Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.
Excerpt from the primary source: BleepingComputer
Who is affected
Security professionals
Why it matters
Source reporting says attackers are already exploiting this, so exposed affected systems are at immediate risk.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
Source reporting says attackers are already exploiting this, so exposed WordPress systems are at immediate risk.
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens.
More RMM Tools In the Wild, (Tue, Oct 6th)
It seems that a trend started⦠I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[ 1 ] about ScreenConnect used in the wild. Today, I found another one.
