Search/lexmark
Vendor

lexmark

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
xm7155x firmware
Connections
298 relationships
Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta
A total of $1,024,750 has been paid out at the Pwn2Own Ireland 2025 hacking contest organized by Trend Micro’s Zero Day Initiative (ZDI), but the event has been overshadowed by the last-minute withdrawal of a researcher who was scheduled to demonstrate a WhatsApp exploit worth $1 million. The highest reward at Pwn2Own Ireland 2025, $100,000, was paid out for an exploit chain targeting the QNAP Qhora-322 router and the QNAP TS-453E NAS device. Two Samsung Galaxy S25 exploit chains were each rewarded with $50,000, and the same amount was earned for vulnerabilities in Synology ActiveProtect Appliance DP320 and the Sonos Era 300 smart speaker. Participants received up to $40,000 for hacking Ubiquiti cameras, QNAP and Synology NAS devices, Lexmark and Canon printers, and smart home systems such as Phillips Hue Bridge, Amazon Smart Plug, and Home Automation Green. A total of 73 previously unknown vulnerabilities were disclosed at Pwn2Own Ireland 2025. A researcher named Eugene (3ugen3) of Team Z3 was scheduled to demonstrate a $1 million zero-click remote code execution exploit against WhatsApp on Thursday. However, the demonstration did not take place. ZDI initially said there was a delay due to “travel complications and delayed flights”, but noted that the researcher would still submit his exploit. ZDI later announced that the researcher withdrew from the competition, citing concerns that the exploit was not sufficiently prepared for a public demonstration. “Team Z3 has withdrawn their WhatsApp entry from Pwn2Own as they did not feel their research was ready to publicly demonstrate,” said Dustin Childs, head of threat awareness at ZDI. “However, Meta remains interested in receiving this research. Team Z3 is disclosing their findings to ZDI analysts to do an initial assessment before handing it over to Meta engineers,” Childs added. “While we are disappointed that we don’t get to publicly show the demo on the Pwn2Own stage, we’re happy to facilitate the coordinated disclosure to Meta so they have the opportunity to address issues should they prove valid.” No updates have been shared on ZDI’s assessment, whether any zero-day exploit information has been shared with Meta, and whether the social media giant paid any bounty for the WhatsApp hack. The delay, the withdrawal, and the lack of public disclosure has led to wide-ranging disappointment and speculation within the security industry regarding the technical viability of the purported exploit. Contacted by SecurityWeek, Eugene, who appears to be from China, described Pwn2Own as an “amazing event”. The researcher said, “We decided to keep everything private between Meta, ZDI and myself. No comments,” adding that he did not want his true identity revealed to the public. Eugene told SecurityWeek that he signed an NDA that prevents him from sharing any details. SecurityWeek has also reached out for comment to ZDI and WhatsApp and will update this article if they respond. UPDATE: A WhatsApp spokesperson has provided the following statement to SecurityWeek. A follow-up article with additional information is available here. “We’re disappointed that Team Z3 withdrew from Pwn2Own yesterday because they didn’t have a viable exploit, but we were in contact with ZDI and Team Z3 to understand their research so we can triage the low-risk bugs we received. As always, we stand ready to receive valid research from the community through our bug bounty program and are grateful to security researchers and Pwn2Own for ongoing collaboration.” Related: $4.5 Million Offered in New Cloud Hacking Competition Related: Over $3 Million in Prizes Offered at Pwn2Own Automotive 2026 Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched
securityweek.comOct 24, 2025extracted
Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000
