ICS/OT

Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

White hat hackers received $180,000 at Pwn2Own Miami 2023 for exploits targeting widely used ICS products.

ICS Pwn2Own

White hat hackers received a total of $180,000 at the Pwn2Own Miami 2023 hacking contest this week for exploits targeting widely used industrial control system (ICS) products.

At the ICS edition of Pwn2Own, hackers have been invited to demonstrate exploits against OPC UA, data gateway and edge products made by Aveva, Inductive Automation, ProSys, PTC, Softing Industrial Automation, Triangle MicroWorks, and Unified Automation.

Prizes ranged between $5,000 and $40,000 per exploit chain, but none of the participants has earned more than $20,000 for a single exploit. 

Researchers received $20,000 for remote code execution exploits targeting Triangle Microworks SCADA Data Gateway, Inductive Automation Ignition, and Softing EdgeAggregator Siemens. A majority of entries demonstrated DoS attacks and earned participants $5,000. 

The team from industrial cybersecurity firm Claroty was declared the winner, earning $98,500 for its exploits and an additional $25,000 representing the winner’s bonus. 

The exploits — excluding the winner’s bonus — earned participants nearly $155,000. In comparison, at last year’s ICS Pwn2Own, white hat hackers took home a total of $400,000 for more than two dozen unique exploits. 

Vulnerabilities demonstrated at Pwn2Own are reported to the vendors whose products they impact. 

Related: Details Disclosed for OPC UA Vulnerabilities Exploited at ICS Hacking Competition

Advertisement. Scroll to continue reading.

Related: Tesla Returns as Pwn2Own Hacker Takeover Target

Related: Device Exploits Earn Hackers Nearly $1 Million at Pwn2Own Toronto 2022

Related Content

Vulnerabilities

Google pushes a new Chrome update to patch another zero-day vulnerability demonstrated at a hacking contest.

Malware & Threats

Google ships a security-themed Chrome browser refresh to fix flaws exploited at the CanSecWest Pwn2Own hacking contest.

Vulnerabilities

Firefox browser updates address two zero-day vulnerabilities exploited at the Pwn2Own hacking contest.

Vulnerabilities

Exploits targeting Tesla cars, operating systems, and popular software earned participants over $1.1 million at Pwn2Own Vancouver 2024.

IoT Security

Participants earned a total of $732,500 on the first day of Pwn2Own Vancouver 2024 for hacking a Tesla, operating systems, and other software.

IoT Security

Participants have earned more than $1.3 million for hacking Teslas, EV chargers and infotainment systems at Pwn2Own Automotive.

IoT Security

Over $1 million paid out in the first two days of Pwn2Own Automotive for Tesla, infotainment and EV charger hacks.

IoT Security

On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version