Pwn2Own Ireland: AI infrastructure gave 23 of the 98 zero-days but 15% of the $1,262,000
ZDI's scoreboard says $1,262,000 for 98 unique zero-days over 61 attempts, a total its three results posts reproduce only after three missing attempts are added back. Phones took 52% of the cash and 11 zero-days; four AI infrastructure products took 15% and 23.
By Parminder Kumar Sharma · · 22 min read

Phones took 52% of the cash. AI infrastructure produced 23 of the 98 zero-days.
The Zero Day Initiative (ZDI) shows, in standings last updated at 21:01 BST on 8 October (revision 493) with all attempts complete, $1,262,000 in cash for 98 unique zero-days, across 61 of 61 attempts, 51 of them successful. BleepingComputer's headline carries the same two figures. We rebuilt them from ZDI's three results posts and set them against ZDI's own categories. Every share below is derived by us.
Mobile phones took $656,000, 52.0% of the cash, and produced 11 of the 98 zero-days (11.2%). ZDI's AI Infrastructure category took $187,750, 14.9% of the cash, and produced 23 (23.5%). Smart home took 19.6% of the cash and 40 of the zero-days. The phone total rests on one product: three Google Pixel 10 awards, $562,500 together, are 44.6% of everything paid.
Most of that gap between money and bugs is a price list. ZDI set a remote Pixel 10 entry at $300,000 and each AI Infrastructure product at $20,000 to $40,000, so one success pays very differently from another. The cash share measures ZDI's prices. The zero-day count says more about how many distinct flaws the contest produced, and it also depends on which products ZDI invited, how many teams chose each one and how much they prepared.
ZDI categories at Pwn2Own Ireland 2026, recounted from ZDI's three results posts and its scoreboard (derived). Shares are of $1,262,000 and of 98 zero-days.
| ZDI category | Attempts (succeeded) | Cash (share) | Zero-days (share) |
|---|---|---|---|
| Mobile phones | 11 (10) | $656,000 (52.0%) | 11 (11.2%) |
| Smart home | 19 (18) | $247,250 (19.6%) | 40 (40.8%) |
| AI Infrastructure | 13 (10) | $187,750 (14.9%) | 23 (23.5%) |
| Printers | 13 (10) | $104,250 (8.3%) | 20 (20.4%) |
| Coding agent | 1 (1) | $40,000 (3.2%) | 1 (1.0%) |
| Wellness | 4 (2) | $26,750 (2.1%) | 3 (3.1%) |
| All categories | 61 (51) | $1,262,000 | 98 |
The totals reproduce, but not from the three posts alone
ZDI's three results posts do not print $1,262,000 or 98 anywhere. They print one short result line per attempt, written as each day went on. We read all three posts, the schedule post and the July targets post in a browser tab and by HTTP (the two matched), keyed each line and added them up. The posts carry 58 result lines. The scoreboard counts 61 attempts, so three are missing from the posts, and the arithmetic says which. The schedule lists 63 attempts: 21, 25 and 17 over the three days.
Per-day recount from ZDI's result lines, with the gaps below filled from the scoreboard (derived). ZDI's Day Two post states Day One as $388,500 for 32 unique zero-days; BleepingComputer states Days Two and Three; all three match.
| Day | Attempts (succeeded, failed) | Cash | Zero-days |
|---|---|---|---|
| Day One, 6 Oct | 21 (16, 5) | $388,500 | 32 |
| Day Two, 7 Oct | 24 (21, 3) | $232,500 | 45 |
| Day Three, 8 Oct | 16 (14, 2) | $641,000 | 21 |
| Total | 61 (51, 10) | $1,262,000 | 98 |
Seven gaps in the posts, and how each closes. Each gap is closed by arithmetic from ZDI's or BleepingComputer's own totals, so each closure is labelled derived.
