Changelog

Follow up on the latest improvements and updates.

RSS

Progress just got more rewarding. You can now earn experience points by completing content on HTB Enterprise, build weekly streaks, and reach new levels, ranks, and grades as you develop your skills. XP and Streaks connect your supported activity across the HTB ecosystem into one visible progression journey.
  • Earn
    experience points
    and watch your progress unlock new levels, ranks, and grades across HTB.
  • Build and maintain your
    streak
    by staying active each week, turning consistent practice into visible momentum.
Screenshot 2026-08-26 at 6
The first Enterprise Season continues the ACT II: Proxy Crown with a new Sherlock, Relay of Deceit.
This time, the focus shifts to the software supply chain. Hidden inside what appears to be a legitimate npm package is malicious code designed to evade review, perform host reconnaissance, and quietly exfiltrate sensitive data over DNS.
Players will practice how to:
  • Analyze npm packages safely without executing untrusted code
  • Uncover malicious behavior hidden in JavaScript
  • Investigate covert DNS-based communication
  • Reconstruct attacker activity from network traffic
  • Assess the impact of a software supply-chain compromise
Relay of Deceit
CTF admins can now access scenario writeups directly from the Content Library while building an event. Instead of selecting challenges based only on titles, descriptions, and difficulty, admins can review the intended solution path before adding content, making it easier to understand what each challenge tests and whether it fits the event's goals.
Choose challenges with more confidence and match content to your goals by validating that each challenge tests the right skills for your audience and training objectives.
Screenshot 2026-08-19 at 6
HTB's first Enterprise Season enters its next phase.
Your search for Arodor's proxy network now leads into a compromised settlement environment, where exposed identities and excessive cloud permissions hide a chained privilege-escalation path.
Take on Silent Market Raid, a new AWS Challenge where you'll enumerate cloud resources, abuse IAM trust relationships, and uncover how seemingly harmless disclosures can lead to complete compromise.
Continue the mission and begin Act II: Proxy Crown.
___________________________________
Need to catch up?
Complete the scenarios from Act I: Gridfall Signals.
Silent Market Raid
We have added a brand-new Satellite category, featuring nine progressive Challenges created in direct partnership with aerospace cybersecurity firm VisionSpace.
This track covers satellite system architecture, main communication protocols, and common attack vectors. Content ranges from Very Easy to Hard difficulty, offering practical exposure to realistic scenarios inspired by real-world satellite software and infrastructure. Available now across both HTB Labs and the Enterprise Platform.
Satellite Exploitation Track_1200x675

improved

Capture The Flag

Defensive

Threat Range

Configurable SLAs & Dispatch pacing for Threat Range events

Threat Range events are now more flexible.
Admins and Event managers can now customize alert dispatch pacing and response-time SLAs, making it easier to tailor exercises to different team skill levels, operational workflows, and event durations.
What's new?
  • Configure how quickly alerts are dispatched throughout an event.
  • Customize response-time SLAs for both alerts and tickets.
Use HTB's recommended defaults or align timings with your organization's internal SLAs and operating procedures.
threat range
AI models do not operate in isolation. An agent consists of the model paired with host-side code that validates tool proposals, communicates with external systems, and controls when the execution loop terminates. Relying strictly on system prompts for security leaves systemic vulnerabilities that attackers can exploit.
In this new Medium-difficulty module available on HTB Academy and HTB Enterprise, you will construct that host-side orchestration code yourself. You will learn how to enforce safety decisions there, not in the prompt.
1200x630 - AI Literacy - Agents
Administrators can now control the sequence of content assigned to a Space, making it easier to build structured workforce development programs that guide learners through deliberate, role-aligned skills journeys.
From the Space’s Content tab, open Assigned Content. Enter
Reorder
mode to drag and drop content cards or update their numeric position fields, then make sure to Save your order selection.
Create deliberate learning paths across modules, challenges, labs, and Sherlocks.
Untitled (Sat Jul 25 2026) (2)
We integrated 191 modules from LetsDefend into the HTB Academy library to expand our defensive and foundational cybersecurity curriculum. This launch increases HTB Academy's defensive content by more than 500%, making comprehensive blue team skills accessible under Tier 0 and Tier 1 access.
Key Updates:
  • 191 Modules Added: Includes 16 Tier 0 modules and 175 Tier 1 modules (166 defensive and 25 general security modules).
  • 3 New Skill Paths: Added dedicated paths for CompTIA Security+ Preparation, Programming for Cybersecurity, and Google Cybersecurity Certificate Preparation.
  • New Badges: We've also included new content completion badges for these modules to make sure all your effort is recognized.
  • Subscription Integration: All new content is made accessible through standard HTB Academy subscription plans without requiring separate add-on subscriptions.

new

Enterprise

Offensive

Defensive

Operation Red Horizon continues with Zeek

A compromised mission operations environment has exposed weaknesses across cloud infrastructure, application security, and containerized workloads.
Deploy into Zeek, a new Linux Machine where you'll enumerate AWS resources, investigate LocalStack services, exploit a vulnerable Lambda function, and pivot from cloud access to full host compromise through Docker.
Continue Act I: Gridfall Signals and uncover the next piece of Arodor's campaign.
Zeek
Load More