Changelog

Follow up on the latest improvements and updates.

RSS

The first Enterprise Season continues the ACT II: Proxy Crown with a new Sherlock, Relay of Deceit.
This time, the focus shifts to the software supply chain. Hidden inside what appears to be a legitimate npm package is malicious code designed to evade review, perform host reconnaissance, and quietly exfiltrate sensitive data over DNS.
Players will practice how to:
  • Analyze npm packages safely without executing untrusted code
  • Uncover malicious behavior hidden in JavaScript
  • Investigate covert DNS-based communication
  • Reconstruct attacker activity from network traffic
  • Assess the impact of a software supply-chain compromise
Relay of Deceit
CTF admins can now access scenario writeups directly from the Content Library while building an event. Instead of selecting challenges based only on titles, descriptions, and difficulty, admins can review the intended solution path before adding content, making it easier to understand what each challenge tests and whether it fits the event's goals.
Choose challenges with more confidence and match content to your goals by validating that each challenge tests the right skills for your audience and training objectives.
Screenshot 2026-08-19 at 6
HTB's first Enterprise Season enters its next phase.
Your search for Arodor's proxy network now leads into a compromised settlement environment, where exposed identities and excessive cloud permissions hide a chained privilege-escalation path.
Take on Silent Market Raid, a new AWS Challenge where you'll enumerate cloud resources, abuse IAM trust relationships, and uncover how seemingly harmless disclosures can lead to complete compromise.
Continue the mission and begin Act II: Proxy Crown.
___________________________________
Need to catch up?
Complete the scenarios from Act I: Gridfall Signals.
Silent Market Raid
We have added a brand-new Satellite category, featuring nine progressive Challenges created in direct partnership with aerospace cybersecurity firm VisionSpace.
This track covers satellite system architecture, main communication protocols, and common attack vectors. Content ranges from Very Easy to Hard difficulty, offering practical exposure to realistic scenarios inspired by real-world satellite software and infrastructure. Available now across both HTB Labs and the Enterprise Platform.
Satellite Exploitation Track_1200x675

improved

Capture The Flag

Defensive

Threat Range

Configurable SLAs & Dispatch pacing for Threat Range events

Threat Range events are now more flexible.
Admins and Event managers can now customize alert dispatch pacing and response-time SLAs, making it easier to tailor exercises to different team skill levels, operational workflows, and event durations.
What's new?
  • Configure how quickly alerts are dispatched throughout an event.
  • Customize response-time SLAs for both alerts and tickets.
Use HTB's recommended defaults or align timings with your organization's internal SLAs and operating procedures.
threat range
AI models do not operate in isolation. An agent consists of the model paired with host-side code that validates tool proposals, communicates with external systems, and controls when the execution loop terminates. Relying strictly on system prompts for security leaves systemic vulnerabilities that attackers can exploit.
In this new Medium-difficulty module available on HTB Academy and HTB Enterprise, you will construct that host-side orchestration code yourself. You will learn how to enforce safety decisions there, not in the prompt.
1200x630 - AI Literacy - Agents
Administrators can now control the sequence of content assigned to a Space, making it easier to build structured workforce development programs that guide learners through deliberate, role-aligned skills journeys.
From the Space’s Content tab, open Assigned Content. Enter
Reorder
mode to drag and drop content cards or update their numeric position fields, then make sure to Save your order selection.
Create deliberate learning paths across modules, challenges, labs, and Sherlocks.
Untitled (Sat Jul 25 2026) (2)
We integrated 191 modules from LetsDefend into the HTB Academy library to expand our defensive and foundational cybersecurity curriculum. This launch increases HTB Academy's defensive content by more than 500%, making comprehensive blue team skills accessible under Tier 0 and Tier 1 access.
Key Updates:
  • 191 Modules Added: Includes 16 Tier 0 modules and 175 Tier 1 modules (166 defensive and 25 general security modules).
  • 3 New Skill Paths: Added dedicated paths for CompTIA Security+ Preparation, Programming for Cybersecurity, and Google Cybersecurity Certificate Preparation.
  • New Badges: We've also included new content completion badges for these modules to make sure all your effort is recognized.
  • Subscription Integration: All new content is made accessible through standard HTB Academy subscription plans without requiring separate add-on subscriptions.

new

Enterprise

Offensive

Defensive

Operation Red Horizon continues with Zeek

A compromised mission operations environment has exposed weaknesses across cloud infrastructure, application security, and containerized workloads.
Deploy into Zeek, a new Linux Machine where you'll enumerate AWS resources, investigate LocalStack services, exploit a vulnerable Lambda function, and pivot from cloud access to full host compromise through Docker.
Continue Act I: Gridfall Signals and uncover the next piece of Arodor's campaign.
Zeek
Following the acquisition of LetsDefend, we have massively expanded your defensive security training.
You can now develop and validate defensive capabilities through a broader combination of structured learning paths, hands-on investigations, and realistic SOC simulations across every stage of the cyber workforce journey.
  • Access 232+ Blue Team modules, representing a 632% expansion in defensive learning
  • Investigate with 127 new Sherlocks (70% more investigation scenarios)
  • Build skills across eight Blue Team job roles, with new and expanded coverage in Cloud Security, DFIR, Malware Analysis, Detection Engineering, and ICS.
Lets Defende Academy Releases - 1080x1350 (1)
Load More