HomeSecurityZeroday Cloud: Hacking competition with bug bounties of $4.5 million.

Zeroday Cloud: Hacking contest with bug bounties of $4.5 million.

Cloud and AI security are taking center stage in an ambitious new hacking competition. Zeroday Cloud, a new organization that aims to unite researchers, companies, and cloud providers in an impressive battle of vulnerabilities, with a total bug bounties of $4.5 million.

Zeroday Cloud hacking bug bounty contest

The competition will be held on December 10 and 11 as part of Black Hat Europe in London, with the organization being owned by Wiz Research, the research arm of the well-known cloud security company Wiz. The company also collaborates with giants Google Cloud, AWS and Microsoft.

Six categories, dozens of goals – from AI to Kubernetes

Zeroday Cloud is not just another traditional bug bounty competition. Participants will compete in six different categories that reflect the core of modern computing: artificial intelligence, cloud-native applications, containers & virtualization, web servers, databases , and DevOps & Automation.

See also: Critical GoAnywhere vulnerability used for ransomware attacks

The cash prizes vary from $10,000 to $300,000 depending on the severity and difficulty of the exploit.

Some of the most impressive bounties include:

  • AI – Ollama ($25k), Vllm ($25k), Nvidia Container Toolkit ($40k)
  • Kubernetes and Cloud-Native – Kubernetes API Server ($80k), Kubelet Server ($40k), Grafana ($10k auth RCE, $40k pre-auth RCE), Prometheus ($40k), Fluent Bit ($10k)
  • Containers and Virtualization – Docker ($40 user-provided image, $60k arbitrary image), Containerd ($40 user-provided image, $60k arbitrary image), Linux Kernel ($30k container escape on Ubuntu)
  • Web Servers – nginx ($300k), Apache Tomcat ($100k), Envoy ($50k), Caddy ($50k)
  • Databases – Redis ($25k auth RCE, $100k pre-auth RCE), PostgreSQL ($20k auth RCE, $100k pre-auth RCE), MariaDB ($20k auth RCE, $100k pre-auth RCE)
  • DevOps & Automation – Apache Airflow ($40k), Jenkins ($40k), GitLab CE ($40k)

Participants will be asked to demonstrate a complete breach of the target, i.e. a functional exploit that leads to either a container/VM escape, or a 0-click Remote Code Execution (RCE).

From HackerOne to Black Hat: How to participate

The registration process is also carried out through the platform HackerOne, with a deadline of November 20.Researchers who complete the necessary identification procedures and Tax Forms can submit one entry per goal, selecting as many goals as they wish in total.

Zeroday Cloud: Hacking contest with bug bounties of $4.5 million.

Selected exploits will be demonstrated live in London, either by individual researchers or by teams of up to five people. Demonstrations will be judged on technical quality, innovation, and completeness of the exploit.

However, there is also a geopolitical filter: entries from countries under embargo or sanctions (such as Russia, China, Iran, Syria, North Korea, Cuba, Libya, Lebanon and the Crimea and Donetsk regions) are excluded from the process.

See also: Warning! Vulnerability in Zabbix Agent and Agent 2 for Windows

Technical challenge with real cloud environments

The organizers emphasize that each target will be offered within a fully functional Docker container environment with default settings to reflect realistic attack scenarios. At the same time, technical resources, instructions and execution conditions for each category are provided.

In this way, Zeroday Cloud aspires to function not just as a competition, but also as a laboratory for modern cybersecurity research, focusing on the practical handling of vulnerabilities that are already widely used in the cloud ecosystem.

Pwn2Own vs Zeroday Cloud: A conflict over "paternity"

Although Wiz's initiative has excited much of the research community, there has been some backlash. Trend Micro, the organizer of the well-known competitions Pwn2Own, accused Wiz of "copying verbatim" much of the rules of Pwn2Own Ireland.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Juan Pablo Castro, Director of Cybersecurity Strategy at Trend Micro, said that a comparison of the rules (from Google's Gemini tool) "proved that it is almost identical text."

Wiz responded modestly, admitting that she was inspired by the Pwn2Own framework, which she considers “mature and reliable.” Despite the controversy, several experts believe that the existence of many such competitions strengthens security research overall and promotes responsible vulnerability disclosure.

Zeroday Cloud: Hacking contest with bug bounties of $4.5 million.

Beyond bounties: An investment in the security of the future

Wiz argues that Zeroday Cloud is not only about monetary reward, but also about creating a community around cloud security and AI.

With the rapid spread of Generative AI models, containers and CI/CD pipelines, the boundaries between cloud, applications and data are becoming increasingly fluid. Vulnerabilities discovered today in tools Kubernetes, Docker or GitLab can become the basis for mass attacks on production environments tomorrow.

See also: PoC exploit and details of Chrome RCE vulnerability released

Competitions of this kind act as a safety net, incentivizing researchers to be the first to identify vulnerabilities — before malicious hackers do.

A new chapter in cloud cybersecurity

Zeroday Cloud marks a new era in collaboration between major cloud providers and the global research community.

If successful, it could become a model for how technology companies will address zero-day threats, through transparency, rewards, and collaboration.

In an era where every line of code in the cloud can become a gateway for cyberattacks, such initiatives aren't just hacking contests — they're investments in the security of our digital world.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS