Trend Micro ZDI Hosts Hacking Contest for Vulnerabilities in AI-Enabled Devices

In This Article:

Pwn2Own Ireland underscores Trend's commitment to securing AI innovations

DALLAS, Oct. 22, 2024 /PRNewswire/ -- Global cybersecurity leader Trend Micro Incorporated (TYO: 4704; TSE: 4704) has invited hackers from around the globe to the first ever Pwn2Own Ireland competition sponsored by Meta, Synology, and QNAP. As cybercriminals increasingly focus on using consumer devices to gain access to enterprise networks, participants in the contest will uncover exploits and unpatched vulnerabilities in widely used AI-enabled hardware and software. Cash prizes are awarded for disclosing vulnerabilities, enabling vendors to patch them and Trend to protect its customers an average of 70 days ahead of the industry.

Trend Micro logo (PRNewsfoto/Trend Micro Incorporated)
Trend Micro logo (PRNewsfoto/Trend Micro Incorporated)

Kevin Simzer, COO at Trend: "Enterprise security is not limited to enterprise devices. Remote work, bring-your-own-device policies, and sprawling corporate networks mean that consumer devices are critical entry points for both employees and cybercriminals. This makes it more difficult than ever for security leaders to understand and secure their organization's highly complex attack surfaces. Our market-leading bug bounty program offers cash prizes to researchers who can find vulnerabilities before the bad guys do, improving security for both our enterprise customers and the entire industry. Pwn2Own is our key to protecting customers weeks or even months in advance, and we remain committed to hosting these events year-round."

The proliferation of generative AI tools has created new attack paths for threat actors who can abuse these tools to damage infrastructure, infiltrate cloud networks, steal sensitive data and rapidly generate convincing deepfakes to perpetrate fraud. Consumer devices that use local AI tools may also pose risks to enterprise security even when not connected to internal networks due to information being saved locally or elsewhere by AI tools.

The contest, hosted by the Trend Micro Zero Day Initiative™, will reward researchers for disclosing vulnerabilities in seven categories: Mobile Phones, Messenger Apps, The SOHO (Small Office/Home Office) Smashup, Surveillance Systems, Home Automation Hubs, Printers, Smart Speakers, and Network Attached Storage (NAS) Devices. AI will play roles for both attack and defense as Trend implements researchers' discoveries into its threat intelligence database in real time.

Dustin Childs, Head of Threat Awareness at Trend's Zero Day Initiative: "Rapid adoption of AI tools combined with widespread use of consumer devices on enterprise networks is presenting organizations around the world with the challenge of reducing risks that they can't easily oversee. Vulnerabilities in these devices and programs are inevitable, but we're here to find them before threat actors do. In doing so, we reduce risk for all parties—employees, enterprises, partners, and the public—without having to place a greater burden on security staff or budgets."