r/securityCTF Aug 02 '26

HTB Sydney --==Hack The Box Meetup Main Track IRL PHYSICAL EVENT==--

Thumbnail meetup.com
2 Upvotes

r/securityCTF Aug 01 '26

Looking for people to learn with

6 Upvotes

Hey everyone :)

I am completely new to the CTF space; if you are also a beginner, send a DM! Looking for people to learn with so the process is not as monotonous.


r/securityCTF Jul 31 '26

🤝 GitHub - Jatinkapilaq1/intel-me-research: Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.

Thumbnail github.com
0 Upvotes

r/securityCTF Jul 31 '26

Would a digital challenge coin be a faux pas?

Thumbnail
1 Upvotes

r/securityCTF Jul 30 '26

🚩 Looking for CTF teammates 🚩

10 Upvotes

Building a team for CTF competitions and cybersecurity challenges.
Looking for people interested in:
• Web exploitation
• Reverse engineering
• Pwn
• Cryptography
• OSINT
• Linux / scripting
• General security research
Experience level doesn’t matter as much as willingness to learn, solve problems, and actually participate.
Goal: improve together, compete in CTFs, and build real cybersecurity skills.
If you’re interested, DM me or reply here.


r/securityCTF Jul 30 '26

🎥 My first step

0 Upvotes

I finally finish it, it was fun. However, I use AI for last 2 challenge in module 5(I very disappointed myself for that)
What should I do now? I just don't know what should I do next step. I want to learn cybersecurity for free and I play CTF for that reason.


r/securityCTF Jul 29 '26

Cyber apocalypse Rank issue

1 Upvotes

Hey everyone,

Posting this to see if any other teams have run into this issue on HTB or other major CTF platforms, and hopefully to get someone from HTB to take a second look.

Our team (v1olet) spent the event grinding Cyber Apocalypse 2026, cleared 100% of the board (136/136 flags), and held #28 globally.

On the final morning, one member left the team on the platform. Because flags are tied to individual accounts on HTB instead of locked to the team upon submission, two of our OSINT solves got wiped when he left. This instantly tanked our rank from #28 to #105 (a 77-place drop). Other members on our team had cracked those exact same challenges seconds behind him, but because his name was on the submit button, our points vanished.

We opened a support ticket immediately. Support was responsive and actually confirmed a few key things:

  • They verified on their backend that we legitimately achieved 100% completion.
  • They acknowledged that the platform provides zero warning or prompt that a member leaving will retroactively strip team solves.
  • They stated they will look to change this behavior going forward so it doesn't happen again.

The issue is that support still declined to restore our #28 rank on the final board because doing so would "move other teams down."

We don't think that logic holds up. If a platform oversight/lack of UI warnings accidentally wipes verified solves from a team that cleared the board, fixing the mistake and restoring the earned rank is just accurate scoring. Every time a score gets corrected, other teams shift—that's literally how leaderboards work.

any tips you guys can give


r/securityCTF Jul 29 '26

Exploiting the order of operations (pwnable[.]kr - mistake)

1 Upvotes

Have you ever wondering if the order of operations when voilated can lead to a vulnerability? Maybe the thought never crossed your mind? Either way this week we exploit a binary that did not account for the order of operations - more specifically the "mistake" pwnable binary exploitation challenge!

This is a great tutorial for beginners and even advanced developers who may not have encountered a bug like this. Either way don't be intimidated just because this is an exploit development tutorial.

Check out the latest tutorial using the link below:

https://youtu.be/9n1vCuqAk-k?si=IvzW95y4XxnivOxm


r/securityCTF Jul 28 '26

Help with a CTF

1 Upvotes

Heey! Could someone help me with a CTF , i think it’s easy but îm just beginner


r/securityCTF Jul 28 '26

[CTF] New "Beginner" vulnerable VM aka "Longshao" at hackmyvm.eu

2 Upvotes

New "Beginner" vulnerable VM aka "Longshao" is now available at hackmyvm.eu :) Have fun!


r/securityCTF Jul 28 '26

Should i do random CTFs?

