Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total
2026-05-17T08:51:46Z•5cd254c565fdd10e0619fe98b95576be97f8159f54b114eabe91fdf790f78e43
aptbitlockerbotnetcisacisco-sd-wanctfmoncve-2026-20182cve-2026-42897frostyneighborghostwritergreenplasmakazuarknown-exploited-vulnerabilitiesmicrosoft-exchangeopenaipwn2ownsupply-chaintanstackturlavulnerabilityyellowkeyzero-day
What happened
Feed summarizing multiple high-impact security events: Pwn2Own Berlin 2026 concluded with 47 zero-days and $1.298M in payouts (DEVCORE dominated). Microsoft confirmed active exploitation of an Exchange Server XSS zero-day (CVE-2026-42897, CVSS 8.1) which CISA added to its Known Exploited Vulnerabilities (KEV) catalog. CISA also added a critical Cisco Catalyst SD‑WAN flaw (CVE-2026-20182, CVSS 10.0) to KEV. Russia-linked APT Turla evolved Kazuar into a stealthy P2P botnet for long-term access. OpenAI was hit by a TanStack supply‑chain attack that compromised two employee devices and exposed SCM
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5cd254c565fdd10e0619fe98b95576be97f8159f54b114eabe91fdf790f78e43
- Enrichment time
- 2026-05-17T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.