Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, global, zero-day] · confidence: high · severity: high · affected_sectors: [global] · au_impact: true

On the opening day of Pwn2Own Ireland 2026, researchers earned US$388,500 across seven product categories, exploiting 32 zero-days — including chains against the Samsung Galaxy S26 (hacked three times), the Philips Hue Bridge Pro (seven zero-days linked), the Oracle Autonomous AI Database (five-zero-day chain), and a single argument-injection bug that took down the OpenAI Codex cloud AI coding agent. Lexmark and Canon multifunction printers, the Sonos Era 300 and LiteLLM were also hit; a wellness healthcare-devices category was among new targets. Vendors get 90 days to patch before Trend Micro's ZDI discloses. Because exploits are revealed to vendors first, Pwn2Own itself is not an incident, but the sheer volume of novel chains — 32 on day one — underscores how many unknown weaknesses remain across mainstream consumer and AI-infrastructure software that attackers could find independently. The contest runs to the third day hunting Pixel 10, S26, smart-home and AI devices.

Attribute Detail
Sector Global (Macro)
Date 2026-10-07
Source BleepingComputer
Reliability Tier 2