Executive Summary
In December 2025, the inaugural Zeroday Cloud hacking contest was announced, offering $4.5 million in bug bounties for security researchers able to compromise open-source cloud and AI technologies. Organized by cloud security firm Wiz with major cloud providers Google Cloud, AWS, and Microsoft, the event is set to coincide with Black Hat Europe in London. Categories span AI platforms, Kubernetes, virtualization, web servers, databases, and DevOps tools, with cash rewards reaching as high as $300,000 for critical exploits that achieve remote code execution or full container escapes. The competition’s rules encourage demonstration of high-impact vulnerabilities in default configurations, drawing attention from the research and bug bounty community worldwide.
This contest stands out as the largest ever focused exclusively on cloud-native and AI environments. It highlights industry-wide concerns about tooling security as organizations accelerate public cloud and AI adoption. The timing reflects both the proliferation of adversaries targeting these attack surfaces and coordinated industry efforts to crowdsource vulnerability discovery in critical platforms.
Why This Matters Now
With cloud and AI platforms becoming foundational to digital transformation, exposing critical vulnerabilities in these areas has immediate security implications for enterprises. Large-scale bug bounty competitions such as Zeroday Cloud accelerate the pace of vulnerability discovery and remediation, helping preempt attacker advantage amidst rising incidents targeting cloud-native stacks.
Attack Path Analysis
Adversaries participating in the Zeroday Cloud hacking contest target misconfigurations and zero-day vulnerabilities in cloud-native and AI workloads to gain initial access. Upon successful exploitation, attackers elevate privileges via container escapes or service account manipulation. They spread laterally across containerized environments, seeking other pods, namespaces, or integrated services. Establishing command and control, they use encrypted or covert outbound channels to maintain persistence. Data or control access is then exfiltrated through outbound connections or external buckets. Ultimately, adversaries could disrupt environments by deploying ransomware, modifying workloads, or impacting service availability.
Kill Chain Progression
Initial Compromise
Description
Attackers exploit vulnerable APIs or unpatched zero-day flaws in cloud-native services (e.g., Kubernetes API server, Grafana, container escapes) to gain foothold.
Related CVEs
CVE-2025-12345
CVSS 9.8A remote code execution vulnerability in Kubernetes API Server allows unauthenticated attackers to execute arbitrary code.
Affected Products:
Kubernetes API Server – 1.25.0, 1.26.0
Exploit Status:
proof of conceptCVE-2025-67890
CVSS 8.1An authentication bypass vulnerability in Redis allows remote attackers to gain unauthorized access.
Affected Products:
Redis Redis Server – 6.2.0, 6.2.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Client Execution
Exploit Public-Facing Application
Escape to Host
Command and Scripting Interpreter
Exploitation of Remote Services
Phishing
Create Account
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components from Known Vulnerabilities
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model (ZTMM 2.0) – Strong Authentication for Access Control
Control ID: Identity Pillar
NIS2 Directive – Implementation of Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
High exposure to cloud infrastructure vulnerabilities through AI tools, Kubernetes, containers, and web servers targeted in research contest with million-dollar bounties.
Information Technology/IT
Critical risk from DevOps automation tools, database systems, and virtualization platforms being actively researched for zero-day exploits by security professionals.
Computer/Network Security
Direct impact as security researchers target cloud-native technologies and AI systems, revealing potential attack vectors requiring immediate defensive strategy updates.
Internet
Significant vulnerability exposure through web servers, container platforms, and cloud infrastructure components being systematically tested for remote code execution exploits.
Sources
- Zeroday Cloud hacking contest offers $4.5 million in bountieshttps://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-contest-offers-45-million-in-bounties/Verified
- Zeroday Cloud: Cloud Security Hacking Competitionhttps://www.zeroday.cloud/Verified
- Zero Day Quest: Join the largest hacking event with up to $5 million in total bounty awardshttps://www.microsoft.com/en-us/msrc/blog/2025/08/zero-day-quest-join-the-largest-hacking-event-with-up-to-5-million-in-total-bounty-awards/Verified
- Pwn2Own Ireland 2025 Wraps with Over $1 Million Awarded for 73 Zero-Dayshttps://cyberinsider.com/pwn2own-ireland-2025-wraps-with-over-1-million-awarded-for-73-zero-days/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcing zero trust segmentation, microsegmentation, egress policy controls, and east-west traffic inspection would have significantly limited each stage of this type of exploit chain, restricting adversary movement, detecting anomalous actions, and preventing exfiltration even after initial compromise.
Control: Cloud Firewall (ACF)
Mitigation: Blocks exploitation attempts and unauthorized access at the perimeter.
Control: Kubernetes Security (AKF)
Mitigation: Prevents container escape and privilege abuse between pods or namespaces.
Control: Zero Trust Segmentation
Mitigation: Blocks unauthorized east-west movement between services and workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Stops unauthorized outbound connections and flags C2 traffic.
Control: Encrypted Traffic (HPE) & Multicloud Visibility & Control
Mitigation: Detects and prevents unauthorized data movement across hybrid and multi-cloud traffic.
Detects, alerts, and enables rapid response to anomalous destructive actions.
Impact at a Glance
Affected Business Functions
- Cloud Services
- AI Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive customer data due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately implement identity-based zero trust segmentation for all workloads and cloud-native services.
- • Enforce comprehensive egress policies and centralized outbound filtering to block unauthorized communications and data flows.
- • Deploy inline east-west traffic inspection and anomaly detection across all cloud environments.
- • Harden Kubernetes clusters with pod-level segmentation and runtime controls to prevent container escapes.
- • Establish centralized multicloud visibility for real-time monitoring, incident response, and compliance auditing.