What the three posts leave out, and what recovers it (all derived)
| Gap in the posts | Recovered from | Result |
|---|---|---|
| Day One, 19:00, a Canon copier entry has no result line | ZDI Day One total less the 20 printed lines | $20,000, 1 zero-day, a success |
| Day Three, 16:45, a Philips Hue Bridge Pro entry has no line | BleepingComputer Day Three total less 13 printed payouts; scoreboard team total | $6,000, 1 zero-day, a success |
| Day Three, 15:15, a Chroma entry has no line | Scoreboard: the team has two attempts and no success | A failure |
| Day Two, 13:00, a Galaxy S26 line prints no payout | BleepingComputer Day Two total less 20 printed payouts | $12,500 |
| Four Day Two success lines print no bug count | Team totals on the scoreboard | 2, 6, 3 and 2 zero-days |
| One Day Three Pixel 10 line says collision, prints no count | Team total on the scoreboard | 2 zero-days |
| Two scheduled attempts have no line of any kind | Points arithmetic, next paragraph | Two withdrawals (inferred) |
Two scheduled attempts did not happen. A Pixel 10 USB entry on Day Two (09:30) and a Brother printer entry on Day Three (15:15) are on the schedule and have no result line, success or failure. ZDI's rules say an entrant who withdraws after the contest starts has half of that attempt's Master of Pwn points deducted. The scoreboard totals for the two entrants equal their printed points less exactly that: 3.5 plus 2 minus half of 7.5 is 1.75, and 2 plus 2 minus half of 2 is 3. We therefore count two withdrawals, as an inference, because ZDI's pages do not use the word. ZDI's Day Two introduction (24 attempts, roughly $780,000) already excludes the first; its Day Three introduction (17 attempts, roughly $1.33 million) still counts the second. We recomputed both dollar figures from the schedule's list prices and they agree.
Where the press and ZDI differ. Not on the headline totals: ZDI's scoreboard, BleepingComputer ($1,262,000 and 98) and SecurityWeek (more than $1.2 million) agree. SecurityWeek's headline gives $560,000 for the Pixel 10 exploits; the three result lines sum to $562,500 and its text says "more than $560,000", so that is rounding, not a conflict. Two smaller differences. ZDI's rules and its scoreboard header give the contest as 6 to 9 October, but all 61 attempts were complete after Day Three on 8 October. And ZDI's Day Two introduction counts five Home Assistant Green attempts and four AI Infrastructure attempts where its own schedule table lists six and six, so this briefing counts tables, not prose.
Method, and whose figures these are. ZDI is the contest sponsor, sets the prices, decides what counts as a zero-day, and belongs to a security company whose customers receive protection filters ahead of public disclosure, according to its own pages. That is a commercial interest, not a reason to doubt a count, but it is whose count this is. We counted a bug in a chain as unique unless the result line says it was known. That rule reproduces ZDI's own Day One figure exactly and, once the gaps are closed, BleepingComputer's figures for the other two days.
Master of Pwn. Ikotas Labs, Inc. won the title, which ZDI's Day Three post confirms, with 42.5 points and $361,000 from four successes in five attempts: a Galaxy S26, OpenAI Codex, Oracle Autonomous AI Database and the $300,000 Pixel 10 award. Xint was second on 27.5 points and $240,000, and a third team also finished on 27.5 points with $125,000 (scoreboard figures; the sums of the matching result lines agree).
What a collision is, and why the label does not track the money
What a collision is. ZDI's rules say the bugs in an entry must be "unknown, unpublished, and/or not previously reported to the vendor or the Sponsor". If an entry uses a bug already known, ZDI may accept it and pay "at a value less than the initial prize offering". ZDI's result lines call that a collision and say how. One Galaxy S26 entry used four bugs "but 3 were known by the vendor". One Sonos entry had one bug that "was publicly known". Another Galaxy S26 entry had one bug "known to the vendor (yet unpatched)". ZDI's 2022 contestant guide adds a third kind: two entrants who use what looks like the same bug must show whether it is "unique or a bug collision". So a collision means someone else already had the bug, whether the vendor, the public record or another entrant. It is not a new zero-day, which fits ZDI's 98 counting only bugs that were not collisions: our recount reproduces the 98 that way. And it is not a fix: that last line says known and unpatched.
