Thursday , July 30 2026
90 zero-day

Hackers exploit 90 zero days earn $1.3 in two days

Security researchers earned a combined $1,315,250 in cash rewards after exploiting 90 zero-day vulnerabilities during the first two days of Pwn2Own Ireland 2025, organized by Trend Micro’s Zero Day Initiative (ZDI) in Cork.

On Day 1, participants demonstrated 34 new vulnerabilities, earning $522,500 by breaching printers, NAS devices, routers, and smart home products. The top $100,000 “SOHO Smashup” prize went to researchers who chained exploits targeting QNAP Qhora-322 routers and QNAP TS-453E NAS devices. Other highlights included $50,000 for attacks on the Synology ActiveProtect DP320 and Sonos Era 300, alongside successful hacks on Home Assistant Green, Philips Hue Bridge, Canon, and HP printers.

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

On Day 2, hackers uncovered 56 additional zero-days, collecting $792,750. The standout moment was Ken Gannon (Mobile Hacking Lab) and Dimitrios Valsamaras (Summoning Team) breaching the Samsung Galaxy S25 via a five-bug exploit chain, earning $50,000 and 5 Master of Pwn points. Other teams, including CyCraft Technology, Verichains Cyber Force, and Synacktiv, won $20,000 each for compromising QNAP, Synology, and Philips Hue devices.

The Summoning Team currently leads the Master of Pwn leaderboard with 18 points and $167,500 in earnings.

The contest—co-sponsored by Meta, Synology, and QNAP—runs from October 21–24, featuring challenges across smartphones, NAS devices, printers, messaging apps, smart home gear, and wearables.

On the final day, researchers aim for the ultimate prize: a $1 million reward for a WhatsApp zero-click remote code execution exploit. Vendors now have 90 days to patch all reported vulnerabilities before public disclosure.

Check Also

National Cyber Drill 2026

NCSA opens registration for “National Cyber Drill- 2026”

National Cyber Security Agency (NCSA), under the Information and Communication Technology Division of Bangladesh, has …