Changelog
Follow up on the latest improvements and updates.
RSS

Thinking about testing new skills before your next hands-on engagement or certification? Of course you are. Good news: Hack The Box (HTB) has reloaded our stock of Pro Labs with new scenarios to build confidence in your ability to succeed, and with a big discount for the annual plan running until the end of November.
Get access to 26+ Pro Labs and 25% discount on the annual plan using this code on checkout:
NOVPROLABSANNUAL25OFF
. Offer valid until 30 November 2025, 23:59 EET.
If you are interested in knowing more about Pro Labs and the new additions, read all about it here →

Kickstart your certification journey with the Silver Annual subscription on HTB Academy. Now, we're including an extra HTB CJCA exam voucher, so you can learn the basics of cybersecurity and then proceed to the certification of your choice!
This extra voucher is also available on the Gold Annual plan.
The HTB CJCA certification was designed to help beginners break into cybersecurity with practical, hands-on training. By including it in our annual plans, we’re making it easier to go from zero to pro, all within Hack The Box.
Now, one annual subscription supports your entire certification path:
- Kickstart your journey with HTB CJCA
- Climb higher with our core and specialized certifications
It’s more value, more progress, and more recognition, all rolled into your HTB plan.
P.S. If you bought your Silver or Gold Annual subscription recently, don't worry! We are also adding this extra voucher for annual plan purchases after September 1, 2025.
improved
Labs
Features
Discover relevant Labs faster than ever
Exploring Labs just got a lot easier!
Our new improved search functionality helps you find what you’re looking for based on content relevance, not just content names. Now, if you type Active Directory, you’ll instantly see all related challenges and machines rather than guessing and scrolling to find what you were looking for.
This update makes it easier to:
- Discover new content connected to your learning goals
- Quickly find Labs aligned to specific topics or frameworks
- Spend less time searching and more time playing

new
Capture The Flag
Offensive
Defensive
Build your forensics and blockchain skills with two new CTF packs
Two new CTF packs have just dropped, designed to build hands-on expertise in forensics and blockchain.
Cyber Defense Analyst – Essentials
Featuring nine new challenges (with one more coming soon!) for entry-level cyber defense analysts, this pack includes a diverse set of forensics challenges designed to emulate real-world attack scenarios across network, memory, and host-based evidence. Players will investigate complex, multi-stage intrusions ranging from CVE exploitation and phishing to memory-based evasions and malware persistence.
Blockchain Essentials
Complete with 10 challenges built for entry-level penetration testers and security-minded developers, this pack introduces players to the fundamentals of Ethereum smart contracts, transaction mechanics, and on-chain investigation through a progression of realistic, hands-on challenges. From basic account and RPC interaction to reading contract storage and interacting with deployed contracts, participants will learn how blockchain primitives and common Solidity patterns work in practice and how insecure designs can be abused.


improved
Enterprise
New content card experience is live on HTB Enterprise Platform
We’ve just introduced a major enhancement to how content is displayed across the HTB Enterprise Platform designed to make browsing, managing, and understanding training content faster, clearer, and more consistent.
What’s new?
- A cleaner, more visual grid view- Content now appears in a grid layout for easier scanning and a more intuitive visual experience
- Consistent look and feel across all content types- Labs, modules, and scenarios now follow the same structure and design so you always know what to expect
- Unified card behavior- Clicking on any content card opens a modal with detailed descriptions, associated skills, and important information without navigating away from your current page
With this update, it’s now easier to:
- Quickly understand what each lab or module includes
- Identify the skills you or your team will build
- Manage and explore content without jumping between pages
The new content cards are currently available in Dedicated Lab view, Dedicated Lab manage, and Academy Lab view with more improvements to other platform pages coming soon!


new
Academy
Enterprise
Defensive
Master Linux process injection and defenses in new Academy Module
The
Linux Process Injections & Detections
module introduces various Linux process injection techniques, from basic to advanced, from both local and remote standpoints. It focuses on how ELF sections and dynamic-linking structures can be abused for execution flow hijacking and evasion while overriding potential memory protections. It also explores the various detection opportunities and dynamic analysis techniques that can be employed for prevention and mitigation tasks.Key learning outcomes:
- Understand key ELF structures and procfs pseudo-files commonly involved in process injection techniques
- Explore techniques such as return address overwriting and stack based hijacking used in binary exploitation
- Learn how to use the ptrace syscall offensively and defensively
- Discover how auditd can support detection and analysis of process injection techniques

new
Enterprise
Offensive
Practice covert Active Directory operations with new Professional Lab scenario
Wutai
mirrors the structure, complexity, and progression of a real-world Active Directory (AD) penetration test or red team engagement. In this scenario, you’ll practice operating covertly without triggering detection mechanisms. Along the way, you'll see detections in near real time and be able to tune your actions accordingly.After completing the 12 machines and 12 flags included in the lab, you’ll understand how initial access through weak credentials can escalate to full Enterprise Admin control while experiencing first-hand how stealthy movement, credential abuse, and certificate exploitation allow teams to test resilience without touching production.
Learning outcomes include:
- Network & Active Directory Enumeration
- Active Directory & Custom Exploitation
- Active Directory Certificate Services
- Lateral Movement across multiple Forests
- Bypassing EDR Solutions
- Reverse Engineering
- Operating covertly

new
Enterprise
Offensive
Get hands-on in Windows environments with two new Professional Lab scenarios
Two new time-efficient Professional Lab scenarios are now live:
Sidecar
and Push
.Sidecar and Push are small Active Directory scenarios that simulate real-world Windows environments and contain two machines and two flags each. Sidecar simulates PKI abuse, detecting certificate-based persistence, and how shadow credentials enable stealthy lateral movement. Push covers advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.
You’ll gain practical skills in:
- Shadow credential and Kerberos attacks
- Abusing SeTcbPrivilege privilege and .lnk files
- Crafting malicious ClickOnce deployments
- Coercing NTLM authentication with SCCM
- ADCS Golden Certificate attacks
- Advanced lateral movement techniques in Windows environments


improved
Labs
Academy
Capture The Flag
Discord account linking just got a whole lot smoother
We’ve just upgraded how you connect your Hack The Box (HTB) account to Discord, and made it easier than ever to get verified.
✅ No HTB Labs? No problem.
Verification now runs through your HTB Account! To connect, go to the Security Settings section of your HTB Account Portal. Scroll down to the Discord Account section and click Connect.

🌟 Why link your HTB Account to Discord?
- Instantly sync your HTB username so staff and community members can spot you.
- Show off your Hacker Rank directly on your profile.
- Unlock member-only channels and join the inner circle on the official HTB server. All HTB Academy channels on Discord now require verification. If you’re already linked, we recommend re-linking to refresh your roles and get the latest access.
👉 Follow the updated steps in our Welcome Guide here!
improved
Academy
Academy 2.0 (Beta) is live!

We’ve given HTB Academy a major facelift to boost your learning experience. Try our Academy 2.0 (Beta) and enjoy:
- Improved accessibility: Higher contrast, clearer focus states, better keyboard nav.
- Smoother UX: Streamlined workflows, updated visuals, fewer distractions.
- Mobile-friendly design: Fully optimized for phones and tablets.
- Faster performance: Quicker load times and smooth interactions.
- Modern tech stack: Built for speed, security, and future features.
Load More
→