Threat reportVulnerabilityTL-2026-2981

Pwn2Own Ireland 2026 Day 1: 32 zero-days demonstrated against Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle Autonomous AI Database, LiteLLM, OpenAI Codex, Sonos Era 300, Lexmark and Canon printers, and Garmin Index BPM

highMONITORING

Pwn2Own Ireland 2026 Day 1 (TL-2026-2981), also tracked as Pwn2Own Ireland 2026, is a high-severity software vulnerability, first published 2026-10-06 and last reviewed 2026-10-10. It has no confirmed attribution, affects Samsung Galaxy S26, maps to 6 MITRE ATT&CK techniques (T1059, T1068, T1190), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-2981

Threat ID
TL-2026-2981
Also known as
Pwn2Own Ireland 2026, Pwn2Own Cork 2026
Severity
HIGH
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer-electronics, smart-home, health, technology, enterprise-it, ai-ml
Target regions
Global
Detection rules
9
Indicators of compromise
16
Updates
2026-10-10 · revalidated 1× · latest source

Malware and tooling in Pwn2Own Ireland 2026 Day 1

Malware and tooling: OpenAI Codex

How Pwn2Own Ireland 2026 Day 1 works

On Day 1 of Pwn2Own Ireland 2026 (Cork, 6 October 2026), researchers demonstrated 32 zero-day vulnerabilities across consumer devices, printers, AI infrastructure and an AI coding agent, earning $388,500 according to BleepingComputer. Exploitation happened in a controlled contest, not in the wild. No CVE IDs or technical details are public, and vendors have 90 days to patch before ZDI discloses.

Pwn2Own Ireland 2026, organised by Trend Micro's Zero Day Initiative (ZDI), runs 6-9 October 2026 in Cork, Ireland. The rules define seven target categories: Mobile Phones, Smart Home, Wellness (new this year), Printers, Messaging (WhatsApp), AI Infrastructure, and AI Coding Agents. Contestants attack fully patched targets from a laptop on the contest network, or via the default browser or NFC/Wi-Fi/Bluetooth for phones.

BleepingComputer (Sergiu Gatlan, 2026-10-06) reports that 32 zero-days were exploited on Day 1 for $388,500 in total. The reported results are: Samsung Galaxy S26 hacked by Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat (Viettel Cyber Security), with some bugs 'already known to the vendor'; a seven-zero-day chain against the Philips Hue Bridge Pro ($40,000) and a five-zero-day chain against Oracle Autonomous AI Database ($40,000) by VinSOC researchers, $80,000 combined for Vu Chi Thanh and Huynh Duc Tin per BleepingComputer; LiteLLM zero-days; Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers; a single argument-injection bug in OpenAI Codex; four vulnerabilities in the Sonos Era 300; and an unsuccessful attempt on the Google Pixel 10 by White Noise Club.

The ZDI Day 1 results post lists per-entry detail for 21 entries. The BleepingComputer 'four vulnerabilities' on the Sonos Era 300 matches the sum of two entries, @_McCaulay (2 bugs: out-of-bounds write and format string, $50,000) and linhlhq and Son Dinh of VinSOC (2 bugs, 1 known, $17,500). Other confirmed entries: Taisic Yun (Xint) LiteLLM, 2 bugs (input validation and code injection, $40,000); Out of Bounds LiteLLM, 4 bugs with 2 known ($15,000); Thanh Do (Team Confused) Lexmark use-after-free ($20,000); Sina Kheirkhah (Summoning Team) Lexmark single bug ($10,000); Interrupt Labs Garmin Index BPM, out-of-bounds read and write ($20,000); Ikotas Labs OpenAI Codex argument injection ($40,000); Galaxy S26 entries by Nguyen Thanh Dat (4 bugs, 3 known, $31,250), Interrupt Labs (4 bugs, 3 known, $15,750) and Ikotas Labs (4 bugs, 1 known, $11,000); Hue Bridge Pro collisions by Out of Bounds (5 bugs, 4 known, $12,000) and Xint's Joohyun Park (5 bugs, 4 known, $6,000). Failed or non-working entries: Brother MFC-L8970CDW (Ikotas Labs), Lexmark CX532adwe (Team T-X Lab), Garmin Index BPM (Summoning Team), Google Pixel 10 (White Noise Club) and Chroma (VinSOC). The ZDI results page as fetched did not include the Canon imageFORCE 1643F entry or the end-of-day totals; the 32-zero-day and $388,500 figures are from BleepingComputer only. The listed ZDI rows sum to $368,500, so the remaining $20,000 would match one Canon payout at the listed $20,000 target price, but this is an inference, not a stated fact.

