Pwn2Own Ireland 2026: Ethical Hackers Uncover 32 Zero-Days, Breaching Samsung, OpenAI & Oracle
The world’s leading ethical hackers gathered in Cork, Ireland for Pwn2Own Ireland 2026. This event, organized by Trend Micro’s Zero Day Initiative (ZDI), saw the discovery of 32 unique zero-day vulnerabilities on the first day, earning a remarkable $388,500 in prize money.
High-profile targets were compromised across seven categories: smartphones, printers, smart home devices, AI infrastructure, AI coding tools, messengers, and a newly introduced wearable and medical health devices category. The most significant breaches included successful attacks on the Samsung Galaxy S26, the exploitation of OpenAI Codex using a single argument-injection bug, a code injection vulnerability in LiteLLM, and a chain of five zero-days to breach Oracle’s Autonomous AI Database.
The top-performing team, VinSOC (Vũ Chí Thành and Huỳnh Đức Tin), earned $80,000 — $40,000 for a seven-vulnerability chain against the Philips Hue Bridge Pro and another $40,000 for the Oracle database exploit. A four-vulnerability chain also brought down the Sonos Era 300 smart speaker.
It’s important to note that these were controlled contest demonstrations, not live attacks. In line with ZDI policy, affected vendors receive private notification and have up to 90 days to patch vulnerabilities before public disclosure. The competition continues until October 9, 2026.
Source: Infosecurity Magazine | Atlabyte
