Zeroday Cloud hacking event awards $320,0000 for 11 zero days
好的,我现在需要帮用户总结一篇关于Zeroday Cloud黑客竞赛的文章,控制在100字以内。首先,我得仔细阅读文章内容,提取关键信息。 文章提到竞赛在伦敦举行,由Wiz Research主办,亚马逊、微软和谷歌云协办。研究人员展示了11个零日漏洞,成功率达到85%。奖金总额为32万美元,其中第一天20万美元用于Redis、PostgreSQL、Grafana和Linux内核的漏洞,第二天12万美元用于Redis、PostgreSQL和MariaDB的漏洞。Linux内核的一个容器逃逸漏洞导致云租户隔离被破坏。团队Xint Code获得冠军,奖金9万美元。尽管结果积极,但奖金仅占450万美元总奖池的一小部分。 接下来,我需要将这些信息浓缩到100字以内。重点包括竞赛名称、主办方、协办方、展示的漏洞数量、成功率、奖金数额以及关键发现如Linux内核漏洞和冠军团队。 确保语言简洁明了,不使用复杂的结构。可能的结构是:竞赛名称+主办方+协办方+展示漏洞数量+成功率+奖金数额+关键发现+冠军团队。 最后检查字数是否在限制内,并确保所有重要信息都被涵盖。 </think> 伦敦举办的Zeroday Cloud黑客竞赛中,研究人员展示了11个零日漏洞,成功率达85%,赢得32万美元奖金。竞赛聚焦云系统安全,由Wiz Research与亚马逊、微软和谷歌云合作举办。Linux内核容器逃逸漏洞导致云租户隔离失效。团队Xint Code夺冠并获9万美元奖金。 2025-12-17 23:15:16 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Zeroday Cloud hacking event awards $320,0000 for 11 zero days

The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure.

The first hacking event focused on cloud systems, the competition is hosted by Wiz Research in partnership with Amazon Web Services, Microsoft, and Google Cloud.

The researchers were successful in 85% of the hacking attempts across 13 hacking sessions, demonstrating 11 zero-day vulnerabilities.

Wiz

blog post summarizing the event notes $200,000 was awarded during the first day for successful exploitation of issues in Redis, PostgreSQL, Grafana, and the Linux kernel.

During the second day, researchers earned another $120,000, showing exploits in Redis, PostgreSQL, and MariaDB, the most popular databases used by cloud systems to store critical information (e.g., credentials, secrets, sensitive user information).

Overview of Zeroday Cloud 2025
Overview of Zeroday Cloud 2025
Source: Wiz

The Linux kernel was compromised through a container escape flaw, which allowed attackers to break isolation between cloud tenants, undermining a core cloud security guarantee.

Researchers at cybersecurity companies Zellic and DEVCORE were awarded $40,000 for their success.

Team CCC receiving the highest bounty payment in the competition
Team CCC receiving the highest single bounty payment in the competition
Source: Wiz

Artificial Intelligence was also a topic, with hacking attempts targeting the vLLM and Ollama models, which could have exposed private AI models, datasets, and prompts, but both attempts failed due to time exhaustion.

The end of the first Zeroday Cloud competition found Team Xint Code crowned champion for successfully exploiting Redis, MariaDB, and PostgreSQL. For its three exploits, Team Xint Code received $90,000.

Team Xint Code winning the historic first event
Team Xint Code winning the first Zeroday Cloud event
Source: Wiz

Despite the positive outcome, the amount awarded is only a small fraction of the total prize pool of $4.5 million available for researchers showcasing exploits for various targets.

The eligible categories and products that didn't see any exploits in the competition include AI (Ollama, vLLM, Nvidia Container Toolkit), Kubernetes, Docker, web servers (ngnix, Apache Tomcat, Envoy, Caddy), Apache Airflow, Jenkins, and GitLab CE.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-event-awards-320-0000-for-11-zero-days/
如有侵权请联系:admin#unsafe.sh