惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 聂微东
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
美团技术团队
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
罗磊的独立博客
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
The Cloudflare Blog
Stack Overflow Blog
Stack Overflow Blog
N
Netflix TechBlog - Medium
小众软件
小众软件

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Ex...
Pierluigi Pa · 2026-05-16 · via Security Affairs

Day two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities over two days.

During the second day of Pwn2Own Berlin 2026, security researchers earned $385,750 after successfully demonstrating 15 unique zero-day vulnerabilities affecting products such as Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. Combined with the first day of the competition, total rewards have reached $908,750 for 39 unique vulnerabilities discovered across two days, with another day of hacking still remaining.

Going into day two, DEVCORE held a commanding lead built almost entirely on Orange Tsai’s four-logic-bug Edge sandbox escape from the previous day.

Microsoft Exchange and Windows 11 were successfully exploited during the second day of Pwn2Own Berlin 2026. Researcher Siyeon Wi demonstrated a Windows 11 privilege escalation flaw caused by an integer overflow bug, earning $7,500. Multiple successful attacks against fully patched Windows 11 systems across two days highlighted the presence of serious real-world vulnerabilities in widely used software.

Ben Koo of Team DDOS had a clean win on Red Hat Enterprise Linux for Workstations, leveraging a use-after-free bug to escalate privileges and earning $10,000.

AI-focused attacks continued during Pwn2Own Berlin 2026 as researcher Byung Young Yi targeted LiteLLM. His exploit matched a vulnerability already demonstrated earlier in the competition, resulting in a collision rather than a new zero-day. He still earned $17,750 and partial Master of Pwn points, highlighting the intense scrutiny researchers placed on LiteLLM throughout the event.

Le Duc Anh Vu of Viettel Cyber Security successfully exploited Cursor, earning $30,000 and 3 Master of Pwn points in a full Pwn2Own win.

Compass Security successfully exploited the AI-powered code editor Cursor during Pwn2Own Berlin 2026, earning $15,000. The attack, alongside earlier exploits targeting OpenAI Codex, highlights growing security risks across AI-assisted developer tools and infrastructure.

Some exploits failed at Pwn2Own Berlin 2026, including Safari and SharePoint attempts that did not work within the time limit. Researchers still showed strong effort, but live conditions and strict timing made reliable exploitation difficult even for well-prepared teams targeting fully patched systems.

DEVCORE leads Pwn2Own Berlin 2026 with 40.5 points and $405,000, but the competition is still open with one day remaining and high-value targets like Firefox and AI systems still ahead. A single successful exploit could change the rankings.

Across two days, researchers demonstrated 39 unique zero-days across widely used software, including operating systems, AI tools, and enterprise platforms, all running fully patched versions. The results highlight how skilled attackers can still find weaknesses even in mature systems. Vendors now have 90 days to patch the vulnerabilities disclosed during the event, turning live exploitation into coordinated disclosure instead of real-world attacks.

Pwn2Own Berlin 2026 day one saw 22 entries and 24 zero-days across major software, with researchers earning $523,000 in total rewards.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Pwn2Own Berlin 2026)