connected world. As we rely more heavily on devices and software, the potential for exploitation grows exponentially. It’s essential that both vendors and security researchers work together to identify and patch vulnerabilities quickly, preventing malicious actors from taking advantage.

In practical terms, this competition highlights the need for individuals and organizations to stay vigilant when it comes to updating their software and devices. Even if a vulnerability is already known to the vendor, it’s still crucial to apply patches as soon as they become available. By doing so, we can significantly reduce our exposure to exploitation by attackers.


Source: Bleeping Computer — 2026-10-06