BBC News | Champion ethical hacker warns AI tools like Mythos will make competing harder

AI generated summary, Read the full article for complete information.

Champion ethical hacker Valentina Palmiotti, known as “Chompie,” won the 2024 Pwn2Own Berlin competition by exploiting systems for prize money, but she warns that powerful new AI tools such as Anthropic’s Claude Mythos could soon make human‑only hacking contests impractical. While AI assistants like Claude Code currently help her and other researchers work faster, the emergence of more advanced models promises to automate many “lower‑hanging‑fruit” bugs, leaving only the very best hackers able to discover novel vulnerabilities. Fellow champion Orange Tsai sees AI as a useful research aid that can free up time but believes human creativity will still be essential. Both experts agree that if AI‑driven tools are responsibly released to defenders, they could tilt the balance against offensive hackers, though criminals are already experimenting with AI to accelerate attacks. The overall sentiment is that AI will raise the bar for security research, benefitting defenders while making traditional bug‑bounty hunting increasingly challenging.

Read more: https://www.bbc.com/news/articles/c3r2zjpryzro?at_medium=RSS&at_campaign=rss

#ValentinaPalmiotti #ClaudeMythos #Pwn2Own #OrangeTsai #AI

Top ethical hacker Chompie warns AI tools could put her out of business

Chompie, one of the world's tops ethical hackers, says AI like Claude Mythos will make it harder for people like her to compete.

BBC News | Champion ethical hacker warns AI tools like Mythos will make competing harder

AI generated summary, Read the full article for complete information.

Valentina Palmiotti, known as “Chompie,” was the top individual at this year’s Pwn2Own hacking competition in Berlin, winning cash prizes by exploiting a Nvidia‑linked system and a Linux‑based target; she credits AI tools such as Claude Code for accelerating her work but warns that newer models like Anthropic’s Claude Mythos—and upcoming versions such as GPT 5.5 Cyber—could soon outpace even champion human hackers, making “lower‑hanging fruit” scarce and relegating ethical hackers to a niche where only the very best can still discover novel bugs. Fellow competitor Orange Tsai shares a more optimistic view, seeing AI as a powerful assistant that can augment research while still relying on human creativity, but both agree that the rise of advanced AI will raise the bar for security research, potentially benefitting defenders if the tools are released responsibly, even as criminal actors also begin to exploit AI for attacks.

Read more: https://www.bbc.com/news/articles/c3r2zjpryzro?at_medium=RSS&at_campaign=rss

#ValentinaPalmiotti #OrangeTsai #ClaudeMythos #GPT55 #Pwn2Own

Top ethical hacker Chompie warns AI tools could put her out of business

Chompie, one of the world's tops ethical hackers, says AI like Claude Mythos will make it harder for people like her to compete.

🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.

These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.

→ Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.

Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked

If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.

Plus: fast16 predated Stuxnet and corrupted nuclear simulations quietly, Pwn2Own Berlin paid $1.3M for 47 bugs, and Bluesky got hijacked for Russian propaganda

X’s InfoSec Newsletter
#Pwn2Own #Berlin 2026: #Hacker verdienen 1,3 Millionen Dollar mit #Schwachstellen in #AI, #Windows und #VMware. #Devcore und #StarLabsSG holten zusammen fast 750.000 Dollar.

📢 Pwn2Own Berlin 2026 : 47 zero-days exploités, 1,298,250 $ de récompenses
📝 ## 🏆 Contexte

Source : BleepingComputer, publié le 18 mai 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-05-19-pwn2own-berlin-2026-47-zero-days-exploites-1298250-de-recompenses/
🌐 source : https://www.bleepingcomputer.com/news/security/hackers-earn-1-298-250-for-47-zero-days-at-pwn2own-berlin-2026/
#Pwn2Own #TTP #Cyberveille

Pwn2Own Berlin 2026 : 47 zero-days exploités, 1,298,250 $ de récompenses

🏆 Contexte Source : BleepingComputer, publié le 18 mai 2026. La compétition Pwn2Own Berlin 2026 s’est tenue du 14 au 16 mai 2026 dans le cadre de la conférence OffensiveCon, organisée par la Zero Day Initiative (ZDI) de TrendMicro. Elle ciblait les technologies d’entreprise et l’intelligence artificielle. 💰 Résultats globaux 47 zero-days exploités au total 1,298,250 $ de récompenses distribuées Jour 1 : 523,000 $ pour 24 zero-days Jour 2 : 385,750 $ pour 15 zero-days Jour 3 : 389,500 $ pour 8 zero-days 🥇 Classement DEVCORE — 50,5 points, 505,000 $ (1er) STARLabs SG — 25 points, 242,500 $ Out Of Bounds — 12,75 points, 95,750 $ 🔓 Exploits notables Orange Tsai (DEVCORE) : 200,000 $ pour une chaîne de 3 bugs permettant une RCE avec privilèges SYSTEM sur Microsoft Exchange ; 175,000 $ supplémentaires pour un sandbox escape sur Microsoft Edge via 4 bugs logiques Valentina Palmiotti (IBM X-Force) : 70,000 $ pour un root sur Red Hat Linux for Workstations et un zero-day NVIDIA Container Toolkit Windows 11 : hacké à plusieurs reprises (LPE) Red Hat Enterprise Linux for Workstations : compromis plusieurs fois VMware ESXi : exploité via un bug de corruption mémoire Agents de codage IA : zero-days démontrés le jour 2 Microsoft SharePoint et Microsoft Exchange : ciblés par DEVCORE 📋 Catégories ciblées Navigateurs web, applications d’entreprise, élévation de privilèges locale, serveurs, inférence locale, environnements cloud-native/conteneurs, virtualisation, LLM ⏳ Divulgation responsable Conformément aux règles ZDI, les vendeurs disposent de 90 jours pour publier des correctifs avant la divulgation publique des vulnérabilités.

CyberVeille

Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at #Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

Read: https://hackread.com/pwn2own-berlin-2026-closes-zero-day-payouts/

#CyberSecurity #BugBounty #Vulnerability #AI #0day

Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts

Cybersecurity researchers demonstrated 47 unique zero-day exploits at Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.

Hackread - Cybersecurity News, Data Breaches, AI and More
#MSXFAQ PWN2OWN 2026 - 0-Day #Exchange https://www.msxfaq.de/exchange/update/pwn2own2026.htm - Ein 0-Day für Exchange von der #PWN2OWN könnte für hektische Updates in den nächsten Wochen führen. Anonym, aus dem Internet per URL auf Exchange und Server Code starten und übernehmen.
PWN2OWN 2026 - 0-Day Exchange

Frank's Microsoft Exchange FAQ

MSXFAQ
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026

The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws.

BleepingComputer

🔥 Pwn2Own Berlin 2026 ends with:
💰 $1.29M awarded
⚠️ 47 zero-days exploited
🎯 Microsoft Exchange, Windows 11, VMware ESXi, AI coding agents, Red Hat Linux all successfully hacked.
Enterprise + AI attack surfaces keep expanding.

Source: https://www.bleepingcomputer.com/news/security/hackers-earn-1-298-250-for-47-zero-days-at-pwn2own-berlin-2026/

Follow @technadu for more.

#InfoSec #Pwn2Own #ZeroDay

Rekordverdächtiges Preisgeld und Exchange-Zeroday auf der Pwn2Own 2026

Exploit-Fachleute aus aller Welt traten beim Wettbewerb der Sicherheitslücken an und nahmen fast 1,3 Millionen US-Dollar Preisgeld mit nach Hause.

heise online