Changelog
Follow up on the latest improvements and updates.
RSS
new
Labs
Academy
Profile
Account
Badges are now part of your HTB Profile
Your HTB Profile now includes an automated Badges showcase that highlights your achievements across HTB Labs and Academy. Clicking any badge reveals the full artwork, completion criteria, and global rarity statistics. This update helps you track your total progress and provides a public-facing snapshot of your milestones.

new
Labs
Academy
Welcome our new HTB XP System 🎉
We have successfully rolled out HTB XP, a cumulative points system that tracks lifetime growth across the entire HTB Labs and Academy platforms.
Key Updates:
Cumulative XP:
XP is now awarded for Machines, Challenges, Academy Modules and Paths. This score is non-deductible and reflects your lifetime activity. More content integration is coming soon.1.3x Active Labs Multiplier:
Completing Active Labs now grants an automatic 1.3x XP bonus.New and Expanded Rank Grades:
Climb through 7 new ranks and 3 sub-grades, and more than 100 levels for more frequent rewards, all the way to Grandmaster.Weekly Streaks:
A streak advances when 200 XP is earned within a calendar week (Monday 00:00:00 UTC to Sunday 23:59:59 UTC).Streak Savers:
Labs VIP/VIP+ (Monthly and Annual) and Academy Annual subscribers now automatically receive Streak Savers every month (Max 3 held at once).new
Academy
Enterprise
Offensive
Introducing the new HTB Certified Offensive AI Expert (HTB COAE)

The HTB COAE is a professional certification designed to validate advanced skills in AI red teaming and is now available on HTB Academy and HTB Enterprise plans. It serves as the final assessment for the AI Red Teamer Job-Role Path, which was developed in collaboration with Google.
The certification consists of a 7-day practical engagement where candidates must assess a complex AI-driven infrastructure. The exam evaluates proficiency in adversarial ML, LLM output exploitation, and AI system security. A commercial-grade technical report is required for successful completion.
If you are an individual, you can access the full path and the HTB COAE exam through our Silver Annual subscription on HTB Academy.
For those of you hacking as part of a team, the certification and its accompanying path are available for all Grow and Scale plans on the HTB Enterprise Platform. Want to explore the right plan for your team? Book a demo with us here.
new
Academy
Enterprise
Defensive
Introducing the Persistence Tradecraft Analysis module
A new
defensive module
, Persistence Tradecraft Analysis, is now available on HTB Academy. This course provides an in-depth look at Windows persistence mechanisms, covering everything from their role in the attack lifecycle to detection and investigation.Throughout this module, you will explore how adversaries abuse legitimate system features like Scheduled Tasks, Windows Services, and Registry-run keys to ensure that malicious code executes automatically. The content focuses on identifying system artifacts left behind by attackers and translating that knowledge into reliable, effective detection rules for real-world environments.

new
improved
Academy
Profile
Introducing public certificate pages
HTB Academy certificate holders now have access to dedicated, public-facing pages for every certification earned. These pages offer a professional, verifiable way to showcase your technical expertise to employers and the community.
How it works:
Users can access these pages directly through their HTB Profile. Clicking on any earned certificate credential takes you to that certificate's dedicated public page.Key features include:
- Unique public URL for every earned certification.
- You can share it on LinkedIn and social media.
- Verification to confirm the authenticity of your achievement.

new
improved
Academy
HTB Academy 2.0 platform migration
The HTB Academy platform has officially migrated to Academy 2.0. This update establishes the new interface as the primary environment for all learners. It’s faster, smoother, and built to power the next wave of content, features, and skill progression.
The previous interface has been retired to ensure a unified experience across the platform.
new
Labs
Academy
Capture The Flag
HTB Profile is now live
HTB Profile introduces a centralized view of your achievements and skills across Hack The Box platforms.
With the HTB Profile, you can:
- Create a complete overview of your acquired skillset, inside and outside of HTB
- Track certifications, CTF events, and all HTB achievements in one place.
- Access an automatically updated profile based on platform activity.
- Share your profile with peers and recruiters
Learn more about it here.

new
Academy
Enterprise
Defensive
Learn how attackers abuse core Windows mechanisms in new Academy module
The Privilege Escalation Tradecraft Analysis module covers the analytical study of privilege escalation tradecraft on Windows, from its role in the attack lifecycle to how it can be detected and investigated. While completing this module, you will analyze real-world techniques and exploits to understand how they work internally and learn how to translate this knowledge into effective and reliable detection strategies.
Key learning outcomes:
- Exploring where Windows privilege escalation fits within the attack lifecycle and how elevated access enables attacker objectives
- Breaking down Windows privilege escalation tradecraft by examining abuse of UAC, access tokens, services, kernel drivers, and COM infrastructure
- Recognizing and deconstructing real-world Windows privilege escalation techniques, including UAC bypasses, access token manipulation, and service account abuse
- Leveraging reverse engineering, debugging, and API call flow analysis to reveal how privilege escalation exploits function under the hood
- Connecting privilege escalation behavior to MITRE ATT&CK and converting technical insight into practical detection, investigation, and response strategies

new
Academy
Enterprise
Offensive
Introducing the HTB Certified Wi-Fi Pentesting Expert (CWPE)
HTB CWPE is a hands-on, cloud-based certification that brings wireless security training into the modern age. Paired with the WiFi Penetration Tester Job-Role Path, it's one of the few programs to offer a holistic curriculum, real-world practice with WPA3 attacks, and doesn’t require specific hardware or complex setups.
Included in the job-role path and certification are learning material and hands-on labs that focus on how attackers actually approach wireless environments: reconnaissance, exploiting weak configurations, credential attacks, evil twins, captive portals, and full corporate Wi-Fi attack chains for anyone who wants to properly understand and test wireless security, not just check a box.
Get started with HTB CWPE here or learn more on our blog here.

new
Academy
Enterprise
Offensive
Explore real-world Android vulnerabilities in new Academy module
The
Android Attacks
module provides a structured, hands-on introduction to the most common and impactful security risks affecting modern mobile applications. By completing the module, you will learn how mobile vulnerabilities arise, how to categorize them based on known mobile security frameworks, how they are exploited in real applications, and how to identify and remediate them using techniques learned in the previous modules.Key learning outcomes:
- Understanding the OWASP Mobile Top 10 and how modern mobile security risks span apps, APIs, networks, and cryptography
- Analyzing Android application architecture to identify key mobile attack surfaces and misconfigurations
- Identifying and exploiting Android vulnerabilities mapped to the OWASP Mobile Top 10, including auth, storage, communication, and cryptography flaws
- Applying analysis techniques to uncover insecure storage, weak crypto, exposed components, and reverse-engineering gaps
- Mapping mobile vulnerabilities to real attacker behaviors and applying practical remediation and hardening strategies

Load More
→