Cloud Security

$4.5 Million Offered in New Cloud Hacking Competition

Wiz has teamed up with Microsoft, Google and AWS and is inviting cloud security researchers to its Zeroday.Cloud competition.

Zeroday.Cloud competition

Cloud security giant Wiz has announced a new hacking competition where participants can earn significant rewards for demonstrating exploits against widely used cloud software.

The competition is named Zeroday.Cloud and it offers participants a total of $4.5 million in bug bounties. Interested security researchers must submit their entry by December 1 and they will demonstrate their exploits live on stage at the Black Hat Europe conference taking place December 10-11 in London. 

Wiz has teamed up with AWS, Google Cloud and Microsoft for Zeroday.Cloud. It’s worth noting that Google has announced plans to acquire Wiz for $32 billion. 

The Zeroday.Cloud hacking competition covers six categories. One of them is AI, with participants being offered maximum prizes ranging between $25,000 and $40,000 for hacking products such as Ollama, vLLM, and Nvidia Container Toolkit.  

In the Kubernetes and cloud native category, prizes range between $10,000 and $80,000 for exploits targeting the Kubernetes API Server, Kubelet Server, Grafana, Prometheus, and Fluent Bit. The highest reward is for Kubernetes API Server exploits.

The containers and virtualization category covers Docker, Containerd, and Linux Kernel, with prizes ranging between $30,000 and $60,000. 

Advertisement. Scroll to continue reading.

In the web server category, participants can earn up to $300,000 for Nginx exploits, $100,000 for Tomcat exploits, and up to $50,000 for Caddy and Envoy vulnerabilities. 

Database hacks can also earn significant rewards — up to $100,000 is being offered for unauthenticated remote code execution exploits targeting Redis, PostgreSQL, and MariaDB. 

Vulnerabilities in DevOps and automation software such as Apache Airflow, Jenkins, and GitLab CE can earn Zeroday.Cloud participants up to $40,000. 

“Submitted exploits should result in total compromise of the target, meaning a full Container/VM Escape for the Virtualization category, and a 0-click Remote Code Execution (RCE) vulnerability for other targets,” explained Nir Ohfeld, head of vulnerability research at Wiz. 

Given the significant prize pool and the standing of its backers, the cloud hacking competition has a high likelihood of success. However, it also appears to be facing some controversy.

Trend Micro, whose Zero Day Initiative (ZDI) has been organizing the Pwn2Own hacking competition for nearly two decades, has accused Wiz of copying some sections of its rules word-for-word. 

Related: $1 Million Offered for WhatsApp Exploit at Pwn2Own Ireland 2025

Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Related: Microsoft Offers $5 Million at Zero Day Quest Hacking Contest

Related Content

Artificial Intelligence

The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million.

Vulnerabilities

Researchers found more than 80 high-impact cloud and AI vulnerabilities during the event, which had a $5 million prize pool.

Cloud Security

Phil Venables, former CISO of Google Cloud and now a venture partner at Ballistic Ventures, has joined Native’s board of directors.

Cloud Security

Google has completed its $32 billion acquisition of the cloud security giant, which will maintain its brand.

Cloud Security

The AWS Security Hub Extended plan aims to reduce security tool sprawl by correlating findings across multiple security domains.

Government

Rewards for exploits are reportedly much smaller than in the contest’s glory days.

Cloud Security

The flaws dubbed LookOut can be exploited for remote code execution and data exfiltration.

Cloud Security

The CNAPP company will use the fresh investment to scale its runtime-first cloud security offering across data, AI and code.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version