22/06/2026
Finding a 0-day is rarely a matter of luck. It requires understanding complex systems well enough to spot the assumptions, edge cases, and design gaps that escape routine scrutiny. That's precisely what stood out at TyphoonPWN 2026, where researchers uncovered previously unknown vulnerabilities across a diverse set of targets.
Last month, during TyphoonCon 2026, 34 researchers participated in TyphoonPWN, with 13 of them joining remotely from around the world. Over the course of the competition, we saw successful exploitation across a diverse set of targets, including Windows, Linux, LG webOS, and HP printers.
Every submission underwent live technical verification by the SSD team before being accepted. No theoretical reports. No "works on my machine." Exploit chains had to reliably reproduce against the designated targets under competition conditions before payouts were approved.
By the end of the event, SSD had awarded $300,000 USD onsite.
We've seen researchers take techniques developed for a competition environment and later apply the same methodology to uncover vulnerabilities in enterprise software, embedded devices, operating systems, and products that affect millions of users. The line between "competition research" and "real-world research" is often much thinner than people think.
At SSD, we see the same pattern every day through our disclosure program.
Many of the most impactful vulnerabilities don't fit neatly into existing bug bounty ecosystems. Some vendors don't operate public programs. Others have restrictive scopes, low rewards, or lengthy response cycles. Yet the technical quality of the research remains high.
Our goal is simple: provide researchers with another path.
If you've found a novel exploitation technique, an interesting RCE chain, a sandbox escape, an embedded device vulnerability, or a bug that you believe has meaningful security impact, we'd like to review it. Our team handles technical validation, vendor coordination, and disclosure management, while researchers retain the option to stay anonymous throughout the process.
Submit your research at
Found an interesting vulnerability? Submit your vulnerability here for review and get the chance to get the biggest payouts out there.