The collision share. ZDI labels 29 of the 49 result lines for successful attempts "SUCCESS / COLLISION": 7 of 15 on Day One, 13 of 21 on Day Two and 9 of 13 on Day Three, or 59.2% overall (derived). The share rises day by day, 47%, 62% and 69%, which fits the 2022 guide's remark that "the chances for bug collisions are higher" for entrants who draw late slots. By category it runs from 9 of 10 phone successes (all three Pixel 10 and six of seven Galaxy S26) to 6 of 10 in AI Infrastructure and 1 of 10 for printers. Two successes have no line and are unlabelled. In the 44 success lines that print a chain length, 67 of the 148 bugs, 45%, are described as collisions (derived).
The label and the money. A collision lowers the award, but not by a fixed rule, and a lower award does not prove a collision. Among the 29 collision-labelled successes ZDI paid from 12.5% to 100% of the list price, with a median of 22.5%; one, a Pixel 10 entry that followed an earlier Pixel 10 success paid $150,000, was paid the full $300,000. Among the 20 plain successes, 10 were paid in full and 10 were paid 25% to 50%, for example $10,000 on a $40,000 Oracle entry with no collision stated. ZDI's July post explains part of that: "only the first demonstration in a category wins the full cash award", so a later success is paid less whether or not a collision is printed. In 11 of the 14 products that fell, the first successful entry was paid the full list price. The three that were not, a Pixel 10, a Galaxy S26 and a Chroma entry, were all collision-labelled. All of this is derived.
Why a defender should care. A collision shows that a flaw could be found by more than one party. It does not show that anyone used it. It also means the 98 undercounts the flaws in the chains: the chains held at least 67 further bugs that were already known. If a vendor says a reported bug was "already known", ask whether that means known to the vendor and unfixed, which is how ZDI used the phrase once, or known and fixed.
What fell in AI infrastructure, and what the category list says
ZDI's rules list five AI Infrastructure targets: Chroma ($20,000), Postgres pgvector ($30,000), and Oracle Autonomous AI Database, LiteLLM and Dynamo at $40,000 each. A separate Coding Agent category lists two more at $40,000, Anthropic's Claude Code and OpenAI's Codex. ZDI's July post says it introduced the AI Infrastructure targets at Pwn2Own Berlin and "decided to immediately bring them back" for Ireland. The rules require an AI Infrastructure attempt to be launched from the contestant's laptop within the contest network, with authentication configured if the product has it, and say a successful entry "must bypass authentication of the target".
AI Infrastructure and Coding Agent results (derived from ZDI result lines and scoreboard). Zero-days: Dynamo's 2 comes from a team total.
| Product (list price) | Fell of tried | Chain lengths, collisions | Paid |
|---|---|---|---|
| Oracle Autonomous AI Database ($40,000) | 5 of 5 | 5, 5, 7, 4, 5 bugs; 3 collision-labelled | $76,250 |
| LiteLLM ($40,000) | 2 of 2 | 2 and 4 bugs; 1 collision-labelled | $55,000 |
| Dynamo ($40,000) | 1 of 1 | Length not printed; none labelled | $40,000 |
| Chroma ($20,000) | 2 of 5 | 3 and 3 bugs; both collision-labelled | $16,500 |
| AI Infrastructure total | 10 of 13 | 6 of 10 collision-labelled; 23 zero-days | $187,750 |
| OpenAI Codex, Coding Agent ($40,000) | 1 of 1 | 1 bug; none labelled | $40,000 |
The reading. Four AI infrastructure products fell, 10 times in 13 attempts, for $187,750. All three failures were Chroma attempts, one of them recovered from the scoreboard rather than a result line. Oracle fell five times out of five, so five separate chains, with 16 unique zero-days among them; three of the five were collision-labelled, so those chains used bugs already known to someone else. Codex fell once, $40,000, to what ZDI calls a single argument injection bug. For the others ZDI prints a class on only two chains: improper input validation with code injection on a LiteLLM entry, and a use-after-free and a type confusion at the end of a seven-bug Oracle chain. Those one-line classes are all the contest publishes, and all this briefing repeats.
