Article Details
Scrape Timestamp (UTC): 2025-10-06 17:15:24.952
Original Article Text
Click to Toggle View
Zeroday Cloud hacking contest offers $4.5 million in bounties. A new hacking competition called Zeroday Cloud, focused on open-source cloud and AI tools, announced a total prize pool of $4.5 million in bug bounties for researchers that submit exploits for various targets. The contest is launched by the research arm of cloud security company Wiz in partnership with Google Cloud, AWS, and Microsoft, and is scheduled for December 10 and 11 at the Black Hat Europe conference in London, UK. Zeroday Cloud has six separate categories researchers can participate in, with bug bounties between $10,000 and $300,000: The rules of the competition say that submitted exploits should result in complete compromise of the target. Wiz explains that this means "a full Container/VM Escape for the Virtualization category, and a 0-click Remote Code Execution (RCE) vulnerability for other targets." The organizers also provide the conditions for each target, as well as the instructions and technical resources (Docker container with target on default configuration) security researchers can use to test their exploits. Researchers who register through the HackerOne platform and complete their ID verification and Tax Forms by November 20, are free to submit exploits for as many targets as they like, but they are limited to only one entry per target. Submitters of approved exploits will be invited to demonstrate them live during the event, either alone or in a team of up to five members. People residing in embargoed or sanctioned countries such as Russia, China, Iran, North Korea, Cuba, Sudan, Syria, Libya, Lebanon, and also the regions of Crimea and Donetsk, are restricted from participating in the Zeroday Cloud contest. The complete rules for the zeroday.cloud hacking competition are available here. The announcement for the event, however, did not resonate well with the organizers of the Pwn2Own hacking competitions that have been going with great success for several years. In a public post, Trend Micro called out Wiz for copying the rules for Pwn2Own Ireland. Juan Pablo Castro, Director of Cybersecurity Strategy & Technology at Trend Micro, said that Gemini's output when comparing the rules for the two events were a "word-for-word" copy. Wiz responded with a defusing statement, admitting that the Pwn2Own rulebook was "a trusted, mature framework by which we were inspired." The Security Validation Event of the Year: The Picus BAS Summit Join the Breach and Attack Simulation Summit and experience the future of security validation. Hear from top experts and see how AI-powered BAS is transforming breach and attack simulation. Don't miss the event that will shape the future of your security strategy
Daily Brief Summary
Zeroday Cloud, a new hacking contest, offers $4.5 million for exploits targeting open-source cloud and AI tools, hosted by Wiz with Google Cloud, AWS, and Microsoft.
The competition will take place at the Black Hat Europe conference in London on December 10 and 11, featuring six categories with bounties ranging from $10,000 to $300,000.
Researchers must achieve full target compromise, such as Container/VM Escape or 0-click RCE, with submissions to be demonstrated live at the event.
Participants must register via HackerOne, complete ID verification, and submit tax forms by November 20 to compete.
Entrants from embargoed or sanctioned regions, including Russia and China, are barred from participation.
Trend Micro's Pwn2Own organizers accused Wiz of copying their contest rules, but Wiz acknowledged using Pwn2Own's framework as inspiration.
This contest aims to advance cloud security by incentivizing researchers to uncover critical vulnerabilities in widely-used technologies.