Zeroday.Cloud Hacking Competition Announced with $4.5 Million in Prizes
Summary
Hide ▲
Show ▼
The Zeroday.Cloud hacking competition, announced by Wiz, offered $4.5 million in bug bounties for exploits in widely used cloud software. The event, scheduled for December 10-11 at the Black Hat Europe conference in London, covered six categories: AI, Kubernetes, containers, web servers, databases, and DevOps tools. Participants had to submit entries by December 1 and demonstrate exploits live at the event. The competition faced controversy due to alleged rule copying from Trend Micro's Pwn2Own hacking competition. Wiz partnered with AWS, Google Cloud, and Microsoft for the event. Google is also in the process of acquiring Wiz for $32 billion. Specific bounties ranged from $10,000 to $300,000. During the event, researchers were awarded $320,000 for demonstrating 11 zero-day vulnerabilities across 13 hacking sessions. Exploits were successful in Redis, PostgreSQL, Grafana, the Linux kernel, and MariaDB. A container escape flaw in the Linux kernel allowed attackers to break isolation between cloud tenants. Team Xint Code was crowned champion, receiving $90,000 for their exploits.
Timeline
-
18.12.2025 01:09 1 articles · 23h ago
Zeroday.Cloud Hacking Competition Awards $320,000 for 11 Zero-Day Vulnerabilities
The Zeroday Cloud hacking competition awarded $320,000 for demonstrating 11 zero-day vulnerabilities. Researchers were successful in 85% of the hacking attempts across 13 hacking sessions. Exploits were found in Redis, PostgreSQL, Grafana, the Linux kernel, and MariaDB. A container escape flaw in the Linux kernel allowed attackers to break isolation between cloud tenants. Team Xint Code was crowned champion, receiving $90,000 for their exploits. Hacking attempts targeting AI models vLLM and Ollama failed due to time exhaustion. Eligible categories and products without exploits include AI, Kubernetes, Docker, web servers, Apache Airflow, Jenkins, and GitLab CE.
Show sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
06.10.2025 12:44 3 articles · 2mo ago
Zeroday.Cloud Hacking Competition Announced
The Zeroday.Cloud hacking competition, announced by Wiz, offers $4.5 million in bug bounties for exploits in widely used cloud software. The event, scheduled for December 10-11 at the Black Hat Europe conference in London, covers six categories: AI, Kubernetes, containers, web servers, databases, and DevOps tools. Specific bounties range from $10,000 to $300,000, with detailed conditions and resources provided for each target. Participants must register through the HackerOne platform and complete ID verification and Tax Forms by November 20. They are limited to one entry per target but can submit exploits for multiple targets. Approved exploit submitters will be invited to demonstrate their exploits live at the event, either alone or in teams of up to five members. Participants from embargoed or sanctioned countries are restricted from participating. The competition has faced controversy due to alleged rule copying from Trend Micro's Pwn2Own hacking competition.
Show sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
Information Snippets
-
Zeroday.Cloud is a new hacking competition with a total prize pool of $4.5 million.
First reported: 06.10.2025 12:442 sources, 3 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
The competition is organized by Wiz in partnership with AWS, Google Cloud, and Microsoft.
First reported: 06.10.2025 12:442 sources, 3 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Participants must submit entries by December 1 and demonstrate exploits live at the Black Hat Europe conference in London on December 10-11.
First reported: 06.10.2025 12:442 sources, 3 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
The competition covers six categories: AI, Kubernetes, containers, web servers, databases, and DevOps tools.
First reported: 06.10.2025 12:442 sources, 3 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Google is acquiring Wiz for $32 billion.
First reported: 06.10.2025 12:442 sources, 2 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
The competition has faced controversy due to alleged rule copying from Trend Micro's Zero Day Initiative (ZDI).
First reported: 06.10.2025 12:442 sources, 2 articlesShow sources
- $4.5 Million Offered in New Cloud Hacking Competition — www.securityweek.com — 06.10.2025 12:44
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
-
The Zeroday.Cloud competition includes specific bounties for various targets, ranging from $10,000 to $300,000.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Participants must register through the HackerOne platform and complete ID verification and Tax Forms by November 20.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Participants are limited to one entry per target but can submit exploits for multiple targets.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Approved exploit submitters will be invited to demonstrate their exploits live at the event, either alone or in teams of up to five members.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Participants from embargoed or sanctioned countries, including Russia, China, Iran, North Korea, Cuba, Sudan, Syria, Libya, Lebanon, and the regions of Crimea and Donetsk, are restricted from participating.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
The competition's rules have been criticized by Trend Micro for allegedly copying the rules from the Pwn2Own hacking competition.
