On the opening day of the Pwn2Own Ireland 2026 competition, security researchers successfully exploited 32 zero-day vulnerabilities across various devices. These exploits resulted in payouts totaling $388,500 for the participating teams.
Key targets included the Samsung Galaxy S26, which was hacked twice, as well as Lexmark and Canon multifunction printers. Researchers also compromised a Sonos Era 300 smart speaker and demonstrated zero-days in LiteLLM.
The competition featured a range of categories, including mobile phones like the Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10. In the AI category, the OpenAI Codex cloud-based AI coding agent was taken down using a single argument-injection bug.
Teams like Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security were notable for their successful compromises of the Samsung Galaxy S26. Some exploited bugs were already known to the vendor.
The Zero Day Initiative (ZDI) organizes the Pwn2Own hacking competition to proactively identify zero-day vulnerabilities. This process allows vendors to address security flaws before malicious actors can exploit them in the wild.
Following a successful exploit at Pwn2Own, vendors are given a 90-day window to release security updates. After this period, Trend Micro's ZDI publicly discloses the vulnerabilities.
The competition is scheduled to continue with further attempts on devices in the AI infrastructure, printers, smart home, and wellness categories. The Samsung Galaxy S26 and Google Pixel 10 will also be targeted again on subsequent days.
Last year's Pwn2Own Ireland event saw researchers earn $1,024,750 for 73 zero-day flaws, with Summoning Team being a top earner for compromising various devices including the Samsung Galaxy S25 and several NAS systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers exploited 32 zero-day vulnerabilities on the first day of Pwn2Own Ireland 2026, earning $388,500. Exploits included the Samsung Galaxy S26, printers, smart home devices, and OpenAI Codex, highlighting ongoing efforts to identify and patch critical flaws in various technologies.