Thezdi Pwn2Own Ireland 2026: Samsung Galaxy S26 Hacked Multiple Times
Article Content
- •Samsung Galaxy S26 was hacked three times on the first day of Pwn2Own Ireland 2026.
- •A total of 32 zero-day vulnerabilities were exploited, leading to $388,500 in rewards.
- •VinSOC's team achieved a notable seven-zero-day exploit against the Philips Hue Bridge Pro.
During the Pwn2Own Ireland 2026 competition, security researchers exploited the Samsung Galaxy S26 three times, earning a total of $388,500. The event, which began on October 6, 2026, featured 32 zero-day vulnerabilities across various devices, including smart devices and printers. Notably, Nguyen Thanh Dat of Viettel Cyber Security and teams from Interrupt Labs and Ikotas Labs successfully targeted the Galaxy S26, with some exploits involving previously known vulnerabilities. VinSOC's researchers also demonstrated a seven-zero-day exploit against the Philips Hue Bridge Pro, earning an additional $40,000. The competition is organized by the Zero Day Initiative, which aims to identify vulnerabilities before they can be exploited by malicious actors. Vendors have 90 days to release security updates after flaws are disclosed. The event continues over three days, with more hacking attempts scheduled against various devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track Philips Hue and CVE-2026-58704 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many zero-days were exploited?
What devices were targeted?
What is the prize for successful exploits?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…