惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
量子位
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
Google DeepMind News
Google DeepMind News
小众软件
小众软件
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
雷峰网
雷峰网
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Ex...
Pierluigi Pa · 2026-05-16 · via Security Affairs

Day two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities over two days.

During the second day of Pwn2Own Berlin 2026, security researchers earned $385,750 after successfully demonstrating 15 unique zero-day vulnerabilities affecting products such as Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. Combined with the first day of the competition, total rewards have reached $908,750 for 39 unique vulnerabilities discovered across two days, with another day of hacking still remaining.

Going into day two, DEVCORE held a commanding lead built almost entirely on Orange Tsai’s four-logic-bug Edge sandbox escape from the previous day.

Microsoft Exchange and Windows 11 were successfully exploited during the second day of Pwn2Own Berlin 2026. Researcher Siyeon Wi demonstrated a Windows 11 privilege escalation flaw caused by an integer overflow bug, earning $7,500. Multiple successful attacks against fully patched Windows 11 systems across two days highlighted the presence of serious real-world vulnerabilities in widely used software.

Ben Koo of Team DDOS had a clean win on Red Hat Enterprise Linux for Workstations, leveraging a use-after-free bug to escalate privileges and earning $10,000.

AI-focused attacks continued during Pwn2Own Berlin 2026 as researcher Byung Young Yi targeted LiteLLM. His exploit matched a vulnerability already demonstrated earlier in the competition, resulting in a collision rather than a new zero-day. He still earned $17,750 and partial Master of Pwn points, highlighting the intense scrutiny researchers placed on LiteLLM throughout the event.

Le Duc Anh Vu of Viettel Cyber Security successfully exploited Cursor, earning $30,000 and 3 Master of Pwn points in a full Pwn2Own win.

Compass Security successfully exploited the AI-powered code editor Cursor during Pwn2Own Berlin 2026, earning $15,000. The attack, alongside earlier exploits targeting OpenAI Codex, highlights growing security risks across AI-assisted developer tools and infrastructure.

Some exploits failed at Pwn2Own Berlin 2026, including Safari and SharePoint attempts that did not work within the time limit. Researchers still showed strong effort, but live conditions and strict timing made reliable exploitation difficult even for well-prepared teams targeting fully patched systems.

DEVCORE leads Pwn2Own Berlin 2026 with 40.5 points and $405,000, but the competition is still open with one day remaining and high-value targets like Firefox and AI systems still ahead. A single successful exploit could change the rankings.

Across two days, researchers demonstrated 39 unique zero-days across widely used software, including operating systems, AI tools, and enterprise platforms, all running fully patched versions. The results highlight how skilled attackers can still find weaknesses even in mature systems. Vendors now have 90 days to patch the vulnerabilities disclosed during the event, turning live exploitation into coordinated disclosure instead of real-world attacks.

Pwn2Own Berlin 2026 day one saw 22 entries and 24 zero-days across major software, with researchers earning $523,000 in total rewards.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Pwn2Own Berlin 2026)