Changelog

Follow up on the latest improvements and updates.

RSS

Effective adversary emulation begins long before the first packet is sent.
This module covers the planning and reconnaissance that precede a red team engagement, exploring how operators decide which adversary to emulate and how they gather information about a target while remaining undetected. As organizations mature their defenses, the ability to plan a realistic engagement and conduct reconnaissance without being detected is what separates a convincing emulation from a noisy one.
1200x630 (1)
Train across the entire cyber operational spectrum with a single membership. HTB PRO combines enterprise-grade offensive and defensive hands-on training directly inside HTB Labs, giving you full VIP+ access, 10 flagship Pro Lab environments, and upcoming SOC Range simulations.
What is included:
  • 10 flagship Pro Labs: Access real-world enterprise network environments like Dante, Zephyr, Offshore, RastaLabs, and Shinra.
  • Full VIP+ access: Get unlimited access to retired Machines, Challenges, and 150+ new Sherlocks from the LetsDefend platform.
  • Pro Lab preparation tracks: Master enumeration, privilege escalation, and pivoting with prerequisite paths built for Dante, Zephyr, Wanderer, and Offshore.
  • SOC Range (coming Q4 2026): Work real-world security analyst shifts with live alert queues, SIEM logs, playbooks, and one-click containment actions.
HTB PRO is available now on HTB Labs for $49 per month or $490 per year. Existing VIP+ options remain active alongside this subscription.
Learn more here.
👉 Get started with HTB PRO here
Horizontal - HTB Pro Plan Blog
The 1st HTB Enterprise Season comes to an end with Uplink, a Hard Windows Machine.
Investigate a compromised satellite ground segment, uncover weaknesses in its command-signing pipeline, and determine whether forged commands can reach privileged execution paths.
Skills covered:
  • ECDSA cryptographic weaknesses and private-key recovery
  • Source-code review and Git repository reconnaissance
  • Windows lateral movement and privilege escalation to SYSTEM
New to Operation Red Horizon? Catch up on previous scenarios
Uplink (2)
In this special Season, you will be running a red team engagement, set at HTB International Airport, and testing various assets across an airport network that might be vulnerable.
9 weeks. 9 Machines. One leaderboard. Kicks off on September 26th!
HTB Seasons brings competitive hacking to the forefront. Complete weekly cybersecurity labs, earn points, and climb the Seasonal leaderboard as the challenges roll out.
It’s free to join and open to the entire HTB community.
The final Sherlock of the season is live on HTB Enterprise Platform.
A forged beacon order has been staged inside a satellite broadcast queue using CFDP. You must analyse the uplink PCAP, spot the fake transmission, and stop an adversary from hijacking the fleet before the window closes.
The final Sherlock of the season is waiting...
CosmicCorruption
We are bringing 150+ investigation scenarios from the LetsDefend platform directly to HTB Labs. We are releasing them as 16 new retired Sherlocks every week from the end of August 2026 until October 15th. Each batch of Sherlocks will be free to play for a full month following its release date.
This gives blue teamers and defenders a steady stream of fresh, real-world analytical scenarios to investigate and solve.
Screenshot 2026-09-15 at 16
CTFs now earn you XP
Every CTF you play now contributes XP toward your HTB progression, reflected currently on your HTB Profile. Since CTFs are team efforts, XP is split among the participating team members.
Screenshot 2026-09-15 at 11
Introducing Streak Protocol
Streak Protocol is a new CTF mini-game built for quick, competitive knowledge testing.
Answer cybersecurity questions against the clock, build your streak, and compete with other players on the event leaderboard. The game is powered by 1,300+ questions generated from Marketplace content and is available on both desktop and mobile.
CTF Quiz

improved

new

Labs

Academy

Profile

Mobile

HTB Profile experience updates

We've just refreshed the HTB Profile experience to give you a cleaner, more streamlined way to showcase your cybersecurity achievements.
Updates include:
  • Removed all empty section spaces across public profiles for a cleaner layout.
  • Added embedded social sharing buttons to easily showcase your profile and HTB Academy Certifications pages to your networks.
  • Added a new activity Matrix to display your activity and consistency across the HTB Ecosystem.
Screenshot 2026-09-14 at 4
Your mission started in June..You joined Phoenix task force to save Earth. Now the final ACT begins, and you need to save the mission to Mars.
GNU Day is your first challenge.
Phoenix has intercepted a replacement uplink module destined for Zenium’s orbital ground segment. But before any command can reach Mars, it must pass Phoenix’s authority checks.
Analyze the uplink validation system, uncover weaknesses in its trust chain, bypass the authority controls, and recover the classified mission data before control of the Mars program changes hands.
Catch up on previous Operation Red Horizon scenarios
GNU Day
How far can you take a compromised Azure environment?
Altairus is an advanced Azure offensive lab built for experienced cloud security professionals and red teamers looking to push beyond the fundamentals of Entra ID, Azure RBAC, and hybrid identity.
Step into the environment of Omni Multinational, a global trade management company with a mature Azure footprint connected to its on-premises infrastructure. Starting with no credentials and no prior knowledge, you’ll need to uncover weaknesses in identities, applications, secrets, and trust relationships and turn small footholds into a full-scale compromise. Altairus challenges you to navigate the boundaries between cloud and on-premises infrastructure while putting advanced Azure attack techniques to the test.
Expect to tackle:
  • Azure enumeration
  • Authentication and credential abuse
  • Cloud application and serverless security
  • Secrets and data protection
  • Azure Automation and DevOps security
  • Active Directory privilege escalation and lateral movement
  • Exploitation of cloud misconfigurations
  • Phishing and social engineering
15 Flags. Advanced difficulty.
altairus changelog (1)
Load More
→