What the list does not show. Postgres pgvector and Claude Code were on the rules list at $30,000 and $40,000 and have no attempt on the schedule, and neither do Apple iPhone 17, WhatsApp, Dexcom Stelo or Oura Ring 5. Absence from the schedule says no attempt was scheduled; it says nothing about those products' security. Equally, a product that fell here is not shown to be weaker than one that was not entered. The products are ZDI's selection, five teams were scheduled against each of Oracle and Chroma, and ZDI's rules say target versions and configurations are given to entrants at registration, so the entrants had time to prepare.
What it does show, carefully. Data and agent infrastructure now sits on the same price list as phones and printers, at a contest that chose to bring the category back for a second event, and entrants prepared chains against it: 11 successful chains across four AI infrastructure products and one coding agent in three days. That is a handful of results from two events, not a trend. Its relevance to AI governance is narrower and practical. An AI gateway, a vector store, an inference server and a managed AI database are ordinary network services with authentication in front of them, and the contest's rules say authentication was configured where the product has it and was still what entrants were paid to get past.
Stated and not stated
What the sources state and what they do not (sources: ZDI scoreboard, results posts, rules, disclosure policy; BleepingComputer; vendor pages read on 9 October)
| Topic | Stated | Not stated |
|---|---|---|
| Totals | Scoreboard, 8 October 21:01 BST: $1,262,000, 98 unique zero-days, 61 of 61 attempts | Any total in the three results posts; 3 attempts and 1 payout are absent from them |
| Collisions | 29 result lines labelled; Day One lines say "known by the vendor", "publicly known" or "previously known"; one adds "yet unpatched" | Who knew each bug, since when, or whether a fix exists |
| Disclosure clock | Rules: details go to the affected vendors. ZDI standard policy: 120 days from initial notification | A contest deadline in days in any ZDI page read; the date vendors were told; BleepingComputer says 90 days |
| Exploitation | Bugs were demonstrated at the contest on targets ZDI installed and configured | Any use of any of these bugs outside the contest |
| Fixes | Vendor pages read on 9 October, in the vendor section | A fix tied to any contest bug, on any page read |
| Versions | Rules: latest fully patched software, default configuration, authentication on where available | Which build of any product fell; which Oracle deployment (cloud service, container or on-premises) was tested |
| Withdrawals | Rules: half the points deducted on withdrawal | That any attempt was withdrawn; we infer two from points |
The disclosure clock: 90 days, 120 days, and the dates they give
ZDI's rules say vulnerabilities and exploit techniques revealed by winners "will be disclosed to the affected vendors" and that the exploits and whitepapers become ZDI's property. Neither the rules nor the four results posts give a deadline in days. ZDI's disclosure policy gives its standard case as four months, 120 days, and its FAQ says the count runs from initial notification. Its Upcoming Advisories page lists 719 advisories pending public disclosure, and every one of the 719 rows carries a deadline exactly 120 days after its reported date (we checked each row). BleepingComputer says vendors must patch contest zero-days "within 90 days" before ZDI shares details. That is the outlet's statement, not a ZDI page we could read, so this briefing gives both clocks and does not choose between them.
Dates the two clocks give (derived arithmetic; the start date is not stated)
| Clock, counted from | Ends | Day |
|---|---|---|
| 90 days from 8 October 2026 | 6 January 2027 | Wednesday |
| 120 days from 8 October 2026 | 5 February 2027 | Friday |
| 90 days from 6 October 2026 | 4 January 2027 | Monday |
Neither date is a patch date. It is when ZDI's policy lets it publish details if a vendor has not acted, and policy says extensions are possible "only in rare circumstances". As read on 9 October, none of the 12 pending entries reported between 6 and 8 October names a contest product's vendor: they name Apple, Adobe, Microsoft, Malwarebytes, Parallels, Fuji Electric, Avira and MindsDB. So ZDI's public list does not yet show the contest bugs, and how long ZDI takes to list them is not stated. The disclosure policy also says protection filters "may be distributed" to ZDI's own customers at the same time the vendor is notified. Whether that has happened for these bugs is not stated.
