Find notable cyber news and cases, enriched with sources, timelines, and signals.

Pwn2Own Ireland 2026 multi-product zero-day flaws security flaw

Vulnerability
First reported
Last updated
Happening score
H score 0
1 unique sources, 1 articles

Summary

Hide ▲

On October 6, 2026, Pwn2Own Ireland 2026 produced 32 zero-day vulnerabilities across smartphones, smart home devices, printers, and AI tools. Targets included OpenAI Codex, LiteLLM, Sonos Era 300, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, and Garmin Index BPM. The day-one results showed working exploit chains against multiple products, including reverse shell and code execution paths. The discoveries entered responsible disclosure, leaving vendors with a limited window to ship fixes.

Related Happenings

Samsung Galaxy S26 zero-day exploitation security flaw

Vulnerability
H score24 First: 06.10.2026 22:21 Last: 06.10.2026 22:21 Sources 1

About this happening: Researchers twice compromised the Samsung Galaxy S26 on the first day of Pwn2Own Ireland 2026, showing active zero-day exposure on a flagship mobile target. The op...

Anthropic launches Project Glasswing with Claude Mythos for vulnerability discovery

Security Tool/Service
H score58 First: 08.04.2026 12:16 Last: 08.04.2026 12:16 Sources 1

About this happening: Anthropic’s Project Glasswing is now showing measurable results: since launching last month, the Claude Mythos Preview-based initiative has uncovered more than 10,000...

Latest development: 03.06.2026 14:00

President Donald Trump signed a June 2 executive order that sets up a voluntary framework for developers of covered frontier models to give the US government access for cybersecurity review for up to 30 days before release, while expressly rejecting any mandatory licensing or preclearance requirement. The order directs NSA, CISA, and NIST to build a classified benchmark for determining which models cross the covered threshold and creates an AI cybersecurity clearinghouse led by the Treasury Department. The framework closely echoes Anthropic's Project Glasswing, which gives vetted partners early access to Claude Mythos Preview to scan critical software for vulnerabilities.

Timeline

  1. 07.10.2026 12:25 1 articles · 2h ago

    Researchers exploit Sonos, LiteLLM, Philips Hue Bridge Pro, Lexmark, Oracle, OpenAI Codex, and Garmin devices on day one

    Exploitation Observed

    On October 6, 2026 in Cork, teams at Pwn2Own Ireland 2026 demonstrated working exploits against the Sonos Era 300, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, OpenAI Codex, and Garmin Index BPM using out-of-bounds write, format string, improper input validation, code injection, use-after-free, argument injection, and out-of-bounds read/write bugs.

    Show sources
  2. 07.10.2026 12:25 2 articles · 2h ago

    Pwn2Own Ireland 2026 day one yields 32 zero-days and over $368,000 in prizes

    Initial Disclosure

    The Zero Day Initiative said day one of Pwn2Own Ireland 2026 in Cork produced 32 zero-day vulnerabilities and more than $368,000 in prize money, and that findings are responsibly disclosed to relevant vendors under a 90-day update window before publication.

    Show sources