The Zeroday Cloud hacking event exposed how fragile modern cloud infrastructure can be when critical components remain unchecked. During the live competition, security researchers earned $320,000 after successfully demonstrating 11 previously unknown zero-day vulnerabilities affecting widely used cloud and open-source technologies.
What the Zeroday Cloud hacking event focuses on
Zeroday Cloud is a live security competition designed to pressure-test the technologies that underpin cloud computing. Unlike traditional hacking contests, the event targets real-world infrastructure components used by enterprises and cloud providers every day.
The initiative was organized by Wiz Research and supported by major cloud vendors. Its goal is simple: incentivize researchers to responsibly disclose high-impact vulnerabilities before attackers discover them.
Zero-days demonstrated during the event
Over two days, participants successfully exploited 11 critical vulnerabilities, most of them allowing remote code execution or container escapes. These flaws affected technologies that form the backbone of cloud environments.
Targets included:
- Popular database systems such as Redis, PostgreSQL, and MariaDB
- The Grafana observability platform
- The Linux kernel, where a container escape demonstrated a breakdown in tenant isolation
The first day of the event accounted for most of the payouts, with researchers earning $200,000. The remaining exploits were demonstrated on day two, pushing the total reward pool to $320,000.
Why these findings matter
Cloud platforms rely heavily on shared infrastructure and open-source software. A single critical flaw in these layers can affect thousands of organizations at once.
The Linux kernel exploit demonstrated during the event is a strong example. Container isolation is a core cloud security promise. When that boundary fails, attackers can move laterally across systems that were assumed to be securely separated.
These issues are not theoretical. If exploited outside a controlled environment, they could enable data theft, service disruption, or large-scale compromise.
Competition highlights
One research team stood out by chaining multiple successful exploits across different database platforms. Other teams focused on lower-level components, including kernel behavior in containerized environments.
The event also included AI-related infrastructure targets. While no confirmed zero-days were demonstrated in those components, their inclusion signals a growing concern around AI workloads running in shared cloud environments.
Conclusion
The Zeroday Cloud hacking event made one thing clear. Cloud security depends on constant scrutiny of the technologies everyone assumes are safe. By paying $320,000 for 11 zero-day vulnerabilities, the event highlighted both the scale of hidden risk and the value of proactive security research before attackers find the same flaws.


0 responses to “Zeroday Cloud hacking event pays $320,000 for 11 zero-days”