What the vendors had published when read on 9 October
We read the vendor's own security or release page for each product below, looking for any entry that ties a fix to a contest bug. We found none, but read the limits first. The contest ended on 8 October, the October bulletins for Android, Pixel and Samsung were published on 5 and 6 October, and a vendor can ship a fix without an advisory: the NCSC's update-by-default guidance warns that vendors may "silently" update some vulnerabilities "without public acknowledgement". So "no advisory yet" is the state of the pages, not a statement that nothing is fixed.
Vendor pages read on 9 October 2026 (primary pages; counts are ours)
| Vendor page | Latest entry on the page | Fix for a contest bug stated? |
|---|---|---|
| Google Pixel Update Bulletin and Android Security Bulletin | Pixel: published 6 October, patch level 2026-10-05, 6 CVEs. Android: published 5 October, updated 8 October, 25 CVEs | No. Both predate the results; neither names Pwn2Own or ZDI. November bulletins not out |
| Samsung Mobile Security, SMR-OCT-2026 | Published 6 October: 27 SVE items, 13 described, all local-attacker classes; the page says some items "cannot be disclosed at this time" | Not stated either way: nothing links an item to the contest |
| Philips Hue Bridge Pro and Bridge release notes; Signify advisory page | Both notes pages: latest entry 24 September 2026, "several small changes behind the scenes". Signify advisory page: 5 advisories, newest 22 March 2023, brands listed do not include Hue | No |
| Home Assistant 2026.10 release notes; GitHub advisories | Release of 7 October, no security item tied to the contest. GitHub: 25 published advisories, newest 16 September | No |
| Oracle Critical Patch Update schedule | July 2026 CPU latest revision 20 August. Next CPU 20 October, pre-release notice Thursday 15 October; next CSPU 17 November | Not yet. Page says Oracle applies patches to Oracle Cloud under its own change process |
| LiteLLM GitHub advisories | 17 published, newest 1 October 2026; none since 6 October | No |
| Chroma GitHub advisories | None published | No |
| NVIDIA PSIRT bulletins (Dynamo) | One Dynamo bulletin: July 2026, published 4 August, Critical, 15 CVEs. Newest bulletin on the page: 30 September. NVIDIA says bulletins are now also on GitHub; not read | No |
| OpenAI Codex GitHub advisories | One published, 19 September 2025 | No |
What we did not read. Sonos, Brother, Canon, Lexmark and Garmin all had entrants against them. Canon's and Brother's advisory pages answered an HTTP request with 403 and we did not try to get round that. We found no readable advisory page for Sonos, Lexmark or Garmin in the window. Check those yourself if you run them. Oracle's page also cannot tell us which form of Autonomous AI Database ZDI tested, so whether Oracle's customers need to do anything, or Oracle does it for them, is the first question for an Oracle estate.
What a UK organisation can do with this
ZDI's own July post says it removed most consumer devices and kept "pro-sumer" ones that "could have an impact on enterprises". That describes the list: phones, a smart-home bridge, printers and copiers, and AI infrastructure (a database service, a gateway, retrieval and inference software). Two UK clocks apply once a fix exists. The NCSC's update by default guidance (version 2.1, reviewed 1 May 2026) sets best-practice timescales for all updates regardless of severity: 5 days for internet-facing services and software, 7 days for operating systems and applications, applied automatically, and 14 days for internal or air-gapped systems. Cyber Essentials v3.3 (April 2026) requires software in scope to be updated within 14 days of release where the update fixes vulnerabilities the vendor calls critical or high risk, scored CVSS 7 or above, or gives no severity at all. It lists servers, laptops, mobile phones, routers, IaaS, PaaS and SaaS as in scope, and says automatic updates must be on where possible. The same clocks are worked through on a live advisory in our Splunk briefing.
For a managed service the clock may not be yours. Cyber Essentials' table of who typically implements each control puts security update management with "both your organisation and the cloud provider" for IaaS and PaaS and with "the cloud provider" for SaaS, and says that where a provider does it for you, a contract or a document the contract references must say so. For an Oracle AI database service, read which of those it is, and read what your contract commits Oracle to.
