Security News

Windows 10 hacked again at Pwn2Own, Chrome and Zoom also fall
2021-04-08 14:33

Contestants hacked Microsoft's Windows 10 OS twice during the second day of the Pwn2Own 2021 competition, together with the Google Chrome web browser and the Zoom video communication platform. The first to demo a successful Windows 10 exploit on Wednesday and earn $40,000 was Palo Alto Networks' Tao Yan who used a Race Condition bug to escalate to SYSTEM privileges from a normal user on a fully patched Windows 10 machine.

$200,000 Awarded for Zero-Click Zoom Exploit at Pwn2Own
2021-04-08 11:13

Two researchers earned $200,000 on the second day of the Pwn2Own 2021 hacking competition for a Zoom exploit allowing remote code execution without user interaction. Also on the second day of Pwn2Own 2021, Bruno Keith and Niklas Baumstark of Dataflow Security earned $100,000 for an exploit that works both on the Chrome and Microsoft Edge web browsers.

Microsoft's Windows 10, Exchange, and Teams hacked at Pwn2Own
2021-04-07 13:51

During the first day of Pwn2Own 2021, contestants won $440,000 after successfully exploiting previously unknown vulnerabilities to hack Microsoft's Windows 10 OS, the Exchange mail server, and the Teams communication platform. The first to fall was Microsoft Exchange in the Server category after the Devcore team achieved remote code execution on an Exchange server by chaining together an authentication bypass and a local privilege escalation.

White Hats Earn $440,000 for Hacking Microsoft Products on First Day of Pwn2Own 2021
2021-04-07 10:48

On the first day of the Pwn2Own 2021 hacking competition, participants earned more than half a million dollars, including $440,000 for demonstrating exploits against Microsoft products. The competition's organizer, Trend Micro's Zero Day Initiative, said there were seven attempts on the first day and five of them were successful.

Pwn2Own 2021: Hackers Offered $200,000 for Zoom, Microsoft Teams Exploits
2021-01-27 09:49

Pwn2Own Vancouver typically takes place during the CanSecWest conference in Vancouver, Canada, but due to the coronavirus pandemic, this year's event will be hybrid - participants can submit their exploits remotely and ZDI staff in Toronto and Austin will run the exploits. The car is being offered to those who participate in the automotive category.

Routers, NAS Devices, TVs Hacked at Pwn2Own Tokyo 2020
2020-11-09 09:39

Bug bounty hunters have hacked routers, network-attached storage devices and smart TVs at the Zero Day Initiative's Pwn2Own Tokyo 2020 hacking competition. Due to the COVID-19 pandemic, the competition has been turned into a virtual event and Pwn2Own Tokyo is actually coordinated by Trend Micro's ZDI from Toronto, Canada, with participants demonstrating their exploits remotely.

NETGEAR Router, WD NAS Device Hacked on First Day of Pwn2Own Tokyo 2020
2020-11-06 15:52

Bug bounty hunters hacked a NETGEAR router and a Western Digital network-attached storage device on the first day of the Zero Day Initiative's Pwn2Own Tokyo 2020 hacking competition. On the first day of the event, the NETGEAR Nighthawk R7800 router was targeted by Team Black Coffee, Team Flashback, and teams from cybersecurity firms Starlabs and Trapa Security.

ZDI Announces Rules, Prizes for Pwn2Own Tokyo 2020
2020-07-29 10:08

Trend Micro's Zero Day Initiative on Tuesday announced the rules and prizes for its Pwn2Own Tokyo 2020 hacking competition, which invites white hat hackers to demonstrate their smartphone and IoT device exploits. Pwn2Own Tokyo 2020 will take place on November 3-5 and it will coincide with the PacSec conference, which typically takes place in Tokyo that time of year.

Defying Covid-19’s Pall: Pwn2Own Goes Virtual
2020-03-20 20:03

Over the course of two days, hacking teams ranging from Flourescence, RedRocket CTF and Synacktiv attempted to hack Adobe's Acrobat Reader and Apple's macOS and virtualization platforms such as Oracle VirtualBox. During one hacking attempt, the Fluoroacetate team of Amat Cama and Richard Zhu, targeted Adobe Reader and then Windows with a local privilege escalation attack.

Defying Covid-19’s Pall: Pwn2Own Goes Virtual
2020-03-20 20:03

Over the course of two days, hacking teams ranging from Flourescence, RedRocket CTF and Synacktiv attempted to hack Adobe's Acrobat Reader and Apple's macOS and virtualization platforms such as Oracle VirtualBox. During one hacking attempt, the Fluoroacetate team of Amat Cama and Richard Zhu, targeted Adobe Reader and then Windows with a local privilege escalation attack.