Security researchers collected $267,500 in cash after exploiting 22 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition. Today's highlight was Ken Gannon of Mobile Hacking Lab and Dimitrios Valsamaras of Summoning Team hacking the Samsung Galaxy S25 with a chain of five security flaws, earning $50,000 and 5 Master of Pwn points. Also, while PHP Hooligans needed only a single second to hack the QNAP TS-453E NAS device, the vulnerability they exploited had already been used in the contest. Chumy Tsai of CyCraft Technology, Le Trong Phuc and Cao Ngoc Quy of Verichains Cyber Force, and Mehdi & Matthieu of Synacktiv Team were also awarded $20,000 for breaking into the QNAP TS-453E, Synology DS925+, and the Phillips Hue Bridge. The contestants also exploited zero-day bugs in the Canon imageCLASS MF654Cdw printer, Home Automation Green, Synology CC400W camera, Synology DS925+ NAS, Amazon Smart plug, and Lexmark CX532adwe printer. Summoning Team is still at the top of the Master of Pwn leaderboard with 18 points after earning $167,500 during the first two days of the event. On the first day of Pwn2Own Ireland, researchers demoed 34 unique zero-days and collected $522,500 in cash awards. After the competition ends, vendors have 90 days to release patches before ZDI publicly discloses the vulnerabilities. On the third and last day of Pwn2Own, they will again target the Samsung Galaxy S25, as well as multiple NAS devices and printers. Eugene of Team Z3 will also attempt to demonstrate a WhatsApp Zero-Click remote code execution bug eligible for a $1 million reward. Meta is co-sponsoring Pwn2Own Ireland 2025 alongside Synology and QNAP, with the hacking contest taking place from October 21 to October 23 in Cork. Pwn2Own Ireland 2025 features eight categories targeting flagship smartphones (Samsung Galaxy S25, Apple iPhone 16, and Google Pixel 9), printers, network storage systems, home networking equipment, messaging apps, smart home devices, surveillance equipment, and wearable technology (including Meta's Quest 3/3S headsets and Ray-Ban Smart Glasses). This year's contest expands the attack vectors to include USB port exploitation on mobile handsets, requiring researchers to hack locked phones via a physical connection. However, traditional wireless protocols such as Wi-Fi, Bluetooth, and near-field communication (NFC) are still valid attack vectors. During the Pwn2Own Ireland 2024 event, hackers earned $1,078,750 for over 70 zero-days, with Viettel Cyber Security taking home $205,000 in cash after exploiting QNAP, Sonos, and Lexmark flaws. In January 2026, the ZDI will return to the Automotive World technology show in Tokyo for the third Pwn2Own Automotive contest, again sponsored by Tesla. Update: Revised title and story with the correct number of zero-days exploited during Pwn2OWn Ireland Day 2. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 22, 2025extracted
Hackers exploit 34 zero-days on first day of Pwn2Own Ireland
On the first day of Pwn2Own Ireland 2025, security researchers exploited 34 unique zero-days and collected $522,500 in cash awards. The highlight of the day was Bongeun Koo and Evangelos Daravigkas of Team DDOS chaining eight zero-day flaws to hack the QNAP Qhora-322 Ethernet wireless router via the WAN interface and gain access to a QNAP TS-453E NAS device. For this successful attempt, they won $100,000 and are now in second place on the Master of Pwn leaderboard with 8 points. Synacktiv Team, Sina Kheirkhah of the Summoning Team, the DEVCORE Team, and Stephen Fewer of Rapid7 have also earned $40,000 each after gaining root on the Synology BeeStation Plus, the Synology DiskStation DS925+, the QNAP TS-453E, and the Home Assistant Green, respectively. STARLabs, Team PetoWorks, Team ANHTUD, and Ierae researchers hacked the Canon imageCLASS MF654Cdw multifunction laser printer four times, while STARLabs also hacked the Sonos Era 300 smart speaker to earn $50,000, and Team ANHTUD exploited the Phillips Hue Bridge to collect $40,000 in cash. Sina Kheirkhah and McCaulay Hudson of the Summoning Team have used an exploit chain combining two zero-days to gain root on a Synology ActiveProtect Appliance DP320 and win another $50,000. Summoning Team won a total of $102,500 during the first day of the competition and is at the top of the Master of Pwn leaderboard with 11.5 points. The Zero Day Initiative (ZDI) organizes the event to identify security vulnerabilities in targeted devices before threat actors can exploit them, coordinating responsible disclosure with the affected vendors. After the zero-day flaws are exploited during Pwn2Own events, vendors are given 90 days to release security updates before