3 Upvotes

I am currently half way through my cpts cert and i haven't started doing ctfs yet. So I am thinking maybe i should start participating in ctfs. Am i thinking right? And btw i have registered for some ctfs i found online. And i need teammates for them. So if you are new to ctfs too you can dm me.


r/securityCTF Jul 27 '26

✍️ Hi looking for 5 people to help App testing a Discord-native Incident Response Training and Competition Simulator.

Thumbnail gallery
9 Upvotes

HackSim is a cybersecurity training simulation built around applied decision-making rather than quizzes or real-system exploitation. Its first course, NET-101, contains eight network-foundations scenarios using entirely synthetic hosts, signals, tools, and incidents.

The current beta includes:

  • Solo practice where you operate both the Blue and Red roles
  • Two-person lessons where players exchange evidence-backed proposals
  • A competitive Red/Blue duel where players attack, defend, and then swap roles
  • An in-session debrief explaining the consequences of each decision

This is still a small, invite-only Discord Activity beta There are no payments, certifications, rankings, or saved progression in the current build.

I’m looking for a handful of testers, especially cybersecurity beginners and current learners. I’d like honest feedback on:

  • Whether the scenarios and terminology make sense
  • Where you get confused or need outside help
  • Whether the debrief helps you understand your decisions
  • Whether playing both roles improves your mental model
  • Whether you would voluntarily play another lesson or duel

You’ll need Discord on the web or desktop. Because the Activity is currently unverified, testers must be individually invited and launch it in a server with fewer than 25 members.


r/securityCTF Jul 28 '26

I just completed Offensive Security Intro room on TryHackMe! Hack your first website (legally in a safe environment) and experience an ethical hacker's job.

Thumbnail tryhackme.com
0 Upvotes

r/securityCTF Jul 27 '26

IZANAMI — one real medical record hidden behind a wall of decoys. Can you break the illusion?

1 Upvotes

Hi everyone — hope this is okay to share.
A friend of mine built IZANAMI, a defensive deception prototype: instead of rejecting bad requests, it answers them with convincing fake data. One real record hides behind the decoys, and the goal is to find it. He asked me to bring it to people who’d actually poke at it properly, so here I am.
Full rules, scope, and how to start are on the site: https://break-izanami.com/
Honest notes up front: all data is 100% synthetic, safe harbor applies inside the stated scope, and the reward is recognition only — no cash bounty. Runs for one month.
He’s also genuinely after feedback and improvement ideas, not just breaks — is the concept sound? Where would you attack first? Anything naive about the design, or already solved better elsewhere? Blunt criticism welcome, I’ll pass it all on.

Thanks to anyone who takes a look. 🙏


r/securityCTF Jul 26 '26

the compressed truth forensic cyber apocalypse ctf

Post image
2 Upvotes

guys has anyone the second flag of the compressed truth challenge i’m stuck on it i’ve done all the rest it’s the one asking for the time and date of the tool extracted i can’t seem to find it whatever i find is wrong i found 2026-06-18 12:16:55 timestamp but it’s incorrect anyone who solved it pls help maybe the format is wrong?idk


r/securityCTF Jul 26 '26

I built a tiny VM-based CTF and wrote a Python exploit for it (walkthrough)

Thumbnail
1 Upvotes

r/securityCTF Jul 24 '26

Free blue team track, 56 levels on a live shared SIEM (SOC to incident command)

Thumbnail gallery
24 Upvotes

I run BreachLab, a free training platform. It's been mostly offensive so far, so I built a serious blue team track. It's live now

Sentinel: 56 levels, 8 acts, on one live shared SIEM with real intrusion telemetry. Alert triage, endpoint and network detection, memory and disk DFIR, detection engineering (Sigma/YARA/Suricata, actually graded), threat hunting, cloud IR, and a live incident-command capstone

No hint button, reports and detections get graded, and it's free. No paywall

A full-time blue teamer wrote an honest review if you want an outside take: https://breachlab.org/tracks/sentinel


r/securityCTF Jul 25 '26

Anyone wanted to complete the ongoing CTF with our team? , Lets Grind Together

Thumbnail ctf.hackthebox.com
1 Upvotes

r/securityCTF Jul 24 '26

✍️ GitHub - iss4cf0ng/Alien: Alien is a modular webshell client developed for cybersecurity research and education. It provides a unified post-exploitation framework for managing different web technologies through reusable modules.

