Pwn2Own Berlin 2026 showcased AI as both an offensive tool and a target. Researchers used LLMs and agentic coding tools to discover vulnerabilities, while Claude Code, OpenAI Codex, Cursor, Ollama, ChromaDB, and the Nvidia Container Toolkit were all successfully exploited. Common root causes across AI coding agents included overpowered underlying developer tools and misplaced trust between agents and users. Every competing team used LLMs in their workflow, primarily for speed rather than accuracy, with high false positive rates reported during bug discovery. Exposed instances of Ollama and ChromaDB on the internet represent significant risks, as successful exploits could grant host-level access. The author warns that vibe coding, supply chain risks, and accelerating software development will expand the attack surface for future competitions.

10m read timeFrom trendmicro.com
Post cover image
171 Impressions