By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Earn $1.26M for 98 Zero-Days at Pwn2Own Ireland
The Pwn2Own Ireland 2026 hacking competition concluded this week, with cybersecurity researchers earning a total of $1,262,000 by successfully exploiting 98 previously unknown vulnerabilities, referred to as zero-days. These exploits targeted a range of software and hardware products, demonstrating significant security weaknesses that could be leveraged by malicious actors. The event, organized by Trend Micro's Zero Day Initiative (ZDI), serves as a critical platform for identifying and mitigating security flaws before they can be exploited in the wild.
Among the notable successes, a team of researchers identified as "360 Stars" achieved the highest earnings, securing $450,000 for demonstrating a chain of exploits against a Western Digital My Cloud Pro NAS device. This exploit allowed them to gain full administrative control over the device, a critical finding for users relying on network-attached storage for sensitive data. Another significant achievement was by the "QAX" team, who earned $300,000 for exploiting a zero-day vulnerability in the Synology DS920+ NAS, also gaining administrative control. These findings highlight the persistent security challenges associated with network-attached storage devices, which often store vast amounts of personal and business data.
The competition also saw exploits targeting enterprise-grade software and hardware. The "Synacktiv" team was awarded $200,000 for demonstrating a remote code execution vulnerability in the VMware ESXi hypervisor, a foundational technology for many cloud computing environments. This exploit could have far-reaching implications for cloud security. Additionally, researchers successfully exploited vulnerabilities in products such as the Ubiquiti UniFi Dream Machine Pro, earning $150,000, and the TP-Link Archer AX6000 router, for which they received $100,000. The ZDI also awarded $62,000 for an exploit targeting the Western Digital My Cloud Pro NAS, demonstrating multiple successful attacks against the same product line.
Across all successful exploits, a total of 98 zero-day vulnerabilities were disclosed and rewarded. The ZDI, which manages the Pwn2Own events, purchases these vulnerabilities from researchers and then responsibly discloses them to the affected vendors for patching. This process is crucial for improving the overall security posture of widely used technologies. The substantial payouts reflect the high value placed on discovering and reporting these critical security flaws, incentivizing ethical hacking and contributing to a more secure digital ecosystem. The success of Pwn2Own Ireland 2026 underscores the ongoing need for rigorous security testing and prompt vendor responses to emerging threats.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.