😢TyphoonPWN 2026 Unpwned😢
Found a bug in the "ipTime Router WAN PreAuth Remote Code Execution" category ($10,000) using an LLM and reported it in February for TyphoonPWN 2026. Unfortunately, it was patched in March before the event.
#TyphoonCon26
https://t.co/ILTHGKQnfT
Excited to share that Jinddabi’s has advanced to the DEF CON 34 CTF Finals!
Huge thanks to all my teammates for their hard work and dedication.
We’ll keep pushing and do our best on the finals stage.
#DEFCON34#CTF#CyberSecurity#Jinddabis
@neko__hat
New CVE Assigned: CVE-2025-59383 🛡️
I found a Stack-Based Buffer Overflow (BOF) vulnerability affecting QNAP NAS devices. Stay secure and make sure to check the official advisory:
https://t.co/UjwTSWn4kS
#QNAP#Cybersecurity#ExploitDev#SecurityAdvisory#NAS
After a long rest, I’m happy to share Team DDOS (or known as KIMCHI and YOGURT 😅) got 2nd place !!
My first appreciation goes to my best teammate, @freddo_1337. And congrats to all the teams - there's no doubt how much effort we all put into this!
Lastly, thanks to all friends I met and chatted with there, including ZDI and researchers! Wishing you all the best after the competition 💙
Collision! @gul9ul, @d0kk2bi, @dig06161, @neko__hat, @hanR0724, @meixploit, Jinyeong Yoon, and @ZIEN0621 of ZIEN, Inc. targeted the ChargePoint Home Flex (CPH50-K), demonstrating two unique bugs (symlink following and command injection) but encountered a collision with a previous attempt - still earning $16,750 USD and 3.5 Master of Pwn points. #Pwn2Own #P2OAuto
Our first collision of Day Three: the group from STEALIEN Inc. successfully popped the Lorex camera, but the bug they used had already been demonstrated in the contest. They still earn $3,750 and 1.5 Master of Pwn points. #Pwn2Own#P2OIreland
Confirmed! The STEALIEN Inc. team used a combination of bugs in their attack chain to exploit the #Ubiquity AI Bullet and flash the lights (plus get a root shell). Their work earns them $30,000 and 3 Master of Pwn points. #Pwn2Own#P2OIreland