Thezdi Pwn2Own Ireland 2026: Samsung Galaxy S26 Hacked Multiple Times
Article Content
- •Samsung Galaxy S26 was hacked three times on the first day of Pwn2Own Ireland 2026.
- •A total of 32 zero-day vulnerabilities were exploited, leading to $388,500 in rewards.
- •VinSOC's team achieved a notable seven-zero-day exploit against the Philips Hue Bridge Pro.
During the Pwn2Own Ireland 2026 competition, security researchers exploited the Samsung Galaxy S26 three times, earning a total of $388,500. The event, which began on October 6, 2026, featured 32 zero-day vulnerabilities across various devices, including smart devices and printers. Notably, Nguyen Thanh Dat of Viettel Cyber Security and teams from Interrupt Labs and Ikotas Labs successfully targeted the Galaxy S26, with some exploits involving previously known vulnerabilities. VinSOC's researchers also demonstrated a seven-zero-day exploit against the Philips Hue Bridge Pro, earning an additional $40,000. The competition is organized by the Zero Day Initiative, which aims to identify vulnerabilities before they can be exploited by malicious actors. Vendors have 90 days to release security updates after flaws are disclosed. The event continues over three days, with more hacking attempts scheduled against various devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Canon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many zero-days were exploited?
What devices were targeted?
What is the prize for successful exploits?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…