Hackers Earn $1.3 Million at Pwn2Own Berlin 2026
2026-05-18T07:24:03Z•b01323907567fd07c2a17986ebfda2a1c1598d5f61557be8eb637ad747e45c04
Chrome updateCisco SD-WANMicrosoft ExchangeNGINXOpenAIPoCShai-HuludTeamPCPUAT-8616credential-theftdata-breachexploitsproof-of-conceptpwn2ownransomwaresupply-chainzero-day
What happened
Feed of SecurityWeek headlines (mid-May 2026) reporting multiple high-risk events: winners at Pwn2Own Berlin 2026 (exploits across Windows, Linux, VMware, Nvidia, AI products); proof-of-concept code published for a critical NGINX vulnerability (introduced 2008) that was just patched; Microsoft warning and mitigations for an Exchange Server zero-day (CVE-2026-42897) exploited in the wild; Cisco patch for an actively exploited SD‑WAN zero-day (CVE-2026-20182) attributed to UAT-8616; OpenAI impacted by a TanStack supply-chain incident with stolen credentials; TeamPCP released Shai‑Hulud worm源码 to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- b01323907567fd07c2a17986ebfda2a1c1598d5f61557be8eb637ad747e45c04
- Enrichment time
- 2026-05-18T07:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.