Cyber & Technology — 2026-05-17
Pwn2Own Berlin 2026 Concludes with $1.3 Million Paid for 47 Zero-Day Vulnerabilities
BLUFDemonstrated exploitation of OpenAI Codex confirms AI-assisted development tools now carry the same exploitable attack surface as legacy enterprise software, a risk enterprise procurement has yet to price into vendor evaluations.
The
Analysis
Berlin's 47 zero-days against Vancouver 2025's 32 signal that offensive research is outpacing defensive patching across both traditional enterprise software and AI infrastructure, a pattern the concurrent Calif M5 kernel exploit reinforces, per a single Cyber Insider report pending ZDI confirmation. Successful exploitation of OpenAI Codex establishes that AI-assisted development tools carry an attack surface enterprise procurement has not priced into risk models. The count may instead reflect incentive design: higher AI-target payouts redirected research effort that would otherwise have targeted traditional software, overstating any genuine acceleration in exploitable attack surface.
Berlin's 47 zero-days against Vancouver 2025's 32 signal that offensive research is outpacing defensive patching across both traditional enterprise software and AI infrastructure, a pattern the concurrent Calif M5 kernel exploit reinforces, per a single Cyber Insider report pending ZDI confirmation. Successful exploitation of OpenAI Codex establishes that AI-assisted development tools carry an attack surface enterprise procurement has not priced into risk models. The count may instead reflect incentive design: higher AI-target payouts redirected research effort that would otherwise have targeted traditional software, overstating any genuine acceleration in exploitable attack surface.