The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
π¨New CTF Alert: Got trust issues?
Ever wondered what it's like to investigate a real data leak? Now's your chance.
π΅οΈ Your mission:
1) Investigate the compromised machine
2) Figure out how the attacker exfiltrated the data
3) Find the flag
π Start here: cloudsecuritychampionship.com
25.02.2026 14:20
π 0
π 0
π¬ 0
π 0
How good is AI at hacking? We built a benchmark to find out. π§ͺ
Introducing the Offensive AI Benchmark, the framework that tests AI agents on 250+ real-world offensive security challenges.
Check it out β
www.wiz.io/cyber-model-...
12.02.2026 16:16
π 0
π 0
π¬ 0
π 0
π¨ CodeBreach: Wiz Research identified a critical repository-hijacking vulnerability that abused a CodeBuild Regex flaw to compromise core AWS GitHub repos, including a core lib running at the heart of the cloud's most critical interface - the #AWS Console.
15.01.2026 15:05
π 0
π 0
π¬ 1
π 0
π§ Just in time for a new year, a NEW CTF drop!
Think you know Terraform inside out? State of Affairs (challenge 7) might change your mind...
This challenge uncovers an overlooked #Terraform risk and proves IaC tools are part of your supply chain.
www.cloudsecuritychampionship.com/challenge/7
29.12.2025 14:22
π 0
π 0
π¬ 0
π 0
MongoBleed (CVE-2025-14847) exploited in the wild | Wiz Blog
Detect and mitigate CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB. Exploitation has been observed in the wild.
π¨ CRITICAL: MongoBleed (CVE-2025-14847). MongoDB bug leaks in-memory data pre-auth and is exploited in the wild. 42% of clouds vulnerable, ~87K exposed. Atlas patched. Self-hosted: patch now or disable zlib.
www.wiz.io/blog/mongobl...
28.12.2025 12:29
π 1
π 0
π¬ 0
π 0
Day 2 at zeroday.cloud, letβs roll. πΎ
π Didnβt register? No panic.
Walk-ins are welcome for the onsite CTF and all the action happening on the floor.
Flags are hidden. Only the sharp survive.
11.12.2025 12:19
π 1
π 0
π¬ 0
π 0
Day 1 of zeroday.cloud = PURE EXPLOIT ENERGY πΎ
From crowd shots π to researchers buried deep in terminals π»
From first checks being claimed
To live container escapes blowing minds in real time.
See you tomorrow!
11.12.2025 10:01
π 0
π 0
π¬ 0
π 0
Day 1 at zeroday.cloud didnβt come to play π
New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked π€―
100% success rate for day one.
Letβs see what we find tomorrow π
11.12.2025 09:37
π 0
π 0
π¬ 0
π 0
Zeroday.cloud 2025 kicks off TOMORROW! π»
London, brace yourself -
IDEs open. Exploits cooking.
13 zero-days are on the line π£
Don't miss it. Here's the schedule ahead β¬
09.12.2025 14:56
π 0
π 0
π¬ 0
π 0
π¨ React2Shell (CVEβ2025β55182) inβtheβwild exploitation & deepβdive analysis. Critical RCE across React 19, Next.js & all RSC frameworks. Patch now.
www.wiz.io/blog/nextjs-...
08.12.2025 17:24
π 1
π 0
π¬ 0
π 0
π This is not a dream π€ OUR WizZZZ BOOTH IS NOW OPEN.
Behold the ULTIMATE cloud security booth!
Games, demos, swag, napsβ¦ and the coziest cloud security playground in history ποΈ
Come see why CISOs are finally sleeping through the night π΄
02.12.2025 02:00
π 0
π 0
π¬ 0
π 0
The Ultimate Cloud Security Championship | 12 Months Γ 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
Itβs time to bust some malware! π¦
Challenge #6 βMalware Bustersβ is LIVE.
Built by Gili Tikochinski for the reverseβengineering pros - dive into assembly and uncover whatβs hidden inside.
