Tuesday, May 13, 2025
HomeCyber Security NewsTianfu Cup 2018 PWN - Ethical Hackers Hacked Apple, Adobe, Google, Microsoft,...

Tianfu Cup 2018 PWN – Ethical Hackers Hacked Apple, Adobe, Google, Microsoft, Oracle, VMware & Earned 1,000,000 USD

Published on

SIEM as a Service

Follow Us on Google News

One of the Worlds Leading Cybersecurity based international Contest Tianfu Cup 2018 PWN held in China where Whitehat Hackers exploited various Zero-day Exploits and earned more than 1,000,000 USD.

Last week, A Group of White hat hackers compromised Samsung Galaxy S9, iPhone X,  Xiaomi Mi6 and earned $325,000 in Pwn2Own, two days Hacking completion in Tokyo 2018 organized by Trend Micro’s Zero Day Initiative (ZDI).

This Cybersecurity contest was held on November 16-17 in Chengdu, China during Tianfu Cup conference and it was organized by various technology giants Alibaba, Tencent, Baidu etc.

- Advertisement - Google News

Experts discussed various Important topics including vulnerability research, AI security, Cloud Security and network security talent training, video surveillance, mobile security etc.

Tianfu Cup 2018 PWN invited All cyber security researchers and lovers all over the world and totally 17 teams arrived at the event, but 7 teams gave up for various reasons.

Totally 13 targets have participated including Apple, Adobe, Google, Microsoft, Oracle, VMware, OPPO, Xiaomi, and Vivo.

Worlds top experts have attended the event and they compromised 11 targets and 30 vulnerabilities are submitted to vendors along with most of the Zero-day vulnerabilities.

In this contest, iPhoneX has been successfully compromised by 360 security Team experts and they earned 200,000 US dollars which is one of the highest paid Zero-day reports to Apple.

Event Management team gave different points for each and every target along with the Rules and the highest point was give to Apple, Chrome, and VMware bugs.

The total prize amount offered by the Sponsor is 1 million USD. Prizes will be distributed within twelve (12) weeks after each winner has fulfilled the requirements

Winners, Prices & Awards

Overall 10 teams have participated n the contest, among them, Team of Security experts from 360security got the first Price. They won 620000 USD through 68 PWN points and got the championship.

360security discovered and successfully exploited the serious Zero-day bugs from Apple Safari, iPhoneX, Google Chrome, Microsoft  Edge, Microsoft Office, and Oracle Virtual Box.

                                                                 Champion: 360Security (68 points)

Followed by 360security, the Institute of Computing Technology of the Chinese Academy of Sciences and Tencent Atuin got 26 PWN points and earned 75000 USD for exploiting bugs in Edge, Xiaomi Mi8 OPPO And adobe PDF reader.

                                        Runner-up winner: The Team of CAS and Tencent

Likewise, Qixun Zhan got 18 PWN  points and earned 90000 USD, Tianwan Tang, an Individual security expert alone earned 100000 USD and also got Best Pwning Skills Award.

                                                     Best Pwning Skills Award: Tianwen Tang

Apart from this, 360VT Team earned $80000 for Anti Financial oyear team earned $9000, Zhenjie jia, an individual earned $ 40000, Nirvan Team earned $10000.

So The highest reward is $200,000 that was paid out for iPhone X jailbreak and a remote code execution exploit ,  $120,000 for two Microsoft Edge exploits,  $150,000 paid for two Chrome exploits, $150,000 paid for Safari flaw,  $100,000 for a macOS zero-day exploit,  $100,000 paid for VMware Workstation and $120,000 paid for two Oracle VirtualBox exploit and There is no bug was exploited from Mozilla Firefox.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Microsoft Patch Tuesday May 2025 Released With the Fixes for 72 Flaws With 5 Actively Exploited 0-Day

Microsoft has released its May 2025 Patch Tuesday updates, addressing 72 security vulnerabilities across...

Ivanti Released Security Updates to Fix for the Mutiple RCE Vulnerabilities – Patch Now

Ivanti, a leading enterprise software provider, has released critical security updates addressing vulnerabilities across...

Fortinet FortiVoice Zero-day Vulnerability Actively Exploited in The Wild

A critical stack-based buffer overflow vulnerability (CWE-121) has been discovered in multiple Fortinet products,...

Ransomware Attacks Surge by 123% Amid Evolving Tactics and Strategies

The 2025 Third-Party Breach Report from Black Kite highlights a staggering 123% surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Patch Tuesday May 2025 Released With the Fixes for 72 Flaws With 5 Actively Exploited 0-Day

Microsoft has released its May 2025 Patch Tuesday updates, addressing 72 security vulnerabilities across...

Ivanti Released Security Updates to Fix for the Mutiple RCE Vulnerabilities – Patch Now

Ivanti, a leading enterprise software provider, has released critical security updates addressing vulnerabilities across...

Fortinet FortiVoice Zero-day Vulnerability Actively Exploited in The Wild

A critical stack-based buffer overflow vulnerability (CWE-121) has been discovered in multiple Fortinet products,...