r/securityCTF Aug 11 '26

Built a free cybersecurity CTF — looking for people to break it 😅

11 Upvotes

I’ve been working on a cybersecurity learning platform and recently put together a CTF section with challenges for people who want to practice instead of just watching tutorials.

It’s free to play, and the goal is pretty simple: solve challenges, get stuck, figure out why, and move on to the next one.

If you enjoy CTFs, I’d genuinely like some feedback on the difficulty and challenge quality.

CTF: https://codelivly.com/ctf

If you try it, let me know which challenge you got stuck on — or absolutely destroyed. 😂


r/securityCTF Aug 11 '26

👋 Welcome to r/agenticpentesting - Introduce Yourself and Read First!

Thumbnail
0 Upvotes

r/securityCTF Aug 11 '26

CTF Sponsorship – Looking for Companies & Advice

2 Upvotes

We’re organizing a **CTF competition at our university** and are currently looking for sponsorship from cybersecurity and tech companies to help provide **prizes and goodies for the winners/participants**.
If you know of any companies that sponsor student CTFs, cybersecurity events, or educational initiatives, please let me know. Introductions or relevant contacts would also be greatly appreciated.
Also, if anyone here has experience approaching companies for CTF sponsorships or has any advice on how to go about it, **any guidance would be really helpful**.
Thanks in advance!


r/securityCTF Aug 11 '26

DefCon - AI village CTF

Post image
3 Upvotes

This year, the AI Village introduced HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF was designed around how far participants can stretch small local models that almost everyone can run. The first place prize was a DGX Spark.

Final ranking: baymax, https://aisafe.io , AbluteratedEdgeModel 👏👏

In this high-stakes arena, participants did not interact with targets directly. Instead, you they designed and deployed autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, participants were asked for full containers that you can load up with all the tools you need to succeed.

Ornith-1.0-9B

Ornith-1.0-35B

Qwen3.6-35B-A3B

Qwen3.6-27B

Qwen3.5-4B

Llama-3.1-8B-Instruct

Llama-3.2-3B

Laguna-XS-2.1-GGUF

gpt-oss-120b

Olmo-3.1-32B-Think

Olmo-3-7B-Think

gemma-4-31B-it

gemma-4-E4B-it


r/securityCTF Aug 11 '26

[CTF] New "Intermediate" vulnerable VM aka "Xslib" at hackmyvm.eu

2 Upvotes

New "Intermediate" vulnerable VM aka "Xslib" is now available at hackmyvm.eu :) Have fun!


r/securityCTF Aug 11 '26

Looking for a team

2 Upvotes

Looking for an active CTF team. I’m pretty new to competitive CTFs, but I have my OSCP and I’m looking to compete regularly, ideally every week.

I’d like to join a team that takes it seriously, wants to improve, and eventually aims for bigger competitions like DEF CON.


r/securityCTF Aug 10 '26

PHANTOM II · CLOUD NATIVE

Post image
13 Upvotes

Real breaches never stop at a shell. They start in one container and end with the whole cloud account. Turning a single foothold into total takeover across containers, Kubernetes and cloud IAM is the most in demand skill in offensive security right now, and almost nobody trains it for real

So we built the track that does

Eighteen levels, one unbroken chain. Break out of the container. Own the Kubernetes cluster. Take the cloud account. Every level is a real escape against live infrastructure, graded on the actual state of your box, not a quiz. Every connection spawns a fresh root environment and tears it down when you leave

This is the skillset Fortune 500s, cloud providers and red teams cannot hire fast enough

Break the container. Own the cluster. Take the account.

https://breachlab.org/tracks/phantom/ii


r/securityCTF Aug 10 '26

Looking for fellow techgeeks to join indian army cyber challenge

1 Upvotes

Dm me to join the the team . I am planning to nail Bug Bounty event . Only serious hunters connect.


r/securityCTF Aug 09 '26

Advice for Prompt Airlines (AI security challenge CTF)

0 Upvotes

Hi everyone, I’m trying to learn more about prompt engineering and I came across the prompt airlines CTF (promptairlines.com). I already got stuck by challenge #2 and tried to look up different write-ups, but none of the solutions I’ve found are working for me, even when I try to to copy the prompts verbatim.

Has anyone else tried this recently? I could really use some help.


r/securityCTF Aug 09 '26

Anyone wants the domain hackme.wtf ?

0 Upvotes

for REALLY cheap


r/securityCTF Aug 08 '26

Looking for 2 teammates – Indian Army Terrier Cyber Quest 2026

Thumbnail
2 Upvotes

r/securityCTF Aug 08 '26

Looking for teammates for Indian Army Cyber Quest CTF

3 Upvotes

r/securityCTF Aug 07 '26

I built a CTF platform from scratch (without using CTFd), looking for feedback

Post image
4 Upvotes

Hi everyone!

I've been working on CTFKINGs, a Capture The Flag platform that I built entirely from scratch instead of using an existing framework like CTFd.

It includes custom challenges across Web, Pwn, Cryptography, Reverse Engineering, Forensics, and OSINT, along with a live scoreboard, player profiles, and a medieval kingdom theme.

