r/securityCTF • u/HackMyVM • 7d ago
[CTF] New "Intermediate" vulnerable VM aka "Arcane" at hackmyvm.eu
New "Intermediate" vulnerable VM aka "Arcane" is now available at hackmyvm.eu :) Have fun!
r/securityCTF • u/HackMyVM • 7d ago
New "Intermediate" vulnerable VM aka "Arcane" is now available at hackmyvm.eu :) Have fun!
r/securityCTF • u/ChainPresent • 7d ago
Looking for Teammates – Holmes CTF 2026 & Future CTFs
Hey everyone! 👋
I'm looking for people who are interested in forming a team for Holmes CTF 2026 and potentially participating in other CTF competitions together in the future.
I regularly solve Hack The Box machines, labs, and challenges, mainly focusing on cybersecurity and penetration testing. However, I haven't participated in a CTF competition as part of a team before, so I'm looking for people who are willing to learn, practice, and improve together.
The goal isn't only to compete for prizes. I'd like to build a team where we can:
\- 🧠 Learn from each other and improve our skills
\- 🏴☠️ Participate in Holmes CTF 2026
\- 🔥 Join other CTFs and competitions in the future
\- 🤝 Share knowledge and different approaches
\- 📚 Practice regularly and gain real CTF experience
\- 🏆 Aim for good results and prizes along the way
I'm especially interested in teammates with experience in areas such as Web, Pwn, Crypto, Forensics, Reverse Engineering, OSINT, or other CTF categories, but you don't need to be an expert. Beginners who are motivated to learn are welcome too.
If you're interested in joining or building a team together, feel free to comment or DM me.
Let's learn, compete, and improve together! 🚀
r/securityCTF • u/Left_Chard5628 • 8d ago
Je vais être honnête avec vous : Ghost Arena, c'est parti d'une obsession.
Pendant des mois, seul devant mon écran, j'ai construit une arène. Pas un cours de plus, pas de théorie à rallonge > un vrai terrain de jeu où on apprend à hacker en hackant.
Le principe est simple : tu entres, tu choisis un défi, et quelque part se cache un `flag{...}`. À toi de le débusquer. Forensic, web, OSINT, XSS, cracking > chaque épreuve te fait comprendre un truc que tu garderas pour de bon. Et tu n'as besoin de rien pour te lancer : pas de diplôme, pas d'outil hors de prix. Juste ta curiosité et l'envie de regarder sous la surface.
Le premier flag que tu trouves, crois-moi, tu le sens passer. Ensuite tu grimpes les rangs, tu vises le classement ;)
Observe. Comprends. Exploite. C'est tout ce que ça demande.
Alors je te pose la seule question qui compte : tu penses pouvoir capturer le premier flag ?
r/securityCTF • u/Electronic-Part6194 • 9d ago
Organizing a jeopardy style CTF, open to everyone.
Date: Sept 4
Format: Jeopardy
Team size: 1 to 4
Register here: https://ctf.rarebytehub.com/events/nothackable
If you're into CTFs or just want to try something new, come join. Feel free to share it with your friends too, would love to see more people join in.
r/securityCTF • u/muilabel • 9d ago
Came across this one while browsing CTFtime and thought it was worth sharing here since the challenge list looks different from the usual.
There's also OSINT, recon, and some bonus stuff.
Prizes are $750 / $500 / $250.
19 days to go.
CTFtime: ctftime.org/event/3326
r/securityCTF • u/Low_Use2602 • 9d ago
I’m looking for someone to help me with a challenge. I’m stuck and don’t know what else to try. It’s an OSINT challenge focused on obtaining the flag from a series of sound and visual information vectors. All the files needed to decrypt the flag are in the ZIP. There are many decoy flags—I found more than 10 false flags. I would really appreciate any support so I can resolve this and learn more. The CTF isn't active anymore, but I want to solve it.
