Windows 11, Red Hat Linux, & Oracle VirtualBox Hacked – Pwn2Own Day 1
The first day of Pwn2Own Berlin 2025 wrapped up with a bang, as hackers showcased 11 exploit attempts, including AI-targeted attacks, and walked away with $260,000 in prizes. The Pwn2Own competition, known for pushing the boundaries of cybersecurity, saw successful breaches of Windows 11, Red Hat Linux, Oracle VirtualBox, and Docker Desktop, alongside the first-ever […] The post Windows 11, Red Hat Linux, & Oracle VirtualBox Hacked – Pwn2Own Day 1 appeared first on Cyber Security News.

The first day of Pwn2Own Berlin 2025 wrapped up with a bang, as hackers showcased 11 exploit attempts, including AI-targeted attacks, and walked away with $260,000 in prizes.
The Pwn2Own competition, known for pushing the boundaries of cybersecurity, saw successful breaches of Windows 11, Red Hat Linux, Oracle VirtualBox, and Docker Desktop, alongside the first-ever AI category win in Pwn2Own history.
STAR Labs surged to an early lead in the race for Master of Pwn, but with more challenges ahead, the title remains up for grabs.
Day 1 Highlights: Major Systems Compromised
End of Day 1 results, Several products has been exploited with zero-days as follows.
Red Hat Linux Falls Twice: Pumpkin (@u1f383) from DEVCORE Research Team exploited an integer overflow to escalate privileges, earning $20,000 and 2 Master of Pwn points.
Meanwhile, Hyunwoo Kim (@V4bel) and Wongi Lee (@_qwerty_po) of Theori used an information leak and a use-after-free (UAF) bug for a root escalation, but a known N-day bug led to a collision, netting them $15,000 and 1.5 Master of Pwn points.
Windows 11 Breached Multiple Times: Chen Le Qi (@cplearns2h4ck) of STAR Labs SG combined a UAF and integer overflow to escalate to SYSTEM, securing $30,000 and 3 Master of Pwn points.
Marcin Wiązowski delivered a flawless out-of-bounds write exploit for another SYSTEM escalation, also earning $30,000 and 3 points. Hyeonjin Choi (@d4m0n_8) of Out Of Bounds capped the Windows 11 attacks with a type confusion bug, winning $15,000 and 3 Master of Pwn points.
Oracle VirtualBox Escape: Team Prison Break (Best of the Best 13th) used an integer overflow to break out of Oracle VirtualBox and execute code on the host OS, pocketing $40,000 and 4 Master of Pwn points.
Docker Desktop Hacked: Billy and Ramdhan of STAR Labs executed a UAF in the Linux kernel to escape Docker Desktop and run code on the underlying OS, earning the day’s biggest prize of $60,000 and 6 Master of Pwn points.
Historic AI Exploit Steals the Show
In a Pwn2Own first, Sina Kheirkhah (@SinSinology) of Summoning Team successfully exploited Chroma in the new AI category, earning $20,000 and 2 Master of Pwn points. This landmark achievement highlights the growing focus on AI system security as artificial intelligence becomes integral to modern technology.
NVIDIA Triton Collisions Spark Discussion
The NVIDIA Triton Inference Server saw multiple exploit attempts, but all resulted in collisions due to known bugs.
Sina Kheirkhah (@SinSinology) of Summoning Team and Viettel Cyber Security (@vcslab) both demonstrated successful exploits, each earning $15,000 and 1.5 Master of Pwn points despite the vendor’s prior knowledge of the vulnerabilities. Wiz Research, however, failed to get their Triton exploit working within the allotted time.
With STAR Labs leading the Master of Pwn leaderboard, anticipation is high for Day 2 as more researchers target Microsoft, AI systems, and other platforms.
The collisions on NVIDIA Triton underscore the challenge of patching known vulnerabilities before they’re exploited, while the AI category’s debut signals a new frontier in cybersecurity.
How to Discover Vulnerable External Assets Associated with a Domain or an IP? -> Try Cyber Asset Finder for Free
The post Windows 11, Red Hat Linux, & Oracle VirtualBox Hacked – Pwn2Own Day 1 appeared first on Cyber Security News.