Original Article Text

Click to Toggle View

Over 70 zero-day flaws get hackers $1 million at Pwn2Own Ireland. The fourth day of Pwn2Own Ireland 2024 marked the end of the hacking competition with more than $1 million in prizes for over 70 unique zero-day vulnerabilities in fully patched devices. The hacking contest pits security researchers against various software and hardware products, in an attempt earn the "Master of Pwn" title by compromising targets in eight categories ranging from mobile phones, messaging apps, home automation, and smart speakers to printers, surveillance systems, network-attached storage (NAS), and SOHO Smash-up. This edition of Pwn2Own was the fourth consecutive one where white-hat hackers passed over the million-dollar prize mark, earning a total of $1,066,625. During the last day of the competition, security researchers successfully exploited devices from Lexmark, True NAS, and QNAP: Viettel Cyber Security received the "Master of Pwn" award for collecting a total of 33 Master of Pwn points. They earned $205,000 for the flaws demonstrated in QNAP NAS, Sonos speakers, and Lexmark printers. The next Pwn2Own event is scheduled for January 22, 2025, and will happen in Tokyo, Japan. The event focuses on the automotive industry and has four categories for participants: Tesla, In-Vehicle Infotainment (IVI), Electric Vehicle Chargers, and Operating Systems. Zero Day Initiative (ZDI) has published details about the categories and the money prizes for successful exploitation. The rules of the competition are available here.

Daily Brief Summary

MISCELLANEOUS // Over 70 Zero-Day Vulnerabilities Exposed in Pwn2Own Ireland 2024

Over $1 million was awarded in prizes at the Pwn2Own Ireland 2024 for discovering over 70 zero-day vulnerabilities across various fully patched devices.

The competition tested security on multiple categories including mobile phones, messaging apps, home automation systems, smart speakers, printers, surveillance systems, NAS devices, and SOHO Smash-up.

Viettel Cyber Security won the "Master of Pwn" title, securing $205,000 in prize money for vulnerabilities found in QNAP NAS, Sonos speakers, and Lexmark printers.

The event achieved a milestone by surpassing the million-dollar prize mark for the fourth consecutive year, with a total prize payout of $1,066,625.

Targets successfully exploited on the final day included products from Lexmark, True NAS, and QNAP.

The next Pwn2Own event is scheduled for January 22, 2025 in Tokyo, focusing on the automotive industry with categories aimed at Tesla, In-Vehicle Infotainment (IVI) systems, Electric Vehicle Chargers, and Operating Systems.

Details about the upcoming competition's categories and prize money were outlined by the Zero Day Initiative (ZDI).