ZDI Announces Pwn2Own Ireland 2026 Competition Details and Targets
The Zero Day Initiative (ZDI) has announced the upcoming Pwn2Own Ireland 2026 cybersecurity competition, scheduled for October 6-9, 2026. The event will focus on discovering new vulnerabilities in mobile phones, smart home devices, wellness technology, printers, messaging apps, and AI infrastructure and coding agents.

English Brief
The Zero Day Initiative (ZDI) has announced the upcoming Pwn2Own Ireland 2026 cybersecurity competition, scheduled for October 6-9, 2026. The event will focus on discovering new vulnerabilities in mobile phones, smart home devices, wellness technology, printers, messaging apps, and AI infrastructure and coding agents.
الموجز العربي
مبادرة Zero Day تعلن عن تفاصيل ومستهدفات مسابقة Pwn2Own أيرلندا 2026
أعلنت مبادرة Zero Day عن إقامة مسابقة الأمن السيبراني Pwn2Own أيرلندا لعام 2026، والمقرر عقدها في الفترة من 6 إلى 9 أكتوبر 2026. ستركز الفعالية على اكتشاف ثغرات أمنية جديدة في الهواتف المحمولة، وأجهزة المنازل الذكية، وتقنيات الصحة، والطابعات، وتطبيقات المراسلة، بالإضافة إلى البنية التحتية للذكاء الاصطناعي ووكلاء البرمجة المعتمدين عليه.
- 1Audit current AI coding agent configurations to ensure secure sandbox environments.
- 2Maintain strict patch management for all mobile handsets and messaging platforms.
- 3Restrict network exposure for 'pro-sumer' IoT and wellness devices.
English Advisory
// Intelligence Summary
The Zero Day Initiative (ZDI) has unveiled the categories and operational requirements for Pwn2Own Ireland 2026, taking place from October 6-9, 2026, in Cork. The competition aims to identify zero-day vulnerabilities across diverse technology stacks, including mobile hardware, IoT, healthcare devices, and emerging AI-centric systems.
التقرير العربي
// ملخص استخباراتي
كشفت مبادرة Zero Day (ZDI) عن الفئات والمتطلبات التشغيلية لمسابقة Pwn2Own أيرلندا 2026، والتي ستُعقد في الفترة من 6 إلى 9 أكتوبر 2026 في مدينة كورك. تهدف المسابقة إلى تحديد ثغرات اليوم الصفر في حزم تقنية متنوعة، بما في ذلك أجهزة الهواتف المحمولة، وإنترنت الأشياء، وأجهزة الرعاية الصحية، والأنظمة القائمة على الذكاء الاصطناعي.
// Technical Context
Contestants are required to demonstrate vulnerabilities against seven categories: Mobile Phones (browser or short-distance protocols), Smart Home Devices (network/RF services), Wellness devices (network/RF services), Printers, Messaging applications, AI Infrastructure, and AI Coding Agents. Entries involving AI Coding Agents must interact with contestant-controlled resources via common use cases. Physical interaction (buttons/codes) or pre-paired conditions for wellness/IoT devices are strictly out of scope.
// السياق الفني
يُطلب من المشاركين إثبات الثغرات عبر سبع فئات: الهواتف المحمولة (عبر المتصفح أو بروتوكولات الاتصال قصير المدى)، أجهزة المنازل الذكية (خدمات الشبكة/التردد اللاسلكي)، أجهزة الصحة (خدمات الشبكة/التردد اللاسلكي)، الطابعات، تطبيقات المراسلة، البنية التحتية للذكاء الاصطناعي، ووكلاء البرمجة المعتمدين على الذكاء الاصطناعي. تُستبعد الثغرات التي تتطلب تفاعلاً فيزيائياً (أزرار/رموز) أو شروط اقتران مسبقة.
// Exposure Notes
This competition represents a controlled environment for vulnerability research. The participation criteria require contestants to have an aggregate bounty history of $15,000 with ZDI, or to be accepted as one of 10 new contestants. Entries are capped at 80, emphasizing professional-grade research into vendor-supplied, fully updated systems.
// ملاحظات التعرض
تمثل هذه المسابقة بيئة محكومة للبحث في الثغرات الأمنية. تتطلب معايير المشاركة وجود سجل مكافآت تراكمي قدره 15,000 دولار مع ZDI أو قبولهم كمشاركين جدد. يقتصر عدد المشاركات على 80 مشاركة، مما يؤكد على مستوى البحث الاحترافي في الأنظمة المحدثة كلياً.
// Defensive Priority
Organizations utilizing the specified target technologies should monitor ZDI disclosures following the event. As Pwn2Own historically results in the disclosure of previously unknown vulnerabilities, security teams should prepare for subsequent vendor patches and prioritize updates for mobile, AI, and messaging infrastructure identified during the contest.
// أولوية الدفاع
يجب على المؤسسات التي تستخدم التقنيات المستهدفة مراقبة إفصاحات ZDI بعد انتهاء الحدث. نظراً لأن المسابقة تؤدي تاريخياً إلى الكشف عن ثغرات غير معروفة سابقاً، يجب على فرق الأمن الاستعداد لتحديثات الموردين اللاحقة وتحديد أولويات تحديث البنية التحتية للهواتف والذكاء الاصطناعي وتطبيقات المراسلة التي يتم تحديدها خلال المسابقة.
Mitigation Checklist
- 1Audit current AI coding agent configurations to ensure secure sandbox environments.
- 2Maintain strict patch management for all mobile handsets and messaging platforms.
- 3Restrict network exposure for 'pro-sumer' IoT and wellness devices.
- 4Monitor vendor security advisories in October 2026 for zero-day disclosures originating from Pwn2Own.
قائمة إجراءات التخفيف
- 1مراجعة إعدادات وكلاء البرمجة المعتمدين على الذكاء الاصطناعي لضمان بيئات معزولة (Sandbox) آمنة.
- 2الحفاظ على إدارة صارمة للتصحيحات البرمجية لجميع أجهزة الهواتف المحمولة ومنصات المراسلة.
- 3تقييد الوصول عبر الشبكة لأجهزة إنترنت الأشياء وأجهزة الصحة.
- 4مراقبة إشعارات الأمن الخاصة بالموردين في أكتوبر 2026 لاكتشاف ثغرات اليوم الصفر الناتجة عن المسابقة.
- Source: Zero Day Initiative
# Cybersecurity Preparation Checklist:
# 1. Audit current AI coding agent configurations to ensure secure sandbox environments.
# 2. Maintain strict patch management for all mobile handsets and messaging platforms.
# 3. Restrict network exposure for 'pro-sumer' IoT and wellness devices.
# 4. Monitor vendor security advisories in October 2026 for zero-day disclosures originating from Pwn2Own.