Trend Micro's Zero Day Initiative publicly discloses them. The Pwn2Own Ireland 2025 hacking competition features eight categories targeting flagship smartphones (Apple iPhone 16, Samsung Galaxy S25, and Google Pixel 9), messaging apps, smart home devices, printers, home networking equipment, network storage systems, surveillance equipment, and wearable technology (including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets). This year, the ZDI also expanded the attack vectors for the mobile category to include USB port exploitation for mobile handsets, which requires competitors to hack into locked phones through physical connections. However, traditional wireless protocols such as Bluetooth, Wi-Fi, and near-field communication (NFC) remain valid attack vectors. On the second day, security researchers will again target devices in the network-attached storage, printers, smart home, and surveillance systems categories, as well as the Samsung Galaxy S25 in the mobile phones category. As announced in August, this is also the first time ZDI will offer a $1 million reward to security researchers who demo a zero-click WhatsApp exploit that allows code execution without user interaction. Meta, alongside QNAP and Synology, is co-sponsoring the Pwn2Own Ireland 2025 hacking contest, which takes place from October 21 to October 23 in Cork, Ireland. During last year's Pwn2Own Ireland event, security researchers earned $1,078,750 for more than 70 zero-day vulnerabilities, with Viettel Cyber Security collecting $205,000 for QNAP, Sonos, and Lexmark bugs. In January 2026, the ZDI will return to the Automotive World technology show in Tokyo as a sponsor. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 21, 2025extracted
Pwn2Own hacking contest pays $1 million for WhatsApp exploit
The Zero Day Initiative is offering a $1 million reward to security researchers who will demonstrate a zero-click WhatsApp exploit at its upcoming Pwn2Own Ireland 2025 hacking contest. The record bounty targets zero-click security flaws that allow code execution without user interaction on the messaging platform used by more than three billion people worldwide. Meta, alongside Synology and QNAP, is co-sponsoring the Pwn2Own Ireland 2025 competition, which will take place from October 21 to October 24 in Cork, Ireland. "As you might have guessed from the title, we're excited to announce that Meta is co-sponsoring this year's event, and they are hoping to see some great WhatsApp exploits. They are so excited for it, we're putting up $1,000,000 for a 0-click WhatsApp bug that leads to code execution," the Zero Day Initiative announced Thursday. "We also will have lesser cash awards for other WhatsApp exploits, so be sure to check out the Messaging section for full details. We introduced this category last year, but no one attempted it. Perhaps a number with two commas will provide the needed motivation." The contest features eight categories targeting mobile phones, messaging apps, home networking equipment, smart home devices, printers, network storage systems, surveillance equipment, and wearable technology, including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets, as well as Samsung Galaxy S25, Google Pixel 9, and Apple iPhone 16 flagship smartphones. The ZDI has also expanded the attack vectors for the mobile category to include USB port exploitation for mobile devices, requiring contestants to compromise locked phones through physical connections. Traditional wireless protocols, such as Wi-Fi, Bluetooth, and near-field communication, remain valid attack methods. Registration closes on October 16 at 5 p.m. Irish Standard Time, with the contest order determined by a random drawing. The Zero Day Initiative operates the event to identify vulnerabilities before malicious actors can exploit them, coordinating responsible disclosure with affected vendors. After the flaws are exploited during Pwn2Own events, vendors have 90 days to release security updates before Trend Micro's Zero Day Initiative publicly discloses them. Last year's Pwn2Own Ireland event awarded $1,078,750 for over 70 unique zero-day vulnerabilities, with Viettel Cyber Security collecting $205,000 for flaws demonstrated in QNAP NAS, Sonos speakers, and Lexmark printers. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 1, 2025extracted