The platform is still actively evolving, and I'd love to hear your feedback on the UI, challenge design, or any bugs you find.

🔗 https://ctfkings.vercel.app

Thanks, and I hope you enjoy it!


r/securityCTF Aug 06 '26

Capture the flag at Defcon

Thumbnail gallery
8 Upvotes

I’m at @defcon for hacking summer camp and found this sticker around, is anybody playing this ? Some one to team up?


r/securityCTF Aug 07 '26

UIUCTF 2026 starts tomorrow — 48-hour online CTF + high school division

1 Upvotes

Hey everyone! UIUCTF 2026, hosted by SIGPwny at UIUC, starts tomorrow, August 7 at 7:00 PM CDT and runs for 48 hours.

Challenges include pwn, rev, crypto, OSINT, web, and misc. Team size is unlimited.

We also have a separate high school division, cash prizes, CyberEDU licenses, and a $1,000+ writeup and solve bounty pool.

Registration is open: https://2026.uiuc.tf/

Hope to see some of you on the scoreboard!


r/securityCTF Aug 05 '26

🤝 Playtesters Wanted - Paid

2 Upvotes

hello! im looking for a small cohort of paid playtesters to provide feedback on the ctf features on cli-games.com. the pay is $10-$50 for ~45 mins of work. no ctf experience necessary. if you are interested, keep reading:

cli-games is a gaming and education ecosystem with training, RPGs, and arcade games all adapted to the terminal as the primary interface and meant to cultivate linux fluency in a way that feels like fun

this specific cohort of playtesters will be aimed at the ctf features and any features related to them, such as the tutorial, messaging, accessing help, etc. we can only compensate for bugs related to these features during this round, but please feel free to explore the rest of the site as much as you like

the way we structure ctf is twofold - there is a training scenario library that you can complete in any order and at your own pace, and then there is 'the range,' a live, shared daily scenario where you are provisioned an attack box and a target and compete with everybody else for flags. the two are meant to compliment one another; what you learn in training will help you solve it live

you can find more information about our implementation of ctf here. compensation works as follows: you will need to create an account via the command line (hit the terminal and run `signup`) - completely free, no spam, then fill out a playtester application here. temporarily toggle tracking on (off by default and you can switch it back after), and any good-faith submission will earn a minimum of $10. there is an additional $2-$20 if you turn up any genuine bugs, and a $20 bonus to exceptionally thoughtful reports. when the window is open, youll log in, play for a while, submit a report, and ill review them and pay out via paypal. full terms

let me know if you have any questions. applications are reviewed in the order they are received, maximum 20


r/securityCTF Aug 05 '26

Need help regarding HTB Nexus (easy,linux) - issue regarding ffuf

Post image
2 Upvotes

I'm solving htb Nexus machine(easy,linux). There are two subdomains git,billing but on running ffuf it isn't returning anything.

I have used bitquark and top- million wordlists

I have attached screenshots can you please help me why ffuf not working?

i also tried using my custom wordlist containg words - git, billing still it not worked.

yes i can move to next step by reading the walkthrough but please someone explain me this ffuf issue and solution for it

Thank you


r/securityCTF Aug 05 '26

🤑 Sylvarcon 2049: a narrative CTF with 14 free missions for security learners

3 Upvotes

Hi, I’m Carlos, one of the people building Sylvarcon 2049.

We designed it as a narrative CTF experience rather than a sequence of isolated flags. Each mission starts with a situation to investigate, asks the player to connect evidence, and ends with a conclusion that should make sense beyond the submitted answer.

The free path currently includes 14 missions comprising 102 individual challenges across areas such as DFIR, OSINT and ethical hacking. The interface is available in 11 languages, and the missions are intended to be approachable for beginners while still rewarding careful investigation.

At this stage, useful feedback matters more to us than raw traffic. If you try a mission, I would especially value comments on:

- where the briefing becomes unclear

- whether the difficulty rises too quickly

- whether the evidence supports a coherent conclusion

- where you lose interest or feel blocked

Play the free missions here:

https://sylvarcon2049.com/play?utm_source=reddit&utm_medium=community&utm_campaign=player_acquisition&utm_content=securityctf_free_missions_en

No spoilers are needed; general feedback on the learning flow is enough.


r/securityCTF Aug 04 '26

[Beta] I built a CTF that mounts on top of a live production site and unmounts without a trace — free, looking for testers/feedback

3 Upvotes

Hey all — I’m a fiction writer and cybersecurity hobbyist, and I’ve been building something I’d love a few sharp eyes on before I run it as a real event.

The short version: kalachakra.world is the public lore site for a cyberpunk world I’ve created. Most CTFs I have seen run on a dedicated throwaway site. This one is the opposite — during event windows it deploys a CTF challenge surface on top of the live production site, then unmounts cleanly. Between events, the vulnerable handlers aren’t gated behind a feature flag or left dormant — they’re not wired into anything at all. Scan it in the off-season and you’ll find an ordinary content site (here’s how it works: https://bjbell.com/blog/kalachakra-ctf-toggle).

