Changelog

Follow up on the latest improvements and updates.

RSS

In this special Season, you will be running a red team engagement, set at HTB International Airport, and testing various assets across an airport network that might be vulnerable.
9 weeks. 9 Machines. One leaderboard. Kicks off on September 26th!
HTB Seasons brings competitive hacking to the forefront. Complete weekly cybersecurity labs, earn points, and climb the Seasonal leaderboard as the challenges roll out.
It’s free to join and open to the entire HTB community.
The final Sherlock of the season is live on HTB Enterprise Platform.
A forged beacon order has been staged inside a satellite broadcast queue using CFDP. You must analyse the uplink PCAP, spot the fake transmission, and stop an adversary from hijacking the fleet before the window closes.
The final Sherlock of the season is waiting...
CosmicCorruption
We are bringing 150+ investigation scenarios from the LetsDefend platform directly to HTB Labs. We are releasing them as 16 new retired Sherlocks every week from the end of August 2026 until October 15th. Each batch of Sherlocks will be free to play for a full month following its release date.
This gives blue teamers and defenders a steady stream of fresh, real-world analytical scenarios to investigate and solve.
Screenshot 2026-09-15 at 16
CTFs now earn you XP
Every CTF you play now contributes XP toward your HTB progression, reflected currently on your HTB Profile. Since CTFs are team efforts, XP is split among the participating team members.
Screenshot 2026-09-15 at 11
Introducing Streak Protocol
Streak Protocol is a new CTF mini-game built for quick, competitive knowledge testing.
Answer cybersecurity questions against the clock, build your streak, and compete with other players on the event leaderboard. The game is powered by 1,300+ questions generated from Marketplace content and is available on both desktop and mobile.
CTF Quiz

improved

new

Labs

Academy

Profile

Mobile

HTB Profile experience updates

We've just refreshed the HTB Profile experience to give you a cleaner, more streamlined way to showcase your cybersecurity achievements.
Updates include:
  • Removed all empty section spaces across public profiles for a cleaner layout.
  • Added embedded social sharing buttons to easily showcase your profile and HTB Academy Certifications pages to your networks.
  • Added a new activity Matrix to display your activity and consistency across the HTB Ecosystem.
Screenshot 2026-09-14 at 4
Your mission started in June..You joined Phoenix task force to save Earth. Now the final ACT begins, and you need to save the mission to Mars.
GNU Day is your first challenge.
Phoenix has intercepted a replacement uplink module destined for Zenium’s orbital ground segment. But before any command can reach Mars, it must pass Phoenix’s authority checks.
Analyze the uplink validation system, uncover weaknesses in its trust chain, bypass the authority controls, and recover the classified mission data before control of the Mars program changes hands.
Catch up on previous Operation Red Horizon scenarios
GNU Day
How far can you take a compromised Azure environment?
Altairus is an advanced Azure offensive lab built for experienced cloud security professionals and red teamers looking to push beyond the fundamentals of Entra ID, Azure RBAC, and hybrid identity.
Step into the environment of Omni Multinational, a global trade management company with a mature Azure footprint connected to its on-premises infrastructure. Starting with no credentials and no prior knowledge, you’ll need to uncover weaknesses in identities, applications, secrets, and trust relationships and turn small footholds into a full-scale compromise. Altairus challenges you to navigate the boundaries between cloud and on-premises infrastructure while putting advanced Azure attack techniques to the test.
Expect to tackle:
  • Azure enumeration
  • Authentication and credential abuse
  • Cloud application and serverless security
  • Secrets and data protection
  • Azure Automation and DevOps security
  • Active Directory privilege escalation and lateral movement
  • Exploitation of cloud misconfigurations
  • Phishing and social engineering
15 Flags. Advanced difficulty.
altairus changelog (1)

new

Enterprise

Offensive

Defensive

New Machine: Nemesis | Operation Red Horizon

The first Enterprise Season closes ACT II: Proxy Crown with Nemesis (Machine).
Arodor is days from launching its Mars rocket. Zenium wants it grounded and you're the one breaking into Arodor's machinery testing facility to compromise their OT controllers.
Nemesis is a Linux machine set in an assumed breach scenario, starting with access to a CCTV portal overlooking Arodor's Evaluation Compound. From there, you'll need to work through industrial control protocols, chain together an unexpected credential leak, and find your way to full control of the OT controller.
Catch up with the previous scenarios of Operation Red Horizon before the final ACT!
Nemesis (1)
Progress just got more rewarding. You can now earn experience points by completing content on HTB Enterprise, build weekly streaks, and reach new levels, ranks, and grades as you develop your skills. XP and Streaks connect your supported activity across the HTB ecosystem into one visible progression journey.
  • Earn
    experience points
    and watch your progress unlock new levels, ranks, and grades across HTB.
  • Build and maintain your
    streak
    by staying active each week, turning consistent practice into visible momentum.
Screenshot 2026-08-26 at 6
The first Enterprise Season continues the ACT II: Proxy Crown with a new Sherlock, Relay of Deceit.
This time, the focus shifts to the software supply chain. Hidden inside what appears to be a legitimate npm package is malicious code designed to evade review, perform host reconnaissance, and quietly exfiltrate sensitive data over DNS.
Players will practice how to:
  • Analyze npm packages safely without executing untrusted code
  • Uncover malicious behavior hidden in JavaScript
  • Investigate covert DNS-based communication
  • Reconstruct attacker activity from network traffic
  • Assess the impact of a software supply-chain compromise
Relay of Deceit
Load More