First reported: 06.10.2025 20:121 source, 2 articlesShow sources
- Zeroday Cloud hacking contest offers $4.5 million in bounties — www.bleepingcomputer.com — 06.10.2025 20:12
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
The Zeroday Cloud hacking competition awarded $320,000 for demonstrating 11 zero-day vulnerabilities.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Researchers were successful in 85% of the hacking attempts across 13 hacking sessions.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
$200,000 was awarded on the first day for exploits in Redis, PostgreSQL, Grafana, and the Linux kernel.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
$120,000 was awarded on the second day for exploits in Redis, PostgreSQL, and MariaDB.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
A container escape flaw in the Linux kernel allowed attackers to break isolation between cloud tenants.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Researchers at Zellic and DEVCORE were awarded $40,000 for their successful exploits.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Hacking attempts targeting AI models vLLM and Ollama failed due to time exhaustion.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Team Xint Code was crowned champion, receiving $90,000 for exploits in Redis, MariaDB, and PostgreSQL.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
-
Eligible categories and products without exploits include AI, Kubernetes, Docker, web servers, Apache Airflow, Jenkins, and GitLab CE.
First reported: 18.12.2025 01:091 source, 1 articleShow sources
- Zeroday Cloud hacking event awards $320,0000 for 11 zero days — www.bleepingcomputer.com — 18.12.2025 01:09
Similar Happenings
73 Zero-day Vulnerabilities Exploited in Pwn2Own Ireland 2025
The Pwn2Own Ireland 2025 hacking competition concluded with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities. The event, held in Cork, Ireland, targeted vulnerabilities in various devices, including smartphones, messaging apps, smart home devices, printers, and more. The Zero Day Initiative (ZDI) operates the event to identify security flaws before threat actors can exploit them. Summoning Team won the competition with 22 Master of Pwn points and $187,500 earned throughout the three-day event. Team ANHTUD secured the second position with $76,750 and 11.5 Master of Pwn points, while Team Synactiv took third place with $90,000 in prizes and 11 Master of Pwn points. The event featured eight categories, including new attack vectors for mobile devices, and offered a $1 million reward for a zero-click WhatsApp exploit. On the first day, researchers demoed 34 unique zero-days and collected $522,500 in cash awards. Team DDOS chained eight zero-day flaws to hack a QNAP Qhora-322 Ethernet wireless router and gain access to a QNAP TS-453E NAS device, earning $100,000. On the second day, researchers exploited 56 unique zero-day vulnerabilities and collected $792,750 in cash awards. Ken Gannon and Dimitrios Valsamaras hacked the Samsung Galaxy S25, earning $50,000 and 5 Master of Pwn points. On the third day, the Samsung Galaxy S25 was hacked by Interrupt Labs via an improper input validation bug, earning 5 Master of Pwn points and $50,000.
Apple increases bug bounty payouts for zero-click RCE vulnerabilities
Apple has expanded and redesigned its bug bounty program, doubling maximum payouts and adding new research categories. The highest reward is now $2 million for zero-click remote code execution (RCE) vulnerabilities, with a bonus system that can exceed $5 million. The program now includes higher payouts for various types of vulnerabilities, including one-click remote attacks, wireless proximity attacks, and unauthorized iCloud access. Apple also plans to distribute secured iPhone 17 devices to civil society organizations and researchers in 2026. The changes aim to incentivize the discovery and reporting of sophisticated security issues, particularly those exploited by mercenary spyware. The program has awarded $35 million to 800 security researchers since its inception in 2020. The expansion includes a $100,000 reward for a complete Gatekeeper bypass and a $1 million reward for broad unauthorized iCloud access. Apple's latest bug bounty announcement is a response to the growth of commercial spyware activity, with the UK’s National Cyber Security Centre (NCSC) estimating that the commercial cyber intrusion sector doubles every 10 years.