Cyber News / Article / Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition

Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition
Wiz and the leading CSPs are launching one of the largest hacking competitions ever to secure the open-source software powering the cloud ecosystem
The Wiz Research team is proud to launchzeroday.cloud, a first-of-its-kind cloud hacking competition with a prize pool totalingup to about $4.5 million in bounties, making zeroday.cloud one of the largest cloud hacking events ever held.
Cloud and AI now power critical systems around the world, from hospitals and banks to governments and entire economies. These cloud platforms are built on top of many open-source projects, like database engines and virtualization technologies. As we’ve demonstrated in some of ourrecent work, a single vulnerability in such projects can affect the entire cloud ecosystem. Despite the critical impact, some of these projects don’t have the backing of a major bug bounty program to incentivize top-tier security researchers. Until now.
zeroday.cloud is a natural extension of our mission atWiz Research: uncover emerging threats in cloud infrastructure, share our findings, and help vendors patch vulnerabilities quickly. This is a space that needs greater visibility and collaboration, so we’re inviting the broader security community to join us and accelerate the future of cloud and AI security together.
zeroday.cloud is where responsible researchers can dissect the software powering the cloud, identify critical zero-days, and help fix them in partnership with vendors.
We’re incredibly grateful to AWS, Microsoft, and Google Cloud for partnering with Wiz Research to make zeroday.cloud possible. Their support shows a shared industry commitment to advancing cloud security for everyone.
The competition will take placeat Black Hat Europein London, December 10 and 11.
Researchers can compete across six categories:
AI: Ollama, vLLM, NVIDIA Container Toolkit (Container Escape)
Kubernetes and Cloud-Native: Kubernetes API Server, Kubelet Server, Grafana, Prometheus, Fluent Bit
Containers and Virtualization: Docker, Containerd, Linux Kernel (Ubuntu)
Web Servers: nginx, Apache Tomcat, Envoy, Caddy
Databases: Redis, PostgreSQL, MariaDB
DevOps & Automation:Apache Airflow, Jenkins, GitLab CE
Submitted exploits should result intotal compromiseof the target, meaning a full Container/VM Escape for the Virtualization category, and a 0-click Remote Code Execution (RCE) vulnerability for other targets.
Contestants may submit exploits for different targets. Submissions will be demonstrated live by the contestant, on stage in London, and judged by Wiz Research together with some of our CSP partners. Winning submissions will win a generous cash prize, as detailed onzeroday.cloud.
Cloud and AI are reshaping the world. It’s up to us to secure them together.
If you’re ready to test your skills, make a difference, and help shape the future of cloud security, visitzeroday.cloudto register your exploit and learn more. And for any questions that aren’t answered in our Contest Rules or FAQ onzeroday.cloud, please contact us [email protected].
We’ll see you in London!
See how Wiz protects your cloud from code to runtime
Bring network context into the Security Graph to enrich cloud visibility and strengthen posture
A closer look at LameHug, the Amazon Q Developer Extension compromise, s1ngularity, and PromptLock.
Unified cloud security without compromise, delivering commercial features to sensitive government systems
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
1 day ago
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
4 days ago
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms
22 days ago
You might Also like

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