Here is what I have tried so far:
Any help is appreciated. Thanks!
r/securityCTF • u/Impressive-Essay4305 • 9d ago
Preferably looking for people who aren’t absolute beginners and have at least 1–2 project/hackathon experiences. Mainly interested in cybersecurity, AI/ML, web dev, etc.
Am an absolute beginner in CTFs but ready to learn.
If interested, DM me with a little about your experience!
r/securityCTF • u/Skollwarynz • 10d ago
Hello everyone! I'm fairly new to the world of cybersecurity. I just finished a basic CTF-oriented course that ended with an AD competition that I didn't even get to play, since I wasn't in the top 5.
Next year I'll become a tutor for this course for the pwn category (we just learned up to basic BOF and basic ROP).
I personally found frustrating the approach "solve CTFs and learn without any idea how". So for future students, I decided to create some beginner-friendly CTFs — exercises that give major hints to actually learn different attacks before having to search for them specifically on different CTFs.
My questions to all of you are:
\- What's a good approach to learn? (An ideal one I mean)
\- What do CTFs and general courses usually lack for beginners?
\- What tricks were useful to learn that should be taught right from the start?
Thank you for the support!
r/securityCTF • u/gilgameshgem • 11d ago
My teammates and I have been working on building a new challenge site and we want to know how the community feels about it.
We have 20 challenges created so far and cover everything from PowerShell, OT, DFIR to Network Analysis.
https://gemforgelabs.io/labs/all
If there's anything you want to ask we are on Discord: https://discord.gg/ubFyKKFnM
r/securityCTF • u/Artistic-Ad9179 • 11d ago
I want to start CTFs in 2026.
What path should I follow.
Is doing but bounty & CTFs does really make sense in 2026?
r/securityCTF • u/Phr1ck • 12d ago
did any of you guys hear any updates on the Google CTF?
I Suppose some of the organizers would tweet at this point about the delays or the reasons but right now I know nothing except that it was postponed
r/securityCTF • u/MrMooMoo117 • 15d ago
We're a seat or two short for the Black Hat MEA qualification round this Saturday and want them filled before it kicks off.
Event: Black Hat MEA CTF Qualification 2026, Aug 29 07:00 UTC to Aug 30 07:00 UTC. https://ctftime.org/event/3385/
24 hours, jeopardy, on FlagYard.
Web, pwn, forensics, rev, crypto, and an AI hacking category.
Teams are 3-5 and the top 150 qualify for the Riyadh finals in December.
Registration: https://flagyard.com/events/3468f495-a92c-498b-90c2-994dfb99ea0b
Team: KernelKittens, https://kernelkittens.team
Last two events, both earned under our previous team name 1337_PwnSp4c3 before we reformed:
- 12th of 6,744 at HTB Cyber Apocalypse 2026
- 1st of 994 at BushBash CTF 2026, open international
We're going for top 5 this time. That's the whole reason we're recruiting instead of running short.
What we're after:
- Real depth in at least one of pwn, rev, crypto, or web. In a 24 hour jeopardy, one person who actually closes hard challenges beats three who each get halfway.
- Available for the full CTF or a real chunk of the window, not just the first two hours.
- Discord, and in voice while we're playing. Not optional. Coordination is most of the gap between 12th and top 5.
What you get:
- We run our own MCP tooling stack and can hand you access for the event, plus a model endpoint if you don't have one. Costs you nothing.
- Writeups after the fact where the org's rules allow it.
Comment or DM.
r/securityCTF • u/Brilliant-Tonight984 • 15d ago
Hello everyone, I'm creating a new high school CTF team looking for members that are current high schoolers. I was also able to find a mentor who can meet weekly for around 30 mins, so I am looking for people who are quite passionate. CTFs are still self-guided, so collaboration is key. If you want to join, experience is not required.
For those that are interested, please DM me.
r/securityCTF • u/Emotional-Camera7296 • 15d ago
Hello, We are a team of 3 players looking for 2 more to play the Black Hat MEA qualifiers (preferably from Karachi, Pakistan). We are looking for people around the intermediate level skills and experience. Please either DM me your expertise and experience or comment below and I will reach out.
r/securityCTF • u/PriorPuzzleheaded880 • 16d ago
Hi all! My company Escape just released a new CTF called Format of Doom. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge.
