Pwn2Own Berlin 2026 Awards $908K For 39 Zero-Days
Day 3 of Pwn2Own Berlin 2026 wraps up with $908,750 awarded for 39 zero-days. Teams exploited Red Hat Linux and Windows 11 as the competition nears the million-dollar mark.
Day 3 of Pwn2Own Berlin 2026 wraps up with $908,750 awarded for 39 zero-days. Teams exploited Red Hat Linux and Windows 11 as the competition nears the million-dollar mark.
Threat actors are exploiting ChatGPT’s legitimate conversation-sharing feature to host convincing fake service outage pages that distribute malware. By leveraging OpenAI’s trusted domain reputation, attackers bypass security filters and trick users into downloading malicious payloads disguised as sy
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle WebLogic Server deserialization vulnerability (CVE-2020-14882) to its Known Exploited Vulnerabilities (KEV) catalog. This remote code execution flaw, originally patched in October 2020, is now being actively
An AI-powered fuzzing agent has uncovered 21 previously unknown zero-day vulnerabilities in FFmpeg, the ubiquitous multimedia processing library used by billions of devices worldwide. This discovery marks a significant milestone in automated vulnerability research, demonstrating AI’s capability to i
A critical zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273) has been actively exploited in the wild, resulting in a confirmed data breach at Nissan. The unauthenticated remote code execution flaw affects PeopleSoft versions 9.2 and earlier, allowing attackers to bypass authentication and
A sophisticated cloud attack technique called “bucket hijacking” enables threat actors to redirect legitimate cloud storage data streams to attacker-controlled external buckets. By exploiting misconfigured bucket permissions, dangling DNS references, and predictable naming conventions, adversaries c
A sophisticated malware strain dubbed TONResolver has emerged, leveraging The Open Network (TON) blockchain smart contracts as a dead drop resolver (DDR) mechanism for dynamic command-and-control (C2) infrastructure switching. This novel evasion technique exploits the immutable and decentralized nat
Fortinet has confirmed that multiple critical vulnerabilities in FortiSandbox are being actively exploited in the wild. The flaws, tracked as CVE-2024-27760 and CVE-2024-28649, allow unauthenticated attackers to execute arbitrary code remotely. Organizations using FortiSandbox versions 4.4.0 through
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in Microsoft Windows, Webmin, Fortinet FortiOS, and others. Federal agencies have until specified deadlines to patch these vulnerabilities, and private sector organi
A critical zero-day vulnerability dubbed “RoguePlanet” in Microsoft Defender allows attackers with basic user access to escalate privileges to SYSTEM-level control on Windows machines. The flaw exploits Defender’s built-in scanning mechanisms through a time-of-check-time-of-use (TOCTOU) race conditi