Think you can crack it?
cloudsecuritychampionship.com/challenge/6
27.11.2025 13:49
π 2
π 1
π¬ 0
π 0
New CTF challenge ($20,000 IN PRIZES) π₯
We're running "Operation Cloudfall" - a live CTF during BlackHat & zeroday.cloud on December 10-11.
Get your free pass to the event today: zeroday.cloud/operation-cloudfall
See you in London π¬π§
06.11.2025 17:55
π 0
π 0
π¬ 0
π 0
Path-Man | Wiz
Find exploitable exposures before hackers do
πΉοΈ Meet Path-Man: Your new favorite game. πΎπΎπΎ
Our 1-minute Wiz ASM game has arrived!
π€ Here's the challenge: Navigate the attack surface to reach exploitable risk before the attackers get you.
Think you've got the skills? wiz.io/path-man
05.11.2025 13:15
π 1
π 0
π¬ 0
π 0
π Something spooky's brewing in the cloud...
Introducing a new CTF challenge - "Game of Pods" πΈοΈ
π Written by top Azure researcher & worth 30 points, it's our BIGGEST challenge yet!
Get your skills ready for zeroday.cloud: cloudsecuritychampionship.com
27.10.2025 13:40
π 0
π 0
π¬ 0
π 0
Need a partner to finish that exploit chain for ZERODAY.CLOUD?
We just launched our Research Collaboration Center at zeroday.cloud/collab to connect researchers, combine skills, and meet the deadline. π€
The clock is ticking... β±οΈ
23.10.2025 16:00
π 0
π 0
π¬ 0
π 0
Our biggest reminder yet. ZERODAY.CLOUD.
A first-of-its-kind, open-source cloud hacking competition.
Find vulnerabilities in the critical open-source software that powers the cloud, and compete for your share of a $4.5M prize pool.
β‘οΈ www.zeroday.cloud
16.10.2025 17:24
π 1
π 0
π¬ 0
π 0
π We're giving away 2,000 SHIFT LEFT keyboards β
Want one on your desk?
Fill out the form >> redeem.reachdesk.com/lp/wiz/shift...
That's it! The keyboard is on its way π¦
Why are we doing this? π
A secret game is coming⦠and the whole world is invited.
16.10.2025 16:49
π 0
π 0
π¬ 0
π 0
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog
Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.
π¨ Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.
15.10.2025 14:34
π 2
π 2
π¬ 0
π 0
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog
From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.
@scottpiper.bsky.social highlights an emerging trend of attackers incorporating AI into their payloads, providing recent examples, and discussing the implications of this trend.
Full analysis: www.wiz.io/blog/the-eme...
09.10.2025 14:31
π 1
π 0
π¬ 0
π 0
Emerging Threat: AI-Powered Malware Attacks | Wiz Blog
From LameHug to s1ngularity, attackers are invoking AI directly in malware payloads.
π€ We're witnessing something unprecedented with AI agents:
Malware that literally prompts ChatGPT, Claude, and other LLMs to write its own attack code. Live. On victim machines.
09.10.2025 14:31
π 0
π 0
π¬ 1
π 0
Introducing ZERODAY.CLOUDπ΅οΈββοΈ
Be the first to participate in the first-of-its-kind cloud hacking competition. π€
WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. π°π
Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
30.09.2025 17:39
π 1
π 1
π¬ 0
π 0
@fortune.com JUST DROPPED A FEATURE ON Wiz π₯
If you've been following the Wiz story, this one's for you.
HUGE shoutout to everyone who made this story worth telling. You helped build something Fortune couldn't ignore π
fortune.com/article/wiz-...
30.09.2025 14:58
π 2
π 0
π¬ 0
π 0
π¨ #Shai-Hulud: Major npm supply chain attack.
100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm.
Guidance + detections inside
www.wiz.io/blog/shai-hu...
16.09.2025 14:20
π 3
π 2
π¬ 0
π 1
π¨ Major npm hijack: Attackers took over Qix's account (chalk, debug & more). Malicious versions briefly hit npm, injecting browser code to hijack crypto transactions.
DuckDB ecosystem is also affected.
09.09.2025 12:26
π 0
π 0
π¬ 1
π 0