Dec 16, 2025 • Wiz Security Research
Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra
The ZeroDay.cloud 2025 event highlighted a significant surge in critical vulnerabilities affecting core cloud infrastructure. Organizers awarded $320,000 to...
Executive Summary
The ZeroDay.cloud 2025 event highlighted a significant surge in critical vulnerabilities affecting core cloud infrastructure. Organizers awarded $320,000 to researchers who uncovered a record-breaking number of CVEs within open-source software essential to modern cloud operations. This findings underscore the urgent need for enhanced security measures surrounding foundational cloud technologies. While no specific threat actors or malware families were identified in this report, the sheer volume of zero-day vulnerabilities presents a substantial risk for potential exploitation by adversaries seeking initial access. Organizations relying on these open-source components must prioritize patch management and vulnerability scanning to mitigate risks. The event emphasizes the growing intersection of artificial intelligence and vulnerability discovery, signaling a shift in how security flaws are identified and remediated in critical infrastructure environments globally.
Summary
ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud.
Published Analysis
The ZeroDay.cloud 2025 event highlighted a significant surge in critical vulnerabilities affecting core cloud infrastructure. Organizers awarded $320,000 to researchers who uncovered a record-breaking number of CVEs within open-source software essential to modern cloud operations. This findings underscore the urgent need for enhanced security measures surrounding foundational cloud technologies. While no specific threat actors or malware families were identified in this report, the sheer volume of zero-day vulnerabilities presents a substantial risk for potential exploitation by adversaries seeking initial access. Organizations relying on these open-source components must prioritize patch management and vulnerability scanning to mitigate risks. The event emphasizes the growing intersection of artificial intelligence and vulnerability discovery, signaling a shift in how security flaws are identified and remediated in critical infrastructure environments globally. ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud. ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud.