Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition

Wiz and the leading CSPs are launching one of the largest hacking competitions ever to secure the open-source software powering the cloud ecosystem

The Wiz Research team is proud to launch zeroday.cloud, a first-of-its-kind cloud hacking competition with a prize pool totaling up to about $4.5 million in bounties, making zeroday.cloud one of the largest cloud hacking events ever held.

Cloud and AI now power critical systems around the world, from hospitals and banks to governments and entire economies. These cloud platforms are built on top of many open-source projects, like database engines and virtualization technologies. As we’ve demonstrated in some of our recent work, a single vulnerability in such projects can affect the entire cloud ecosystem. Despite the critical impact, some of these projects don’t have the backing of a major bug bounty program to incentivize top-tier security researchers. Until now. 

zeroday.cloud is a natural extension of our mission at Wiz Research: uncover emerging threats in cloud infrastructure, share our findings, and help vendors patch vulnerabilities quickly. This is a space that needs greater visibility and collaboration, so we’re inviting the broader security community to join us and accelerate the future of cloud and AI security together.

About zeroday.cloud

zeroday.cloud is where responsible researchers can dissect the software powering the cloud, identify critical zero-days, and help fix them in partnership with vendors.

We’re incredibly grateful to AWS, Microsoft, and Google Cloud for partnering with Wiz Research to make zeroday.cloud possible. Their support shows a shared industry commitment to advancing cloud security for everyone.

The competition will take place at Black Hat Europe in London, December 10 and 11

Researchers can compete across six categories:

  • AI: Ollama, vLLM, NVIDIA Container Toolkit (Container Escape)

  • Kubernetes and Cloud-Native: Kubernetes API Server, Kubelet Server, Grafana, Prometheus, Fluent Bit

  • Containers and Virtualization: Docker, Containerd, Linux Kernel (Ubuntu)

  • Web Servers: nginx, Apache Tomcat, Envoy, Caddy

  • Databases: Redis, PostgreSQL, MariaDB

  • DevOps & Automation: Apache Airflow, Jenkins, GitLab CE

Submitted exploits should result in total compromise of the target, meaning a full Container/VM Escape for the Virtualization category, and a 0-click Remote Code Execution (RCE) vulnerability for other targets.

Contestants may submit exploits for different targets. Submissions will be demonstrated live by the contestant, on stage in London, and judged by Wiz Research together with some of our CSP partners. Winning submissions will win a generous cash prize, as detailed on zeroday.cloud.

Join us

Cloud and AI are reshaping the world. It’s up to us to secure them together.

If you’re ready to test your skills, make a difference, and help shape the future of cloud security, visit zeroday.cloud to register your exploit and learn more. And for any questions that aren’t answered in our Contest Rules or FAQ on zeroday.cloud, please contact us at zerodaycloud@wiz.io.

We’ll see you in London!

Register for the event

계속 읽기

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자