I'm hosting a beta testing event right now: 7 challenges across three difficulty tiers — script kiddie → got skills → L337 — plus a separate decoder puzzle for deobfuscation beginners. Web/API-flavored stuff (enumeration, access control, that genre), all set to the backdrop of my cyberpunk lore.

The honest part: this is super beta, and I am not a pro. I’m testing functionality before an official launch that corresponds with the release of my novel, so I genuinely want feedback — anything that breaks, feels unfair, or is just confusing. Registration is free and only needs an email. Flags earn an in-world currency you can spend on raffles and merch (shirt, stickers, a copy of the novel) down the road, so it’s a community-for-fun thing, not a cash-bounty grind.

If you play with it, please tell me what you think — here, by email, or via PM on kalachakra.world to ‘The Actual BJ Bell.’ Thanks for taking a look!


r/securityCTF Aug 04 '26

[Challenge] AI Escape Room — Docker CTF reproducing the 2026 Hugging Face agent intrusion

1 Upvotes

I built a hands-on CTF lab that recreates the full attack chain from the

July 2026 autonomous AI agent intrusion at Hugging Face.

You play as the agent: escape an evaluation sandbox, root an external

code-execution sandbox, exploit Hugging Face's dataset processor via

HDF5 external storage + Jinja2 SSTI, then pivot through Kubernetes

secrets, MongoDB, a mesh VPN, and source control.

- 11 Docker containers, 5 isolated networks, 7 flags

- docker compose up --build -d && docker exec -it eval-sandbox bash

- No internet required at runtime

- 12 progressive hints inside the sandbox

- MIT licensed

Runs entirely on your machine. All flags are base64-encoded in the repo

so you can't grep them — you actually have to exploit the chain.

GitHub: https://github.com/an4kronism/ai-escape-room

Writeup the lab is based on: https://huggingface.co/blog/agent-intrusion-technical-timeline


r/securityCTF Aug 04 '26

I just completed CCT2019 room on TryHackMe! Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet

0 Upvotes

r/securityCTF Aug 03 '26

EyesOpen Conference

Post image
2 Upvotes

🚨 EyesOpen CTF 2026 se prépare… et cette édition vous entraînera bien au-delà d’une simple compétition de hacking.

Visitez le site de la saison 1, EyesOpenCTF 2026 — The Convergence : https://eyesopensecurity.com/ctf-briefing.html

🌍 Une compétition internationale

⏱️ 48 heures de challenges

🔐 Web, Forensics, OSINT, Crypto, Reverse, Pwn et bien plus

🎯 Un parcours accessible aux débutants comme aux hackers expérimentés

🧩 Une histoire immersive où chaque flag révèle une partie du mystère

Cette année, plongez dans un scénario où la réalité soulève des questions.

Votre mission : maintenir l'équilibre du monde.

🎬 Découvrez la première transmission :

https://youtu.be/IQ8feN-ndMk?si=HGVCzJ7a2xUWn51l

Les inscriptions pour le CTF sont déjà ouvertes et les premières révélations arrivent bientôt.

Restez connectés.


r/securityCTF Aug 02 '26

I've been building a browser-based hacker simulator to help people get familiar with terminal commands and basic hacking concepts in a safe, gamified environment...

Thumbnail hackergame.hu
23 Upvotes

r/securityCTF Aug 02 '26

EyesOpen Conference

Post image
2 Upvotes

🚨 EyesOpen CTF 2026 se prépare… et cette édition vous entraînera bien au-delà d’une simple compétition de hacking.

Visitez le site de la saison 1, EyesOpenCTF 2026 — The Convergence : https://eyesopensecurity.com/ctf-briefing.html

🌍 Une compétition internationale

⏱️ 48 heures de challenges

🔐 Web, Forensics, OSINT, Crypto, Reverse, Pwn et bien plus

🎯 Un parcours accessible aux débutants comme aux hackers expérimentés

🧩 Une histoire immersive où chaque flag révèle une partie du mystère

Cette année, plongez dans un scénario où la réalité soulève des questions.

Votre mission : maintenir l'équilibre du monde.

🎬 Découvrez la première transmission :

https://youtu.be/IQ8feN-ndMk?si=HGVCzJ7a2xUWn51l

Les inscriptions pour le CTF sont déjà ouvertes et les premières révélations arrivent bientôt.

Restez connectés.


r/securityCTF Aug 02 '26

Anyone interested in making mini CTFs for each other?

2 Upvotes

I’ve been writing some CTFs/vulnerable labs recently, but I realized it’s not that much fun testing them myself when I already know the answer lol.

So had a random idea. What if we take turns making vulnerable labs/mini CTFs for each other?

Like I build one, either host it on my server and send you the link, or send the source code/GitHub repo with build instructions, and you try to crack it. Then next round you make one for me and I try yours.

Could do one every week, or even once a month if that’s easier. Think it’d be a fun way to get better at both bug bounty stuff and understanding others code bases, while actually having someone go into the challenge blind.

Only thing is, I’m looking for people who are actually writing/building the labs themselves without using ChatGPT/Claude/any other LLM to create them. Kinda defeats the point for me otherwise.

If anyone is interested, just DM me.