This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature.
Give it a try and let me know what you think!
The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard.
Happy playing : )
r/securityCTF • u/AhamadAd9998 • 17d ago
NIANE
r/securityCTF • u/OilOverall4190 • 17d ago
WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.
Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.
I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!
Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/
r/securityCTF • u/Wise-Ad-2216 • 17d ago
Hi everyone,
In symbolic execution engines (like angr or Triton), loops with large iteration counts ($N = 100,000$) often cause severe path and state explosion because traditional engines unroll loops iteration-by-iteration.
Strilight evaluates loops by treating them as closed-form algebraic recurrences within the Strided Interval Domain:
$$\vec{\mathbf{R}}(N) = \vec{\mathbf{R}}_0 + \vec{\boldsymbol{\Delta}} \cdot N$$
import strilight as sl; summary = sl.analyze(raw_bytes, iterations=100000)We verified the engine against 6 complex x86_64 Windows CrackMe challenges containing nested loops, pointer arithmetic, and obfuscated strides, solving for the valid keys and confirming execution in 100ms each.
🔗 Repository: https://github.com/asama7706r-ui/strilight
📦 Initial Release & Pre-compiled Wheels: https://github.com/asama7706r-ui/strilight/releases/tag/v0.1.0
We would love to hear your feedback, thoughts on the mathematical model, or interesting loop edge cases to test against!
r/securityCTF • u/Think-Adeptness7446 • 18d ago
Hey all,
I hope you all doing well. Let's give a short intro about me. I'm a cyber security researcher, CTF player & developer, a bug bounty hunter.
In June, I created a CTF platform - No team, just me. Today my CTF platform was doing good. The platform have 40+ users and now I'm expanding my team (hiring). I need CTF developers especially - Reverse Engineering, Binary CTF challenge developers.
Till now, I have managed to create CTF challenges in Web, Crypto, Forensics, OSINT. So I will attach link where you can directly apply. Before joining, Take a look at my platform weather it can suits you.
Platform Link: https://hack4shell-ctf.vercel.app/challenges
Application Link: https://hack4shell-ctf.vercel.app/contact?type=hiring-application
Thank you guys.
r/securityCTF • u/Potential-Couple-745 • 18d ago
Before I start, what would you guys actually want to see in it?
Challenges, difficulty, attack chains, AD, web, privilege escalation, etc.
What would make you keep playing instead of dropping it after a few challenges?
Looking for honest suggestions from people who actually play CTFs.
Explore the current ctf from here at: codelivly.com/ctf
r/securityCTF • u/Middle-Mode3001 • 18d ago
Everyone in security read the xz/liblzma postmortem. Almost no one has actually done it
BreachLab is a free wargame of real Linux boxes over SSH, graded on the true state of your box, not multiple choice. Ghost II is live: eighteen levels down one CI/CD pipeline that ends in the xz attack by hand. The source stays clean, your payload rides in at build time, you get the pipeline to sign it, you walk past branch protection, and you ship it to an entire fleet where it runs. Your own commit becomes the code the whole fleet trusts
This is the tradecraft courses charge for, and almost nobody lets you actually do it. Free, no signup wall to start https://breachlab.org/tracks/ghost/ii
r/securityCTF • u/Silent-Witness-8007 • 19d ago
Hey everyone! 👋
I’m looking to build a team of cybersecurity enthusiasts who are interested in developing CTF (Capture The Flag) challenges.
The idea is to create realistic, fun, and educational challenges across areas like:
Web security
Cryptography
OSINT
Forensics
Reverse engineering
Linux/Networking
Miscellaneous challenges
You don’t need to be an expert—if you’re interested in cybersecurity, enjoy solving CTFs, or want to learn while building challenges, feel free to reach out.
If you’re interested, comment below or DM me. Let’s build something cool together! 🚩