[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz6awvWd6_LtsOyUEAtzfWH548AWTKoVMZ2EZXXj6X8k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"208150fa-767f-476d-8a0b-d479201d5469","32-zero-days-exploited-on-day-one-of-pwn2own-ireland","32641aa2-5894-4ffb-8854-b4d7f9e25453","32 Zero-Days Exploited on Day One of Pwn2Own Ireland","Security researchers demonstrated 32 previously unknown zero-day vulnerabilities across consumer and enterprise devices — including smartphones, printers, and smart home hubs — on the very first day of Pwn2Own Ireland. This highlights that even widely deployed, mainstream devices from major vendors harbor critical unpatched flaws that attackers could exploit in the wild. The 90-day responsible disclosure window underscores the urgency for vendors to maintain robust vulnerability response programs. When zero-days are discovered at this scale in a controlled setting, it is a strong signal that real-world threat actors may already be probing the same attack surfaces. Organizations relying on these devices must treat vulnerability management as a continuous, proactive discipline rather than a reactive one.","**Immediate actions:**\n- Enroll affected devices (Samsung Galaxy, smart home hubs, printers) in vendor security notification programs to receive patches the moment they are released.\n- Conduct an asset inventory audit to identify all potentially affected device models currently deployed in your environment.\n\n**Long-term improvements:**\n- Establish a formal vulnerability management lifecycle that tracks vendor advisories, CVE feeds, and bug-bounty disclosures for every device category in use.\n- Implement network segmentation to isolate IoT and consumer-grade devices from critical business systems, limiting lateral movement if a device is compromised.\n- Require vendors to demonstrate a documented vulnerability response program (including defined SLAs for zero-day patches) as part of procurement criteria.\n\n**Detection measures:**\n- Deploy behavioral monitoring and anomaly detection on networks where smart devices and printers operate to catch exploitation attempts early.\n- Integrate threat intelligence feeds covering newly disclosed zero-days into your SIEM so defenders are alerted as soon as Pwn2Own or similar disclosures go public.",[12,13,14,15,16,17,18,19,20],"CIS Control 7 – Continuous Vulnerability Management","CIS Control 12 – Network Infrastructure Management","CIS Control 1 – Inventory and Control of Enterprise Assets","NIST SP 800-40 Rev. 4 – Guide to Enterprise Patch Management","NIST SP 800-82 – Guide to ICS\u002FIoT Security","NIST CSF ID.RA-1 – Asset vulnerabilities are identified and documented","NIST CSF RS.MI-3 – Newly identified vulnerabilities are mitigated or documented as accepted risks","ISO\u002FIEC 27001:2022 – Annex A 8.8 Management of Technical Vulnerabilities","ITIL 4 – Problem Management (proactive problem identification)","published","2026-10-06T20:20:24.881295+00:00","2026-10-06T20:20:24.545+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland\u002F","hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland-6921c5","Hackers exploit 32 zero-days on first day of Pwn2Own Ireland",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]