The third day of the Pwn2Own Ireland 2024 hacking competition concluded with the discovery of 11 zero-day vulnerabilities . The researchers/ethical hackers won $124,750, bringing the total prize pool (for all three days) to $874,875.

The global hacking competition, Pwn2Own, challenges top security researchers to exploit vulnerabilities in various devices and software, with the ultimate goal of earning the prestigious title of “Master of Pwn” and claiming up to $1 million in rewards. At the same time, the discovery of vulnerabilities helps companies fix their products.
On the first day of Pwn2Own Ireland, participants revealed 52 zero-day vulnerabilities and on the second day another 51.
See also: Pwn2Own Ireland 2024: 52 vulnerabilities found in one day
The third day continued with impressive performances from teams representing Viettel Cyber Security, DEVCORE, PHP Hooligans/Midnight Blue and other companies.
Ha The Long and Ha Anh Hoang from Viettel Cyber Security compromised a QNAP TS-464 NAS using a command injection vulnerability. This successful attack helped them earn $10,000 and 4 Master of Pwn points.
Pumpkin Chang and Orange Tsai from DEVCORE Research Team combined three exploits to take control of Synology BeeStation, earning $20,000 and 4 points.
PHP Hooligans / Midnight Blue used vulnerabilities to perform a “SOHO Smashup.” They managed to switch from a QNAP QHora-322 router to a Lexmark printer, ultimately printing their own “banknotes.” Their reward was $25,000 and 10 Master of Pwn points.
See also: Pwn2Own Ireland Day 2: Researchers hacked the Samsung Galaxy S24
Viettel Cyber Security scored another success, exploiting the Lexmark CX331adwe. It added $20,000 and 2 more points to its team.
However, not all attempts were completely successful. Many groups used the same vulnerabilities to compromise devices. STEALIEN Inc. successfully compromised a Lorex camera, but the flaw they used had already been exploited, reducing their payout to $3,750 and 1.5 points.

Viettel Cyber Security exploited a Canon printer using a vulnerability previously shown by other researchers. As a result, it only earned $5,000 and 1 point.
Furthermore, Viettel Cyber Security and ANHTUD were unable to complete their efforts in a timely manner during the Ubiquiti AI Bullet breach
As the competition enters its final phase, Viettel Cyber Security is ahead.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In total, as of the third day of Pwn2Own Ireland, 114 zero-day vulnerabilities have been disclosed.
See also: Critical vulnerabilities in Siemens and Schneider Electric products
Pwn2Own Ireland 2024
The reaction from the hacker community and the public is always enthusiastic about these competitions. Everyone recognizes the importance of the competition in promoting the security of products and systems.
At the same time, such competitions give hackers themselves the opportunity to learn and be inspired by the techniques and strategies used by their other colleagues.
The Pwn2Own Ireland 2024 event strengthens the ethical hacking, offering a platform for dialogue, idea exchange and collaboration.
Source: www.bleepingcomputer.com
