Changelog

Follow up on the latest improvements and updates.

RSS

We have introduced XP and Activity Streaks directly to the HTB Profile. This update allows you to highlight your continuous learning and hands-on skills to the community and potential employers.
Screenshot 2026-05-18 at 10
We have added two new preparation tracks to Hack The Box (HTB) Labs to help users prepare for our web security certifications.
The HTB Certified Web Exploitation Specialist (HTB CWES) preparation track builds a foundation in identifying and exploiting common web vulnerabilities. For those looking for a deeper dive, the HTB Certified Web Exploitation Expert (HTB CWEE) preparation track focuses on advanced techniques and chaining vulnerabilities in complex, real-world scenarios.
Both tracks consist of hands-on challenges designed to bridge the gap between theory and exam performance.
Screenshot 2026-04-27 at 17

new

Labs

Academy

Profile

Account

Badges are now part of your HTB Profile

Your HTB Profile now includes an automated Badges showcase that highlights your achievements across HTB Labs and Academy. Clicking any badge reveals the full artwork, completion criteria, and global rarity statistics. This update helps you track your total progress and provides a public-facing snapshot of your milestones.
image
We have successfully rolled out HTB XP, a cumulative points system that tracks lifetime growth across the entire HTB Labs and Academy platforms.
Key Updates:
Cumulative XP:
XP is now awarded for Machines, Challenges, Academy Modules and Paths. This score is non-deductible and reflects your lifetime activity. More content integration is coming soon.
1.3x Active Labs Multiplier:
Completing Active Labs now grants an automatic 1.3x XP bonus.
New and Expanded Rank Grades:
Climb through 7 new ranks and 3 sub-grades, and more than 100 levels for more frequent rewards, all the way to Grandmaster.
Weekly Streaks:
A streak advances when 200 XP is earned within a calendar week (Monday 00:00:00 UTC to Sunday 23:59:59 UTC).
Streak Savers:
Labs VIP/VIP+ (Monthly and Annual) and Academy Annual subscribers now automatically receive Streak Savers every month (Max 3 held at once).
Just days after two critical vulnerabilities were disclosed, you can now explore how they are exploited in the Snapped machine.
The foothold demonstrates CVE-2026-27944 in Nginx-UI, where the /api/backup endpoint is accessible without authentication. This endpoint returns a full backup of nginx and Nginx-UI configuration files, along with the key required to decrypt the backup via response headers, allowing you to recover a weak user password from the Nginx-UI database file.
After gaining initial access, the machine shifts focus to privilege escalation through CVE-2026-3888, a TOCTOU race condition between snap-confine and systemd-tmpfiles. The challenge involves the deletion and recreation of a temporary mimic directory under /tmp, where an attacker must race the cleanup process by recreating the directory with controlled content and influencing execution timing via AF_UNIX socket backpressure during the bind-mount sequence.
By successfully winning the race condition, you can poison the sandbox’s shared libraries and leverage dynamic linker hijacking against the SUID-root snap-confine binary. This ultimately enables full system compromise, demonstrating how misconfigurations and race conditions can be chained together to escalate from initial access to root.
Screenshot 2026-03-23 at 2
Shinra is a full-scale, medium-difficulty scenario consisting of 14 Machines and 12 flags. It demonstrates how covert techniques can bypass EDR, avoid SOC detection, and abuse trusted systems. Designed for users who want to transition from pentesting to red team engagements.
We have also released two Mini Pro Lab scenarios:
  • Reflection: An Active Directory scenario involving three Machines. Users must chain multiple weaknesses across services and identity infrastructure to achieve full domain compromise.
  • Trusted: An internal red team engagement across two Machines. Users start with zero credentials on the internal network to assess the security posture of the environment.
Screenshot 2026-03-06 at 18

new

Labs

Academy

Capture The Flag

HTB Profile is now live

HTB Profile introduces a centralized view of your achievements and skills across Hack The Box platforms.
With the HTB Profile, you can:
  • Create a complete overview of your acquired skillset, inside and outside of HTB
  • Track certifications, CTF events, and all HTB achievements in one place.
  • Access an automatically updated profile based on platform activity.
  • Share your profile with peers and recruiters
Learn more about it here.
Screenshot 2026-02-13 at 18
New advanced filters have been added to the retired tabs to improve content discovery across
Machines, Sherlocks, and Challenges.
With this update, users can:
  • Filter by vulnerability, area of interest, language, or technique.
  • Combine multiple filters for more precise results.
  • Share filtered views via URL with teammates.
This enhancement reduces search time and improves navigation across HTB Labs content.
image (15)
New stats have been added to the HTB Labs profile tab to improve visibility into user progress.
This update includes:
  • A chronological overview of machine completions
  • A difficulty breakdown visualization using progress rings
  • Centralized tracking for Pro Labs, Mini Pro Labs, and Fortresses
image (17)

new

Labs

Enterprise

Offensive

OWASP Top 10 2025 Track now available

The Hack The Box OWASP Top 10 2025 track introduces you to the most critical web application security risks facing modern applications.
Included in the track are 10 hands-on challenges ranging from Very Easy to Medium that have been aligned with the latest OWASP Top 10. By completing these challenges, you will learn how to identify and exploit common vulnerabilities, strengthening your ability to assess web applications in real-world environments.
Challenges include scenarios where you will uncover potential vulnerabilities, secure critical intelligence, infiltrate digital systems, analyze platform architecture, and more.
Screenshot 2026-02-06 at 9
Load More