• News/
  • https://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-event-awards-320-0000-for-11-zero-days/

Zeroday Cloud hacking event awards $320,0000 for 11 zero days

BleepingComputer
·
Bill Toulas
·
Published Dec 17, 2025
·
Updated

The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure. The first hacking event focused on cloud systems, the competition is hosted by Wiz Research in partnership with Amazon Web Services, Microsoft, and Google Cloud. The researchers were successful in 85% of the hacking attempts across 13 hacking sessions, demonstrating 11 zero-day vulnerabilities. A blog post summarizing the event notes $200,000 was awarded during the first day for successful exploitation of issues in Redis, PostgreSQL, Grafana, and the Linux kernel. During the second day, researchers earned another $120,000, showing exploits in Redis, PostgreSQL, and MariaDB, the most popular databases used by cloud systems to store critical information (e.g., credentials, secrets, sensitive user information). The Linux kernel was compromised through a container escape flaw, which allowed attackers to break isolation between cloud tenants, undermining a core cloud security guarantee. Researchers at cybersecurity companies Zellic and DEVCORE were awarded $40,000 for their success. Artificial Intelligence was also a topic, with hacking attempts targeting the vLLM and Ollama models, which could have exposed private AI models, datasets, and prompts, but both attempts failed due to time exhaustion. The end of the first Zeroday Cloud competition found Team Xint Code crowned champion for successfu...

Read full article

Affected Software

5 affected components
Redis redis
PostgreSQL postgresql
Grafana Grafana
Linux Kernel
MariaDB MariaDB
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main focus of the Zeroday Cloud hacking event?

The main focus of the Zeroday Cloud hacking event was to discover and demonstrate critical remote code execution vulnerabilities in cloud infrastructure components.

2

How much prize money was awarded at the hacking event?

A total of $320,000 was awarded to researchers for demonstrating 11 zero-day vulnerabilities.

3

Which software products were found to have vulnerabilities during the event?

The affected software included Redis, PostgreSQL, Grafana, Linux Kernel, and MariaDB.

4

What type of vulnerabilities were highlighted at the Zeroday Cloud event?

The vulnerabilities highlighted were critical remote code execution vulnerabilities.

5

Where did the Zeroday Cloud hacking competition take place?

The Zeroday Cloud hacking competition took place in London.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203