Tianfu Cup 2018 PWN – Ethical Hackers Hacked Apple, Adobe, Google, Microsoft, Oracle, VMware & Earned 1,000,000 USD

One of the Worlds Leading Cybersecurity based international Contest Tianfu Cup 2018 PWN held in China where Whitehat Hackers exploited various Zero-day Exploits and earned more than 1,000,000 USD.

Last week, A Group of White hat hackers compromised Samsung Galaxy S9, iPhone X,  Xiaomi Mi6 and earned $325,000 in Pwn2Own, two days Hacking completion in Tokyo 2018 organized by Trend Micro’s Zero Day Initiative (ZDI).

This Cybersecurity contest was held on November 16-17 in Chengdu, China during Tianfu Cup conference and it was organized by various technology giants Alibaba, Tencent, Baidu etc.

Experts discussed various Important topics including vulnerability research, AI security, Cloud Security and network security talent training, video surveillance, mobile security etc.

Tianfu Cup 2018 PWN invited All cyber security researchers and lovers all over the world and totally 17 teams arrived at the event, but 7 teams gave up for various reasons.

Totally 13 targets have participated including Apple, Adobe, Google, Microsoft, Oracle, VMware, OPPO, Xiaomi, and Vivo.

Worlds top experts have attended the event and they compromised 11 targets and 30 vulnerabilities are submitted to vendors along with most of the Zero-day vulnerabilities.

In this contest, iPhoneX has been successfully compromised by 360 security Team experts and they earned 200,000 US dollars which is one of the highest paid Zero-day reports to Apple.

Event Management team gave different points for each and every target along with the Rules and the highest point was give to Apple, Chrome, and VMware bugs.

The total prize amount offered by the Sponsor is 1 million USD. Prizes will be distributed within twelve (12) weeks after each winner has fulfilled the requirements

Winners, Prices & Awards

Overall 10 teams have participated n the contest, among them, Team of Security experts from 360security got the first Price. They won 620000 USD through 68 PWN points and got the championship.

360security discovered and successfully exploited the serious Zero-day bugs from Apple Safari, iPhoneX, Google Chrome, Microsoft  Edge, Microsoft Office, and Oracle Virtual Box.

                                                               Champion: 360Security (68 points)

Followed by 360security, the Institute of Computing Technology of the Chinese Academy of Sciences and Tencent Atuin got 26 PWN points and earned 75000 USD for exploiting bugs in Edge, Xiaomi Mi8 OPPO And adobe PDF reader.

                                      Runner-up winner: The Team of CAS and Tencent

Likewise, Qixun Zhan got 18 PWN  points and earned 90000 USD, Tianwan Tang, an Individual security expert alone earned 100000 USD and also got Best Pwning Skills Award.

                                                   Best Pwning Skills Award: Tianwen Tang

Apart from this, 360VT Team earned $80000 for Anti Financial oyear team earned $9000, Zhenjie jia, an individual earned $ 40000, Nirvan Team earned $10000.

So The highest reward is $200,000 that was paid out for iPhone X jailbreak and a remote code execution exploit ,  $120,000 for two Microsoft Edge exploits,  $150,000 paid for two Chrome exploits, $150,000 paid for Safari flaw,  $100,000 for a macOS zero-day exploit,  $100,000 paid for VMware Workstation and $120,000 paid for two Oracle VirtualBox exploit and There is no bug was exploited from Mozilla Firefox.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has been…

56 minutes ago

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government, defense,…

60 minutes ago

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency of…

1 hour ago

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working in…

1 hour ago

DragonForce Attacks Critical Infrastructure to Exfiltrate Data and Halt Operations

The DragonForce ransomware group has launched a significant cyberattack on critical infrastructure in Saudi Arabia,…

1 hour ago

New Malware Uses Legitimate Antivirus Driver to Bypass All System Protections

In a concerning development, cybersecurity researchers at Trellix have uncovered a sophisticated malware campaign that…

1 hour ago