Record-Breaking Pwn2Own Berlin 2025: $695K Awarded in 2 Days for Zero-Day Exploits in Top Tech Products

Listen to this Post

Featured Image
Cybersecurity Elites Shake Up the Industry with Shocking Exploits at Pwn2Own 2025

Pwn2Own Berlin 2025 has erupted with record-setting momentum, spotlighting the talents of elite cybersecurity researchers who exposed serious zero-day vulnerabilities across widely used enterprise platforms. Taking place during the OffensiveCon cybersecurity conference from May 15 to 17, this year’s contest introduced a groundbreaking AI category and set its sights on critical systems used globally — from cloud servers to virtual machines, browsers, and even Tesla vehicles.

Within just two days, participants had already raked in a jaw-dropping \$695,000 in rewards. These aren’t ordinary bugs — they’re zero-day vulnerabilities in fully patched, high-profile products from tech giants like Microsoft, Oracle, VMware, Mozilla, and Red Hat. With up to \$1 million in total prizes on the line, the world’s best white-hat hackers demonstrated that even today’s most secure platforms can be breached by those with the right skills and knowledge.

Day Two Highlights and Zero-Day Victories

On day two alone, hackers walked away with \$435,000 in prizes by breaking into major platforms:

Nguusd Hoang Thach from STARLabs SG led the day, winning \$150,000 for an integer overflow attack on VMware ESXi, proving how a single flaw in a hypervisor can put entire virtual infrastructures at risk.

Dinh Ho Anh Khoa of Viettel Cyber Security showcased a dangerous exploit chain combining authentication bypass with insecure deserialization, breaching Microsoft SharePoint and earning \$100,000.

Edouard Bochin and Tao Yan from Palo Alto Networks discovered a zero-day out-of-bounds write in Mozilla Firefox.

Gerrard Tai (STARLabs SG) escalated Red Hat Enterprise Linux privileges to root using a use-after-free bug, highlighting privilege escalation threats in open-source systems.

Another major hit came from Viettel Cyber Security, who triggered an out-of-bounds write in Oracle VirtualBox, achieving a guest-to-host escape.

In the newly introduced AI category, researchers from Wiz Research exploited Redis with a use-after-free bug, while Qrious Secure chained four flaws to successfully compromise Nvidia’s Triton Inference Server.

This builds on day one, where \$260,000 was awarded for exploits affecting Windows 11, Red Hat Linux, and Oracle VirtualBox, bringing the total haul for participants to \$695,000 after 20 unique zero-days.

Despite Tesla hardware being made available (Model Y 2025 and Model 3 2024), no hacking attempts were registered for them at the start of the event. However, targets like Windows 11, VMware Workstation, Mozilla Firefox, and Nvidia’s AI tools remain in the hackers’ crosshairs for the final day.

According to the Zero Day Initiative (ZDI), vendors now have 90 days to patch the exposed vulnerabilities before full technical details are made public.

What Undercode Say:

The second day of Pwn2Own Berlin 2025 offers not just entertainment for cybersecurity professionals, but a harsh reminder of the fragility of modern enterprise ecosystems. What’s astonishing is not just the value of the prizes, but the ease and precision with which top researchers are compromising platforms that power businesses globally.

VMware ESXi, a cornerstone in data centers, fell to a straightforward integer overflow. That means a single miscalculated input could give an attacker control over virtual machines that might host sensitive databases or internal tools. In another case, Microsoft SharePoint — a vital collaboration tool for corporations — was breached via a chained exploit, merging two vulnerabilities into a powerful attack vector. This speaks to how attackers are moving away from isolated bugs and leveraging chained exploits to bypass multiple layers of defense.

The zero-day found in Mozilla Firefox raises alarms about browser security, especially as more users rely on web apps in enterprise environments. Meanwhile, the privilege escalation in Red Hat Linux touches a critical area — Linux is the backbone of most server infrastructure today, and a root-level exploit puts entire networks at risk.

Perhaps the most significant shift is the inclusion of AI infrastructure in the hacking lineup. Redis and Nvidia’s Triton Inference Server are used in modern AI workloads, from chatbots to predictive systems. Demonstrating zero-days here underlines that AI is no longer a theoretical attack surface — it’s live, critical, and vulnerable.

The absence of any successful Tesla hacks doesn’t mean these systems are impenetrable — it might reflect either the complexity of their firmware or the short time frame for testing. As the final day approaches, the spotlight will be on whether these automotive systems remain resilient.

One critical takeaway is that all these platforms were fully patched — showing that even up-to-date systems are not necessarily safe. The 90-day window vendors get to patch these vulnerabilities is generous, but until fixes are out, users remain exposed to unknown threats. Organizations must now not only rely on patches but also enhance their detection, isolation, and response strategies.

These contests serve dual purposes: showcasing research talent and acting as a wake-up call for vendors and users alike. With \$1 million in total bounties, the message is clear — security is not a one-time task but a continual process of evaluation, testing, and evolving.

Fact Checker Results ✅

All exploits were successfully demonstrated live during Pwn2Own Berlin 2025
Vulnerabilities affected fully patched versions of all listed software
Event is officially verified and coordinated with Trend Micro’s Zero Day Initiative 🎯🛡️💻

Prediction 🔮

Expect increased focus on AI infrastructure security in future hacking contests as systems like Redis and Nvidia Triton become essential to enterprise workflows. With zero-day vulnerabilities proven in high-impact environments, the cybersecurity industry will likely prioritize real-time behavioral analysis and sandbox isolation for virtualized and AI systems. Furthermore, automotive targets like Tesla may face deeper scrutiny, especially as their software stacks grow more complex and connected.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram