Cloud and AI security are taking center stage in an ambitious new hacking competition. Zeroday Cloud, a new organization that aims to unite researchers, companies, and cloud providers in an impressive battle of vulnerabilities, with a total bug bounties of $4.5 million.

The competition will be held on December 10 and 11 as part of Black Hat Europe in London, with the organization being owned by Wiz Research, the research arm of the well-known cloud security company Wiz. The company also collaborates with giants Google Cloud, AWS and Microsoft.
Six categories, dozens of goals – from AI to Kubernetes
Zeroday Cloud is not just another traditional bug bounty competition. Participants will compete in six different categories that reflect the core of modern computing: artificial intelligence, cloud-native applications, containers & virtualization, web servers, databases , and DevOps & Automation.
See also: Critical GoAnywhere vulnerability used for ransomware attacks
The cash prizes vary from $10,000 to $300,000 depending on the severity and difficulty of the exploit.
Some of the most impressive bounties include:
- AI – Ollama ($25k), Vllm ($25k), Nvidia Container Toolkit ($40k)
- Kubernetes and Cloud-Native – Kubernetes API Server ($80k), Kubelet Server ($40k), Grafana ($10k auth RCE, $40k pre-auth RCE), Prometheus ($40k), Fluent Bit ($10k)
- Containers and Virtualization – Docker ($40 user-provided image, $60k arbitrary image), Containerd ($40 user-provided image, $60k arbitrary image), Linux Kernel ($30k container escape on Ubuntu)
- Web Servers – nginx ($300k), Apache Tomcat ($100k), Envoy ($50k), Caddy ($50k)
- Databases – Redis ($25k auth RCE, $100k pre-auth RCE), PostgreSQL ($20k auth RCE, $100k pre-auth RCE), MariaDB ($20k auth RCE, $100k pre-auth RCE)
- DevOps & Automation – Apache Airflow ($40k), Jenkins ($40k), GitLab CE ($40k)
Participants will be asked to demonstrate a complete breach of the target, i.e. a functional exploit that leads to either a container/VM escape, or a 0-click Remote Code Execution (RCE).
From HackerOne to Black Hat: How to participate
The registration process is also carried out through the platform HackerOne, with a deadline of November 20.Researchers who complete the necessary identification procedures and Tax Forms can submit one entry per goal, selecting as many goals as they wish in total.

Selected exploits will be demonstrated live in London, either by individual researchers or by teams of up to five people. Demonstrations will be judged on technical quality, innovation, and completeness of the exploit.
However, there is also a geopolitical filter: entries from countries under embargo or sanctions (such as Russia, China, Iran, Syria, North Korea, Cuba, Libya, Lebanon and the Crimea and Donetsk regions) are excluded from the process.
See also: Warning! Vulnerability in Zabbix Agent and Agent 2 for Windows
Technical challenge with real cloud environments
The organizers emphasize that each target will be offered within a fully functional Docker container environment with default settings to reflect realistic attack scenarios. At the same time, technical resources, instructions and execution conditions for each category are provided.
In this way, Zeroday Cloud aspires to function not just as a competition, but also as a laboratory for modern cybersecurity research, focusing on the practical handling of vulnerabilities that are already widely used in the cloud ecosystem.
Pwn2Own vs Zeroday Cloud: A conflict over "paternity"
Although Wiz's initiative has excited much of the research community, there has been some backlash. Trend Micro, the organizer of the well-known competitions Pwn2Own, accused Wiz of "copying verbatim" much of the rules of Pwn2Own Ireland.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Juan Pablo Castro, Director of Cybersecurity Strategy at Trend Micro, said that a comparison of the rules (from Google's Gemini tool) "proved that it is almost identical text."
Wiz responded modestly, admitting that she was inspired by the Pwn2Own framework, which she considers “mature and reliable.” Despite the controversy, several experts believe that the existence of many such competitions strengthens security research overall and promotes responsible vulnerability disclosure.

Beyond bounties: An investment in the security of the future
Wiz argues that Zeroday Cloud is not only about monetary reward, but also about creating a community around cloud security and AI.
With the rapid spread of Generative AI models, containers and CI/CD pipelines, the boundaries between cloud, applications and data are becoming increasingly fluid. Vulnerabilities discovered today in tools Kubernetes, Docker or GitLab can become the basis for mass attacks on production environments tomorrow.
See also: PoC exploit and details of Chrome RCE vulnerability released
Competitions of this kind act as a safety net, incentivizing researchers to be the first to identify vulnerabilities — before malicious hackers do.
A new chapter in cloud cybersecurity
Zeroday Cloud marks a new era in collaboration between major cloud providers and the global research community.
If successful, it could become a model for how technology companies will address zero-day threats, through transparency, rewards, and collaboration.
In an era where every line of code in the cloud can become a gateway for cyberattacks, such initiatives aren't just hacking contests — they're investments in the security of our digital world.
Source: www.bleepingcomputer.com
