Pwn2Own Automotive: $1.3M for 49 zero-days, Tesla hacked twice

Pwn2Own Automotive: $1.3M for 49 zero-days, Tesla hacked twice

January 26, 2024 at 07:37AM

Pwn2Own Automotive’s first edition ended with competitors earning $1,323,750, hacking Tesla twice, and demonstrating 49 zero-day bugs in electric car systems at the Tokyo, Japan contest. Team Synacktiv won $450,000, fuzzware.io $177,500, and Midnight Blue/PHP Hooligans $80,000. The next competition is scheduled for March 20th in Vancouver. Further details can be found on the Pwn2Own website.

Here are the key takeaways from the meeting notes:

– The first edition of Pwn2Own Automotive took place at the Automotive World auto conference in Tokyo, Japan from January 24 to 26.
– Competitors earned $1,323,750 for hacking Tesla twice and demonstrating 49 zero-day bugs in electric car systems.
– The contest was organized by Trend Micro’s Zero Day Initiative (ZDI).
– After a zero-day vulnerability is exploited and reported, vendors have 90 days to release security patches before ZDI discloses it publicly.
– Team Synacktiv won the Pwn2Own Automotive 2024 contest, earning $450,000 in cash.
– Synacktiv demonstrated vulnerabilities in Tesla, Ubiquiti Connect EV Station, JuiceBox 40 Smart EV Charging Station, and the Automotive Grade Linux OS.
– The Pwn2Own Vancouver 2024 competition is scheduled to start on March 20th, featuring a prize pool of over $1,000,000 for exploits in various software categories and automotive systems found in Tesla Model 3 and Model S cars.

If you need further information or details, feel free to ask.

Full Article