Announcing #Pwn2Own Berlin 2026! We've got 10 categories for targets, including an expanded #AI target list. We have 4 AI categories - including coding agents (looking at you #Claude). More than $1,000,000 in cash & prizes available. Read the details at https://t.co/0iMkO6FrOh
@UK_Daniel_Card These were all unique CVEs, but many had been reported by several different researchers, indicating AI assisted vuln discovery was involved.
It seems #Apple can't avoid the ongoing Bug Apocalypse, as their CVE count jumps from 37 to 210 between June and July. Nothing appears to be under active attack. We parse it all out for you at https://t.co/K1uSeyUfdT
CVE-2026-50522 was demonstrated at #Pwn2Own Berlin by @splitline of DEVCORE Research Team. He earned $100,000 for it. @trendaisecurity customers received protection back on May 19,2026.
🛡️We added Check Point SmartConsole vulnerability CVE-2026-16232 & Microsoft SharePoint vulnerability CVE-2026-50522 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec
Exciting news! I'm hiring experienced vulnerability researchers @theZDI.
Do you love VR, sharing your work, and want to run categories at Pwn2Own? Come work with us (remotely).
Apply here: https://t.co/n7asBQcNOC
Feel free to DM me if you have any questions.
@v_metnew If you are one of the first 80 judged to be a qualified entry, you are guaranteed participation. You can reach out to pwn2own [@] trendmicro [dot] com for details.
#Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at https://t.co/XAIi6UXTRB #P2OIreland
[NOPcon Keynote Speaker Announcement 📢]:
Brian Gorenc (@MaliciousInput) joins NOPcon 2026 with “Learnings From Two Decades of Zero-Days: From Manual Exploits to Autonomous Discovery"
It took quite a bit to parse, but the Patch Report for June is alive. @dustin_childs ignored the France vs. Spain match just to figure out this record release and break it down for you. Check out what you may have missed at https://t.co/uNvvwytj4p
It's landed. The bug apocalypse is upon us as #Microsoft releases patches for 620+ CVEs to go along with #Adobe's 88. @dustin_childs has done his best to make sense of it all. Read his analysis at https://t.co/3RrHKdmTDn
Our research team is back looking at CVE-2026-47291 - a CVSS 9.8 RCE bug in #Windows HTTP.sys. They show root cause and look at why detection may be just as hard as exploitation. https://t.co/H9PUy1KsTO
#Apple has joined #Adobe in patching more often. They released 37 CVEs yesterday. @dustin_childs wears his patch wrangler hat as he breaks down the release. https://t.co/b5KiwiVBCy
#Adobe is moving to a twice-monthly patch release as a result of frontier AI models finding bugs. Today, they released two Priority 1 patches for Cold Fusion and Campaign Classic (CVSS 10!). Neither under active attack. Read the announcement at https://t.co/pmsgJy6U2F
@zer0matt_ Apologies on the delay - we really are just swamped. We've just hired two new analysts, so hopefully you get some feedback soon. We haven't forgotten you.
I had an amazing time talking with @chompie1337 during #Pwn2Own Berlin. Her insights into AI assisted vulnerability development are not to be missed. Check out our podcast here or wherever you get yours https://t.co/SgefunqJpz
We've updated the look and feel of our website. The blog is under maintenance for now but will be up soon. Let us know if you find any bugs or issues. https://t.co/xrMXCL2hjj
It's the bug of the month for June 2026! CVE-2026-45657 - A CVSS 9.8 vulnerability in Kernel that allows remote, unauthenticated code execution at SYSTEM without user interaction. Yikes!