Security News

Cybersecurity news aggregator

📰
INFO News SecurityWeek

China Revives Tianfu Cup Hacking Contest Under Increased Secrecy

  • What: China has revived the Tianfu Cup hacking contest, now overseen by the government with limited transparency.
  • Impact: The contest, an alternative to Pwn2Own, offers smaller rewards for exploits compared to its earlier years.
Read Full Article →

GOVERNMENT China Revives Tianfu Cup Hacking Contest Under Increased Secrecy Rewards for exploits are reportedly much smaller than in the contest’s glory days. By Eduard Kovacs | February 13, 2026 (1:49 AM ET) Flipboard Reddit Whatsapp Email China’s Tianfu Cup hacking contest made its return in 2026, now overseen by the government and marked by limited transparency. Tianfu Cup was launched as an alternative to the Zero Day Initiative’s Pwn2Own competition, which regularly pays out more than $1 million to white hat hackers who demonstrate critical vulnerabilities in consumer and enterprise hardware and software, industrial control systems, and automotive products. Tianfu Cup made headlines in 2021, when participants earned a total of $1.9 million for exploits targeting Windows, Ubuntu, iOS, Microsoft Exchange, Chrome, Safari, Adobe Reader, Asus routers, and various virtualization products. The hacking competition took a break in 2022 and returned in 2023 with a focus on domestic products from companies such as Huawei, Xiaomi, Tencent, and Qihoo 360. Little information was provided about the results of the 2023 event. After a two-year hiatus in 2024 and 2025, the Tianfu Cup returned in 2026, but again little information has been made public. The event took place January 29-30. According to threat intelligence firm Natto Thoughts, the hacking competition is now organized by China’s Ministry of Public Security (MPS) and it appears to be even more secretive. ADVERTISEMENT. SCROLL TO CONTINUE READING. Eugenio Benincasa, an ETH Zurich cybersecurity researcher focusing on China, pointed out in a Natto Thoughts blog post that the MPS announced the Tianfu Cup on January 16. A few days later, a post announcing the event was also published on Tianfu Cup’s X account, but it was quickly removed. A day later, the competition’s official website became inaccessible to visitors from outside of China, and after the event ended the website was completely taken offline. Tianfu Cup targets Natto Thoughts obtained the list of Tianfu Cup targets before the site was taken down. It included smartphones such as the iPhone 17, Xiaomi 14 Ultra, Honor Magic 7 Pro, Samsung Galaxy S24 Ultra, Google Pixel 9 Pro XL, Vivo X300, and Oppo Find X9 Pro. A translation of the requirements for hacking these devices reads, “Ability to achieve remote code execution, sandbox escape, kernel privilege escalation, and local kernel privilege escalation on the competition device, thereby obtaining device privileges and data.” In the operating systems category, hackers were invited to demonstrate exploits against Windows 11, Ubuntu, macOS, UOS, and KylinOS. The browsers category included Chrome, Edge, and Safari. Targeted cloud and virtualization products included VMware ESXi, Oracle VirtualBox, ZStack Cloud, QEMU, and Docker Engine, with participants being asked to gain elevated privileges on the host system. Hackers were also invited to fully compromise cybersecurity products from Hillstone Networks, Palo Alto Networks, and the Chinese firm Topsec. The target list also included Microsoft Exchange Server and Coremail mail servers; WeChat, Feishu (Lark), Teams, Zoom, and DingTalk communication apps; and PostgreSQL, Dameng, TiDB, KingbaseES, GBase, and Redis databases. Office applications such as Microsoft Office 365, WPS Office, Foxit PDF Editor, Adobe Acrobat Reader, Sogou, Weaver E-cology, Seeyon, and Yonyou YonBIP were also on the list. Tianfu Cup 2026 also had an AI category that included Hugging Face, Ollama, OpenLLM, vLLM, Text Generation Inference (TGI), Dify, RagFlow, Coze Studio, LangChain, and ComfyUI, with the goal of achieving remote code execution in the default configuration. New rules and smaller prizes An industry insider with knowledge of the Tianfu Cup told SecurityWeek that “rules and targets have changed a lot” this year, but could not provide additional information. Natto Thoughts noted that this year’s event featured a track in which participants used AI agents to identify vulnerabilities during the competition. Another new track focused on reproducing exploits for known vulnerabilities. While there appears to be no public information on individual rewards from this year’s competition, a press release from China’s MPS states a total prize pool of CN„ 1 million (approximately $140,000), significantly smaller than five years ago. The exploits will likely go to the Chinese government Regulations implemented by China in 2021 require Chinese citizens who discover a zero-day vulnerability to report the details to the government and not disclose it to any third party outside the country. One year later, Microsoft warned that Chinese nation-state threat actors had been leveraging the law to stockpile zero-days for their sophisticated attacks. Evidence indicates that the exploits demonstrated at previous editions of the Tianfu Cup were used in cyberespionage operations by Chinese state-sponsored groups, and Natto Thoughts believes the vulnerabilities disclosed now will face a similar fate. “The central role of the MPS in organizing the competition, combined with past episodes that raised long-standing suspicions and the absence of transparent [coordinated vulnerability disclosure] rules, suggests a system oriented toward vulnerability retention and state control rather than on vendor notification or coordinated disclosure,” the threat intel firm noted. Related: $2.5 Million Offered at Upcoming ‘Matrix Cup’ Chinese Hacking Contest Related: Singapore: Rootkits, Zero-Day Used in Chinese Attack on Major Telecom Firms Related: Notepad++ Supply Chain Hack Conducted by China via Hosting Provider WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Conduent Breach Hits Volvo Group: Nearly 17,000 Employees’ Data Exposed Chipmaker Patch Tuesday: Over 80 Vulnerabilities Addressed by Intel and AMD Google-Intel Security Audit Reveals Severe TDX Vulnerability Allowing Full Compromise ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, Phoenix Contact 6 Actively Exploited Zero-Days Patched by Microsoft With February 2026 Updates EU Unconditionally Approves Google’s $32B Acquisition of Wiz Patch Tuesday: Adobe Fixes 44 Vulnerabilities in Creative Apps Reco Raises $30 Million to Enhance AI SaaS Security Latest News How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development ApolloMD Data Breach Impacts 626,000 Individuals Microsoft to Enable ‘Windows Baseline Security’ With New Runtime Integrity Safeguards Hacktivists, State Actors, Cybercriminals Target Global Defense Industry, Google Warns Nucleus Raises $20 Million for Exposure Management Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’ Nevada Unveils New Statewide Data Classification Policy Months After Cyberattack Webinar Today: Identity Under Attack – Strengthen Your Identity Defenses TRENDING Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Leilani Farol has joined Financial services firm First Horizon as SVP, CISO. Pennsylvania has named Andy Ritter as CISO and Jim Sipe as executive deputy CIO. Hayete Gallot has rejoined Microsoft as Executive Vice President, Security. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article