The consumer products raise a different question. The UK's consumer connectable product security regime, in force since 29 April 2024 and explained in our briefing on preinstalled firmware malware, requires manufacturers to ban universal default passwords, publish how to report security issues and publish minimum security update periods, according to GOV.UK guidance. It does not set a deadline for fixing a given flaw, so it will not tell you when a Pixel, a Hue bridge or a home printer gets a fix. It tells you how long the maker has promised to keep issuing them. Whether a given product falls inside the regime, an office copier for instance, is a legal question this briefing does not answer. The NCSC's consumer guidance says to turn on automatic updates and to avoid buying or using phones that are no longer supported.
What to do, in order
Take this with you
Defender actions, most urgent first
- List what you run from these families: Pixel and Galaxy handsets (managed and personal), smart-home bridges, speakers and hubs in offices and in staff homes, printers and copiers, and AI infrastructure: LLM gateways such as LiteLLM, vector stores such as Chroma, inference servers such as Dynamo, Oracle AI database services, and coding agents. Include the ones a team stood up without telling IT.
- For every AI infrastructure instance, confirm authentication is on and that no untrusted network, and above all the internet, can reach it. The contest rules put authentication in front of the targets and still paid entrants to get past it, so authentication alone is not enough; limiting who can reach the service is the control left to you (our inference).
- Turn on automatic updates on every phone and smart device, and record each device's support end date. Replace anything out of support: Cyber Essentials requires software to be licensed and supported, and the NCSC says avoid unsupported phones.
- Put the watch dates in a calendar: Oracle's pre-release notice on Thursday 15 October and its Critical Patch Update on Tuesday 20 October, its next Critical Security Patch Update on 17 November, the monthly Android, Pixel and Samsung bulletins, NVIDIA PSIRT, and the GitHub advisory feeds for LiteLLM, Chroma and Home Assistant. NVIDIA says from 1 October 2026 its bulletins appear on GitHub as well as its site.
- Decide your clock before a fix lands. Internet-facing: 5 days. Operating systems and applications: 7, automatic. Internal: 14. Cyber Essentials: 14 days for critical or high or unrated fixes. If Oracle's 20 October update carries a fix for something you run, 14 days from release is Tuesday 3 November 2026.
- Ask each AI infrastructure supplier, managed or self-hosted, three questions in writing: was a contest bug reported against your product, when will a fix ship, and how will you tell customers. For a managed database, ask which party applies the patch and under which clause.
- Treat "already known to the vendor" as a reason to move sooner, not later. ZDI used it once to mean known and unpatched.
- Re-check the vendor pages after Oracle's 20 October update and the November Android, Pixel and Samsung bulletins, then on 6 January and 5 February 2027, the two dates the clocks give, and look for ZDI advisories on the contest bugs.
The question
A contest that paid for five chains against one managed database, and for two against one AI gateway, tells you which services skilled teams will prepare against. It does not tell you which of yours they can reach.
Could you list, inside the hour, every LiteLLM, Chroma, Dynamo or Oracle AI database instance your organisation runs, and say which networks can reach each one?