No CVE identifiers, CVSS scores, affected firmware versions or exploit details have been published. ZDI discloses vulnerabilities to vendors and, per BleepingComputer, vendors have 90 days to patch before public disclosure. The competition continues 7-9 October with further entries against the Pixel 10, Galaxy S26, Home Assistant Green, Oracle, Chroma, Dynamo, other AI targets and printers. The Day 1 total compares with 2025's event, which ended with 73 zero-days and $1,024,750. Defenders should treat this as a watch item: inventory the named products and prioritise the vendor patches expected after the disclosure window, in particular internet-exposed LiteLLM proxies, Oracle AI Database deployments and developer workstations running Codex.

MITRE ATT&CK techniques used in TL-2026-2981

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Resource Development

T1587.004 Develop Capabilities

Affected products and versions in Pwn2Own Ireland 2026 Day 1

  • Samsung — Galaxy S26
    Vulnerable versions: Unspecified
  • Philips — Hue Bridge Pro
    Vulnerable versions: Unspecified
  • Sonos — Era 300
    Vulnerable versions: Unspecified
  • Garmin — Index BPM
    Vulnerable versions: Unspecified
  • Lexmark — CX532adwe
    Vulnerable versions: Unspecified
  • Canon — imageFORCE 1643F
    Vulnerable versions: Unspecified
  • Oracle — Autonomous AI Database
    Vulnerable versions: Unspecified
  • BerriAI — LiteLLM
    Vulnerable versions: Unspecified
  • OpenAI — Codex
    Vulnerable versions: Unspecified

Remediation for Pwn2Own Ireland 2026 Day 1

Patches

  • No patches or CVEs are published yet; apply vendor fixes as they ship after ZDI's 90-day disclosure window (roughly early January 2027)

Immediate actions

  • Inventory deployments of the named products: Samsung Galaxy S26, Philips Hue Bridge Pro, Sonos Era 300, Garmin Index BPM, Lexmark CX532adwe, Canon imageFORCE 1643F, LiteLLM, Oracle Autonomous AI Database, OpenAI Codex
  • Keep device firmware and OS on automatic update and enrol in vendor security bulletin feeds
  • Do not expose LiteLLM proxy admin or API endpoints, printer management interfaces or smart-home hubs to the internet

Workarounds

  • Restrict management-plane access to trusted admin networks
  • Disable unneeded network services and remote-access features on printers and smart-home bridges

Longer-term hardening

  • Segment printers, IoT and smart-home devices onto isolated VLANs with no route to sensitive networks
  • Run AI coding agents with least-privilege tokens, allow-listed commands and sandboxed workspaces
  • Track ZDI advisories after the 90-day disclosure window and map each CVE to the asset inventory

Weaknesses (CWE) in Pwn2Own Ireland 2026 Day 1

CWE-787, CWE-416, CWE-134, CWE-88, CWE-94, CWE-20, CWE-125

Timeline of Pwn2Own Ireland 2026 Day 1

  • Pwn2Own Ireland 2025 Day One produced 34 zero-days against smart devices; the 2025 event ended with 73 zero-days and $1,024,750 awarded.
  • ZDI announced the Pwn2Own Ireland 2026 targets and categories, including new Wellness devices and AI Coding Agents.
  • Contest registration closed at 5:00 p.m. Irish Standard Time (limit of 80 entries).
  • ZDI published the full four-day schedule of entries; Day 1 order was drawn at random.
  • BleepingComputer published its Day 1 report; the ZDI results post lists the Pixel 10, Chroma, Brother and some Lexmark and Garmin entries as failures.
  • Day 1 in Cork: 21 entries, 32 zero-days reported by BleepingComputer, $388,500 awarded. Targets exploited included Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle Autonomous AI Database, LiteLLM, OpenAI Codex, Sonos Era 300, Lexmark CX532adwe, Garmin Index BPM and Canon imageFORCE 1643F.
  • Day Two: $232,500 for 45 unique zero-days, including three further Samsung Galaxy S26 compromises (KAIST Hacking Lab, PetoWorks, CENSUS Labs), Sonos Era 300 (Jack Dates, RET2 Systems), Dynamo, Home Assistant Green and further Oracle and Philips Hue entries; cumulative $621,000 for 77 zero-days. No iPhone 17 attempts.
  • Final day of the contest (Days 2-4 run 7-9 October with further entries against Pixel 10, Galaxy S26, Home Assistant Green, Oracle, Chroma, Dynamo and printers).
  • Approximate end of the 90-day vendor patch window counted from 2026-10-06, after which ZDI may publicly disclose unpatched flaws (derived date, not stated by the sources).

Update history for TL-2026-2981

Sources cited for Pwn2Own Ireland 2026 Day 1

Detection coverage for TL-2026-2981

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2981 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats