Skip to content

All the news that matters, in plain English.

Latest

Technology

Samsung Galaxy S26 hacked three times on day two of Pwn2Own Ireland

Security researchers collected $232,500 on day two of Pwn2Own Ireland 2026, with the Samsung Galaxy S26 hacked three separate times.

Navy Samsung Galaxy S25+ flagship smartphone photographed for illustration; Samsung flagships were among the phones hacked three times at the Pwn2Own Ireland 2026 cybersecurity competition
Photo: Jakub CA, via Wikimedia Commons

Security researchers collected $232,500 on day two of Pwn2Own Ireland 2026 after exploiting 45 unique zero-day vulnerabilities, BleepingComputer reported. The day’s headline act was the Samsung Galaxy S26, which was hacked three separate times — by KAIST Hacking Lab’s Kyeongmin Kim, by PetoWorks, and by a team of Dimitrios Valsamaras, Ken Gannon, and CENSUS Labs’ Tenia Valsamara.

Jack Dates of RET2 Systems demonstrated a Sonos Era 300 exploit chain in under a minute, while Out of Bounds’ HaeJung Yang took $40,000 for hacking Dynamo in the AI Infrastructure category. The Home Assistant Green smart home hub also fell, to PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec’s Yassine Bengana and Maxence Schmitt. Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.

Before the session, Kyeongmin Kim withdrew his USB-based attack attempt on the Google Pixel 10. CyberInsider reported the October 7 session brought the competition tally to $621,000 awarded for 77 unique zero-day vulnerabilities, including Interrupt Labs’ $5,000 Lexmark CX532adwe printer hack, which displayed DOOM on the device’s screen, and _McCaulay’s $10,000 Canon imageFORCE 1643F compromise via hard-coded credentials, missing authentication and command injection.

Organised by Trend Micro’s Zero Day Initiative in Cork, Ireland from 6 to 9 October 2026, the contest runs targets on the latest firmware and requires demonstrated arbitrary code execution; vendors get 90 days to patch before public disclosure. Apple’s iPhone 17, which carried a $300,000 maximum award for a remote hack, attracted no registered attempts.

More on this topic: all Technology stories

Get Flip News by email

This opens your email app — we add you manually. No account, no spam, no third parties.