Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On October 6, 2026, the first day of Pwn2Own Ireland, researchers racked up $388,500 by exploiting 32 zero-day vulnerabilities across cutting-edge devices. The Samsung Galaxy S26 was compromised twice, but a critical caveat clouds the "zero-day" label: BleepingComputer reports that some of the bugs were already known to the vendors.
- 32 vulnerabilities exploited on day one for $388,500 in prizes, per BleepingComputer.
- Samsung Galaxy S26 hacked twice by Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security.
- VinSOC earned $80,000 total with complex chains against the Philips Hue Bridge Pro and Oracle Autonomous AI Database.
- The source specifies that some bugs were already known to the vendor, without quantifying how many of the 32 fall into this category.
Target Landscape and Teams in Play
The competition spanned seven categories: mobile smartphones (iPhone 17, Galaxy S26, Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and wellness healthcare devices. This diversification reflects an attack surface expanding well beyond traditional enterprise boundaries.
On the mobile front, the Galaxy S26 drew three distinct teams. Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security landed successful exploits. The counterpoint came from Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club, whose attempt against the Google Pixel 10 failed; the team could not get their exploit working within the allotted time. The source does not specify whether the failure stemmed from inherent device mitigations or timing issues in the attack chain.
The Highest-Paying Chains: Philips Hue and Oracle AI
The duo of Vũ Chí Thành and Huỳnh Đức Tin of VinSOC dominated the day with two complex exploits. They earned $40,000 for a seven-zero-day chain on the Philips Hue Bridge Pro, and another $40,000 for a five-zero-day chain on the Oracle Autonomous AI Database — $80,000 total in a single day.
Other compromised targets include LiteLLM, the LLM routing platform; the Lexmark CX532adwe printer; the Canon imageFORCE 1643F; and the Sonos Era 300 speaker, hit with four vulnerabilities. OpenAI Codex fell to a single argument-injection bug, a notable result for its technical economy compared to the multi-step chains.
"However, some of the bugs exploited in each challenge were already known to the vendor."
The Definition Problem: What Counts as a Zero-Day Here
BleepingComputer's qualification introduces an analytical tension the available data cannot resolve. In media narratives, "zero-day" means a vulnerability exploited before a patch is published; in ZDI's competitive practice, the official count may differ if it excludes bugs already known to the vendor.
The source does not quantify how many of the 32 fall into this category. Without a precise figure, it is impossible to determine whether the 32 figure represents a "gross" or "net" count relative to ZDI criteria. This ambiguity has consequences for anyone using Pwn2Own tallies to model risk: an organization should know whether the denominator includes vulnerabilities for which the vendor already has a patch in development.
The dossier also does not specify whether ZDI confirms the 32 count as pure zero-days for its own database. The potential discrepancy between media narrative and official criteria remains an open question.
Why It Matters
The dossier does not document specific mitigations released by vendors during the competition. ZDI's standard mechanism allows 90 days of coordinated disclosure, but the source does not verify the current patch status for any of the mentioned products.
The source does not specify the nature of data exposed in the various exploits, nor detail privilege-escalation or persistence mechanisms where applicable. Technical details of the exploit chains — which primitives were used, which checks bypassed, which attack surfaces are actually reachable remotely — are not included in the available material.
The brief does not document whether vendors have confirmed the vulnerabilities or planned specific advisories. The 2025 edition paid out $1,024,750 for 73 zero-days, per BleepingComputer; the quantitative comparison suggests an acceleration in competitive tempo, but without data on prize-assignment criteria it is impossible to determine whether this acceleration reflects more bugs, simpler bugs, or a different payout structure.
Chronicle and Perspective
The competition runs in a controlled format: exploits demonstrated in limited time on real devices, with delayed disclosure. No infrastructural overlap links the demonstrated actors to known threat-intelligence operations. The motive is competitive and economic, not criminal or state-sponsored.
The presence of AI targets — Oracle Autonomous AI Database, OpenAI Codex, LiteLLM — signals the emergence of this category as a structural attack surface, not an occasional one. The source does not clarify whether the LLM-specific vulnerabilities fall into known weakness classes (e.g., prompt injection, training-data extraction) or more conventional injection/validation bugs.
For organizations using the listed products, the only operationally relevant information is the documented existence of unpatched vulnerabilities at the time of the competition. The source provides no indicators of compromise, signatures, or detection criteria.
Sources
- https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
- https://blog.netmanageit.com/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/
- https://www.bleepingcomputer.com/vpn/
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.