Key facts
Sources
- PrimaryZDI's published standings for Pwn2Own Ireland 2026, read in a browser tab with its public JSON feed: revision 493, updated 8 October 21:01 BST, $1,262,000, 98 unique zero-days, 61 of 61 attempts, 51 successful, per-team totals. ZDI is the contest sponsor and wrote the figures.Zero Day Initiativeaccessed 2026-10-09
- PrimaryThe full schedule, read in full: 63 scheduled attempts, targets, categories and list prices.Zero Day Initiativeaccessed 2026-10-09
- PrimaryDay One results, read in full: 20 result lines, collision wording, the lines used for the recount.Zero Day Initiativeaccessed 2026-10-09
- PrimaryDay Two results, read in full: 24 result lines and the statement of Day One as $388,500 for 32 unique zero-days.Zero Day Initiativeaccessed 2026-10-09
- PrimaryDay Three results and Master of Pwn, read in full (last modified 8 October 20:54 BST): 14 result lines and the Master of Pwn statement.Zero Day Initiativeaccessed 2026-10-09
- PrimaryJuly post on new targets and categories, read in full: the seven categories, the AI targets introduced at Berlin, the first-demonstration payout rule.Zero Day Initiativeaccessed 2026-10-09
- PrimaryOfficial contest rules, read in full: price tables for all seven categories, previously known vulnerability rule, withdrawal penalty, disclosure to vendors.Zero Day Initiativeaccessed 2026-10-09
- PrimaryDisclosure policy: the 120 day standard window and the wording on protection filters.Zero Day Initiativeaccessed 2026-10-09
- PrimaryUpcoming Advisories list read on 9 October: 719 pending advisories, each with a deadline 120 days after the reported date; no contest vendor among entries reported 6 to 8 October.Zero Day Initiativeaccessed 2026-10-09
- PrimaryZDI 2022 contestant guide: the white paper test for a unique bug against a bug collision and the remark on late slots.Zero Day Initiativeaccessed 2026-10-09
- PrimaryPixel Update Bulletin, October 2026, read in a browser tab: published 6 October, patch level 2026-10-05.Googleaccessed 2026-10-09
- PrimaryAndroid Security Bulletin, October 2026, read in a browser tab: published 5 October, updated 8 October, 25 CVEs.Googleaccessed 2026-10-09
- PrimarySamsung Mobile Security updates page, SMR-OCT-2026 read in full: published 6 October, 27 SVE items.Samsungaccessed 2026-10-09
- PrimaryHue Bridge Pro release notes: latest entry 24 September 2026, no security text.Philips Hueaccessed 2026-10-09
- PrimarySignify security advisory page, read in a browser tab: 5 advisories, newest 22 March 2023, filter brands Cooper Lighting, Interact and Philips Dynalite.Signifyaccessed 2026-10-09
- PrimaryHome Assistant 2026.10 release notes of 7 October, searched for security items.Home Assistantaccessed 2026-10-09
- PrimaryPublished advisories, read through GitHub's public API: 25, newest 16 September 2026.Home Assistant on GitHubaccessed 2026-10-09
- PrimaryCritical Patch Update schedule: next CPU 20 October 2026, pre-release notice the Thursday before, next CSPU 17 November, cloud patching statement.Oracleaccessed 2026-10-09
- PrimaryPublished advisories through GitHub's public API: 17, newest 1 October 2026.LiteLLM on GitHubaccessed 2026-10-09
- PrimaryPublished advisories through GitHub's public API: none.Chroma on GitHubaccessed 2026-10-09
- PrimaryNVIDIA PSIRT bulletin list read in a browser tab: one Dynamo bulletin, July 2026, published 4 August 2026.NVIDIAaccessed 2026-10-09
- PrimaryPublished advisories through GitHub's public API: one, 19 September 2025.OpenAI Codex on GitHubaccessed 2026-10-09
- PrimaryUpdate by default, version 2.1, reviewed 1 May 2026, read in full: 5, 7 and 14 day timescales and the warning on silent updates.NCSCaccessed 2026-10-09
- PrimaryCyber Essentials requirements for IT infrastructure v3.3, April 2026, security update management and cloud responsibility table read with pypdf.NCSCaccessed 2026-10-09
- PrimaryConsumer guidance on updates, reviewed 21 December 2021: automatic updates, unsupported phones.NCSCaccessed 2026-10-09
- PrimarySmart devices in the home, reviewed 23 February 2024: update advice and the April 2024 law.NCSCaccessed 2026-10-09
- PrimaryOPSS guidance on the consumer connectable product security regime: in force 29 April 2024 and its three requirements.GOV.UKaccessed 2026-10-09
- Reported byNews report of 9 October: headline totals, Day Two and Day Three totals, and the 90 day statement. Secondary; used as a pointer and to close arithmetic gaps.BleepingComputeraccessed 2026-10-09
- Reported byNews report of 9 October: Pixel 10 awards and the $1.2 million total. Secondary.SecurityWeekaccessed 2026-10-09
- Reported byEarlier briefing that explains the UK product security regime; linked rather than restated.pk-sharma.comaccessed 2026-10-09
- Reported byEarlier briefing that works the NCSC and Cyber Essentials clocks through on a live advisory; linked rather than restated.pk-sharma.comaccessed 2026-10-09


