The Zeroday Cloud hacking competition held in London has put the spotlight on one of the most critical issues in modern computing: the security of cloud infrastructure . Cybersecurity researchers from around the world were rewarded with a total of $320,000 after they managed to prove the existence of serious RCE vulnerabilities in technologies that form the core of the cloud ecosystem.

A competition with the stamp of the big players
The event, organized by Wiz Research, in collaboration with the three cloud giants: Amazon Web Services (AWS), Microsoft and Google Cloud, is the first hacking event to focus exclusively on cloud systems, marking a new era for bug bounty and zero-day contests, where the focus shifts from traditional applications to the infrastructure that runs the internet.
See also: Warning! Critical zero-day vulnerability in Cisco AsyncOS
Impressive success rates and zero-day findings
The results of the competition were impressive: in 13 hacking sessions, the researchers achieved an 85% success rate, revealing a total of 11 zero-day vulnerabilities. These findings highlight how complex and fragile modern cloud environments can be, even when based on mature and widely used technologies.
Day One: Databases and Linux in Focus
According to the official post summarizing the event, $200,000 was awarded on the first day alone. The researchers managed to exploit vulnerabilities in Redis, PostgreSQL, and Grafana, as well as in the Linux kernel. The Linux kernel exploit was of particular concern, as it relied on a container escape bug, allowing the isolation between different cloud tenants – one of the key security guarantees of the cloud model – to be violated.

The second day and critical databases
On the second day of the competition, an additional $120,000 was awarded, thanks to successful exploits in Redis, PostgreSQL, and MariaDB. These are some of the most widely used cloud databases, which often store sensitive data such as user credentials, secrets, and personal information . Their successful exploitation highlights the increased risk organizations face if such vulnerabilities go undetected.
See also: CISA: ASUS Live Update Vulnerability in KEV Catalog
Teams, prizes and artificial intelligence
Cybersecurity firms Zellic and DEVCORE each won $40,000 for their successful exploits, while Team Xint Code emerged as the competition champion. With three successful zero-day exploits in Redis, MariaDB, and PostgreSQL, the team won a total of $90,000.
Notably, the program also included Artificial Intelligence. Hacking attempts targeted the vLLM and Ollama, with potentially serious consequences, such as the exposure of private models, datasets, and AI prompts. However, both attempts failed due to lack of time.

What Zeroday Cloud Means for the Future of Security
While $320,000 is a significant amount, it is only a small portion of the total $4.5 million prize pool that has been pledged for future exploits. It is also worth noting that several categories were not cracked at all, including Kubernetes, Docker, web servers (Nginx, Apache Tomcat, Envoy, Caddy), and CI/CD tools like Jenkins and GitLab CE.
See also: JumpCloud Remote Assist: Vulnerability allows privilege escalation
Zeroday Cloud demonstrated that, no matter how mature cloud technologies become, their continued testing by independent researchers remains vital. In a world where the cloud hosts critical business and personal information, such events act as a necessary “stress test” for the digital security of tomorrow.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
