logo

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M

ID: 4d917a16-0dd0-554c-b70f-c3e3c1da6ada

STIX ID: report--4d917a16-0dd0-554c-b70f-c3e3c1da6ada

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-25

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Infosec roundup: the Pwn2Own Automotive contest exposed 76 zero-day vulnerabilities across automotive targets (including Tesla infotainment and EV chargers) with several successful exploit demonstrations; Google Gemini was vulnerable to a calendar-based prompt-injection that could leak meetings (now patched); French regulators fined a company €3.5M for unlawful customer data sharing; HackerOne published safe-harbor guidance for AI security research; and a ~149 million-credential dataset, apparently compiled by infostealer/keylogger malware, was found publicly exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.