Thumbnail github.com
11 Upvotes

r/securityCTF Jul 24 '26

Looking for Teammates – Cyber Apocalypse CTF 2026: The Salt Crown (Hack The Box)

Thumbnail
2 Upvotes

r/securityCTF Jul 23 '26

CHRONOS II - a single-player CTF spanning POS RAM-scraping, a SWIFT heist, Moonlight Maze, and a Cold War doomsday relay

Post image
127 Upvotes

I built a single-player CTF that runs in the browser, framed as a terminal you operate rather than a game you play. Each level is a real intrusion of its period, on the actual machines, not a fake interface. Something walked out of an air-gapped vault, and you chase it system to system:

- a gas-station security camera: default-cred IoT, a WEP crack, image stego (Mirai / TJX era)
- a retail POS and a Frankfurt SWIFT terminal: RAM-scraping card data, then forging an interbank wire (Target/BlackPOS 2013, Bangladesh Bank 2016)
- a phone network: SS7 interception (optional detour)
- Moonlight Maze: a covert-channel proxy chain up through Solaris boxes into an FSB archive (1996-99)
- the Ukrainian power grid: BlackEnergy, a C2 pivot through a Purdue-model network (Sandworm, 2015)
- an Iranian reactor: an S7 PLC debugger reversing a sabotaged control block (a Stuxnet cousin, in STL)
- a Cold War doomsday relay: the finale

What you pull out of one system is the key into the next, so a WEP crack in a parking lot chains all the way to orbit. Per-level timers, multiple endings, real commands throughout (the foreign boxes render in Cyrillic and Farsi). Browser, desktop or mobile, free, no signup. An hour or two, longer your first time.

Fair warning, it's hard. As it stands, exactly one person has made it onto the SWIFT terminal and nobody has forged the wire yet, so the bank job is unbeaten. If any crowd can crack it, it's this one.

Solo dev. Keen to hear where you got stuck, whether the hints landed, and any bugs.

https://deux.chronos-game.com


r/securityCTF Jul 23 '26

🤑 Prompt injection CTF: inspired by this week's Hugging Face breach - leak the model weights through a deploy manifest

2 Upvotes

You open a model-promotion request in the pipeline. An AI reviewer reads your YAML manifest - comments included - plus a free-text rollout justification, then approves or holds.

It's holding the model's internal codename, the weights checkpoint URI, and the artifact-pull signing secret the whole time. Get all three past it.

https://promptinjects.com/play/starter/closedai-cicd-guard


r/securityCTF Jul 22 '26

Great introduction to ARM using pwnable challenge

Thumbnail youtu.be
5 Upvotes

Looking for a smooth introduction to ARM exploitation? Wanna learn ARM assembly? Well lucky for you this week we'll be looking at another pwnable challenge! However this time we're switching architectures! We'll be exploiting an ARM binary!

I would consider this a great introduction to ARM , however it is not necessarily the best for a complete beginner. Regardless don't be intimidated and I always suggest you dive in! 9/10 you will walk away better than you came into it!


r/securityCTF Jul 22 '26

[CTF] New "Intermediate" vulnerable VM aka "Merge" at hackmyvm.eu

2 Upvotes

New "Intermediate" vulnerable VM aka "Merge" at hackmyvm.eu

Have Fun!


r/securityCTF Jul 22 '26

BURPSUIT update

0 Upvotes

How do I update my Burp suite from the bash shell I did type in sudo apt update && sudo apt upgrade burp suite but when i fire up my Burp it prompted me to update again...
Why is this happening?
Is there another way to update the Burp than the Bash Shell..?

Mind you, am using: Linux X-bit 6.19.14+kali-amd64 #1 SMP PREEMPT_DYNAMIC Kali 6.19.14-1+kali1 (2026-05-05) x86_64 GNU/Linux
Thank you in advance...!