Tianfu Cup 2018 PWN – Ethical Hackers Hacked Apple, Adobe, Google, Microsoft, Oracle, VMware & Earned 1,000,000 USD

One of the Worlds Leading Cybersecurity based international Contest Tianfu Cup 2018 PWN held in China where Whitehat Hackers exploited various Zero-day Exploits and earned more than 1,000,000 USD.

Last week, A Group of White hat hackers compromised Samsung Galaxy S9, iPhone X,  Xiaomi Mi6 and earned $325,000 in Pwn2Own, two days Hacking completion in Tokyo 2018 organized by Trend Micro’s Zero Day Initiative (ZDI).

This Cybersecurity contest was held on November 16-17 in Chengdu, China during Tianfu Cup conference and it was organized by various technology giants Alibaba, Tencent, Baidu etc.

Experts discussed various Important topics including vulnerability research, AI security, Cloud Security and network security talent training, video surveillance, mobile security etc.

Tianfu Cup 2018 PWN invited All cyber security researchers and lovers all over the world and totally 17 teams arrived at the event, but 7 teams gave up for various reasons.

Totally 13 targets have participated including Apple, Adobe, Google, Microsoft, Oracle, VMware, OPPO, Xiaomi, and Vivo.

Worlds top experts have attended the event and they compromised 11 targets and 30 vulnerabilities are submitted to vendors along with most of the Zero-day vulnerabilities.

In this contest, iPhoneX has been successfully compromised by 360 security Team experts and they earned 200,000 US dollars which is one of the highest paid Zero-day reports to Apple.

Event Management team gave different points for each and every target along with the Rules and the highest point was give to Apple, Chrome, and VMware bugs.

The total prize amount offered by the Sponsor is 1 million USD. Prizes will be distributed within twelve (12) weeks after each winner has fulfilled the requirements

Winners, Prices & Awards

Overall 10 teams have participated n the contest, among them, Team of Security experts from 360security got the first Price. They won 620000 USD through 68 PWN points and got the championship.

360security discovered and successfully exploited the serious Zero-day bugs from Apple Safari, iPhoneX, Google Chrome, Microsoft  Edge, Microsoft Office, and Oracle Virtual Box.

                                                               Champion: 360Security (68 points)

Followed by 360security, the Institute of Computing Technology of the Chinese Academy of Sciences and Tencent Atuin got 26 PWN points and earned 75000 USD for exploiting bugs in Edge, Xiaomi Mi8 OPPO And adobe PDF reader.

                                      Runner-up winner: The Team of CAS and Tencent

Likewise, Qixun Zhan got 18 PWN  points and earned 90000 USD, Tianwan Tang, an Individual security expert alone earned 100000 USD and also got Best Pwning Skills Award.

                                                   Best Pwning Skills Award: Tianwen Tang

Apart from this, 360VT Team earned $80000 for Anti Financial oyear team earned $9000, Zhenjie jia, an individual earned $ 40000, Nirvan Team earned $10000.

So The highest reward is $200,000 that was paid out for iPhone X jailbreak and a remote code execution exploit ,  $120,000 for two Microsoft Edge exploits,  $150,000 paid for two Chrome exploits, $150,000 paid for Safari flaw,  $100,000 for a macOS zero-day exploit,  $100,000 paid for VMware Workstation and $120,000 paid for two Oracle VirtualBox exploit and There is no bug was exploited from Mozilla Firefox.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

GitLab Patches HTML Injection Flaw Leads to XSS Attacks

GitLab has announced the release of critical security updates for its Community Edition (CE) and…

8 hours ago

Xerox Printers Vulnerable to Remote Code Execution Attacks

Multiple Xerox printer models, including EC80xx, AltaLink, VersaLink, and WorkCentre, have been identified as vulnerable…

9 hours ago

Cisco ASA Devices Vulnerable to SSH Remote Command Injection Flaw

Cisco has issued a critical security advisory regarding a vulnerability in its Adaptive Security Appliance…

11 hours ago

Google Patches Multiple Chrome Security Vulnerabilities

Google has released several security patches for its Chrome browser, addressing critical vulnerabilities that malicious…

12 hours ago

Grayscale Investments Data Breach Exposes 693K User Records Reportedly Affected

Grayscale Investments, a prominent crypto asset manager, has reportedly suffered a data breach affecting 693,635…

1 day ago

Threat Actors Allegedly Selling Database of 1,000 NHS Email Accounts

A database containing over 1,000 email accounts associated with the National Health Service (NHS) has…

1 day ago