Love some of my interactions on @Bugcrowd
Triager: NMI
Me: provide updated PoC
Triager: uses first one again, ignores new one from the comment, closes as not reproducible
๐ฏ๐ฏ๐ฏ
[ Chromium ] Stealth request that bypasses CSP, hides from DevTools, and leaks the real User-Agent (in case you faked it ๐)
brokenbrowser.com/blog/2026-05-0โฆ
That's a wrap on Pwn2Own Berlin 2026! ๐ $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own#P2OBerlin
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own#P2OBerlin
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin