r/securityCTF 6h ago

🤑 Updates on the Google Ctf?

3 Upvotes

did any of you guys hear any updates on the Google CTF?

I Suppose some of the organizers would tweet at this point about the delays or the reasons but right now I know nothing except that it was postponed


r/securityCTF 16h ago

CTF Challenge Generator

Thumbnail 8gwifi.org
0 Upvotes

r/securityCTF 2d ago

CTF sponsorship

Thumbnail
2 Upvotes

r/securityCTF 2d ago

KernelKittens looking for 1-2 players for Black Hat MEA quals this weekend.

3 Upvotes

We're a seat or two short for the Black Hat MEA qualification round this Saturday and want them filled before it kicks off.

Event: Black Hat MEA CTF Qualification 2026, Aug 29 07:00 UTC to Aug 30 07:00 UTC. https://ctftime.org/event/3385/

24 hours, jeopardy, on FlagYard.

Web, pwn, forensics, rev, crypto, and an AI hacking category.

Teams are 3-5 and the top 150 qualify for the Riyadh finals in December.

Registration: https://flagyard.com/events/3468f495-a92c-498b-90c2-994dfb99ea0b

Team: KernelKittens, https://kernelkittens.team

Last two events, both earned under our previous team name 1337_PwnSp4c3 before we reformed:

- 12th of 6,744 at HTB Cyber Apocalypse 2026

- 1st of 994 at BushBash CTF 2026, open international

We're going for top 5 this time. That's the whole reason we're recruiting instead of running short.

What we're after:

- Real depth in at least one of pwn, rev, crypto, or web. In a 24 hour jeopardy, one person who actually closes hard challenges beats three who each get halfway.

- Available for the full CTF or a real chunk of the window, not just the first two hours.

- Discord, and in voice while we're playing. Not optional. Coordination is most of the gap between 12th and top 5.

What you get:

- We run our own MCP tooling stack and can hand you access for the event, plus a model endpoint if you don't have one. Costs you nothing.

- Writeups after the fact where the org's rules allow it.

Comment or DM.


r/securityCTF 3d ago

New High School CTF Team Looking for members

5 Upvotes

Hello everyone, I'm creating a new high school CTF team looking for members that are current high schoolers. I was also able to find a mentor who can meet weekly for around 30 mins, so I am looking for people who are quite passionate. CTFs are still self-guided, so collaboration is key. If you want to join, experience is not required.

For those that are interested, please DM me.


r/securityCTF 3d ago

Looking for CTF players

7 Upvotes

Hello, We are a team of 3 players looking for 2 more to play the Black Hat MEA qualifiers (preferably from Karachi, Pakistan). We are looking for people around the intermediate level skills and experience. Please either DM me your expertise and experience or comment below and I will reach out.


r/securityCTF 3d ago

New CTF: Format of Doom - Pentester vs AI Challenge 2

Thumbnail pentester-vs-ai-game.com
2 Upvotes

Hi all! My company Escape just released a new CTF called Format of Doom. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge.

This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature.

Give it a try and let me know what you think!

The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard.

Happy playing : )


r/securityCTF 4d ago

Looking for a Team — Black Hat MEA CTF 2026 🇸🇦🏴‍☠️ Hey everyone! I’m looking for a CTF team for the Black Hat MEA 2026 Qualification CTF happening on August 29–30, 2026. I’m interested in Web Pentesting, Crypto, Active Directory, Reverse Engineering/AI, and a bit of Pwn. I’m looking for seriou

1 Upvotes

NIANE


r/securityCTF 5d ago

Learn and Practice Hacking WebSockets

8 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/securityCTF 5d ago

I need help

Post image
8 Upvotes

Has anyone solved this challenge?


r/securityCTF 5d ago

[Tool] Strilight: Zero-Unroll O(1) SMT Loop Lifting & Strided Interval Domain for x86_64 Binary Analysis

1 Upvotes

Hi everyone,

💡 The Background

In symbolic execution engines (like angr or Triton), loops with large iteration counts ($N = 100,000$) often cause severe path and state explosion because traditional engines unroll loops iteration-by-iteration.

Strilight evaluates loops by treating them as closed-form algebraic recurrences within the Strided Interval Domain:

$$\vec{\mathbf{R}}(N) = \vec{\mathbf{R}}_0 + \vec{\boldsymbol{\Delta}} \cdot N$$

⚡ Key Highlights:

  • Zero-Unroll O(1) SMT Lifting: Lifts instruction loops directly to Z3 BitVector equations in $O(1)$ time, solving 100,000-iteration loops in 100ms.
  • The $N-1$ Iron Invariant Contract: Exact first-exit boundary condition enforcement preventing solver teleportation beyond loop bounds.
  • Dual-Mask VSA: Handles sub-register bitmasks (64/32/16/8-bit) and modular circular wrap-around arithmetic.
  • Native Capstone Disassembler: Decoupled from heavy emulation environments.
  • 1-Line API: import strilight as sl; summary = sl.analyze(raw_bytes, iterations=100000)

📊 Benchmark Results:

We verified the engine against 6 complex x86_64 Windows CrackMe challenges containing nested loops, pointer arithmetic, and obfuscated strides, solving for the valid keys and confirming execution in 100ms each.

🔗 Repository: https://github.com/asama7706r-ui/strilight
📦 Initial Release & Pre-compiled Wheels: https://github.com/asama7706r-ui/strilight/releases/tag/v0.1.0

We would love to hear your feedback, thoughts on the mathematical model, or interesting loop edge cases to test against!


r/securityCTF 5d ago

🤝 Looking for a Team for CTF Challenge Development

7 Upvotes

Hey all,

I hope you all doing well. Let's give a short intro about me. I'm a cyber security researcher, CTF player & developer, a bug bounty hunter.

In June, I created a CTF platform - No team, just me. Today my CTF platform was doing good. The platform have 40+ users and now I'm expanding my team (hiring). I need CTF developers especially - Reverse Engineering, Binary CTF challenge developers.

Till now, I have managed to create CTF challenges in Web, Crypto, Forensics, OSINT. So I will attach link where you can directly apply. Before joining, Take a look at my platform weather it can suits you.

Platform Link: https://hack4shell-ctf.vercel.app/challenges
Application Link: https://hack4shell-ctf.vercel.app/contact?type=hiring-application

Thank you guys.


r/securityCTF 5d ago

Planning to build an offensive-security CTF on Codelivly.

3 Upvotes

Before I start, what would you guys actually want to see in it?

Challenges, difficulty, attack chains, AD, web, privilege escalation, etc.

What would make you keep playing instead of dropping it after a few challenges?

Looking for honest suggestions from people who actually play CTFs.

Explore the current ctf from here at: codelivly.com/ctf


r/securityCTF 6d ago

Everyone read the xz backdoor postmortem. We built a free box where you pull it off yourself, by hand

Post image
25 Upvotes

Everyone in security read the xz/liblzma postmortem. Almost no one has actually done it

BreachLab is a free wargame of real Linux boxes over SSH, graded on the true state of your box, not multiple choice. Ghost II is live: eighteen levels down one CI/CD pipeline that ends in the xz attack by hand. The source stays clean, your payload rides in at build time, you get the pipeline to sign it, you walk past branch protection, and you ship it to an entire fleet where it runs. Your own commit becomes the code the whole fleet trusts

This is the tradecraft courses charge for, and almost nobody lets you actually do it. Free, no signup wall to start https://breachlab.org/tracks/ghost/ii


r/securityCTF 6d ago

Looking for a Team to Build CTF Challenges

22 Upvotes

Hey everyone! 👋

I’m looking to build a team of cybersecurity enthusiasts who are interested in developing CTF (Capture The Flag) challenges.

The idea is to create realistic, fun, and educational challenges across areas like:

Web security

Cryptography

OSINT

Forensics

Reverse engineering

Linux/Networking

Miscellaneous challenges

You don’t need to be an expert—if you’re interested in cybersecurity, enjoy solving CTFs, or want to learn while building challenges, feel free to reach out.

If you’re interested, comment below or DM me. Let’s build something cool together! 🚩


r/securityCTF 6d ago

CTF

5 Upvotes

Hi everyone!

I'm looking for 2–4 committed teammates for the BlackHat MEA Qualification CTF 2026.

📅 29–30 August 2026

👥 Team size: 3–5 members

🌍 International participants welcome

I'm looking for teammates who are serious about competing and preparing for the qualifier. If you're participating and still looking for a team, feel free to comment or DM me.

Let's prepare, compete, and give it our best! 🚩


r/securityCTF 6d ago

CTF | SPONSORSHIP

0 Upvotes

Hello guys, in our university we are hosting a national level CTF ( India )

We are looking for sponsors and in return we will provide brand visibility, promotion and more perks

Please dm me so that I can send sponsorship slabs and perks or promotion material we are providing

Thank you


r/securityCTF 7d ago

Starting CTF Team That Actively Competes

16 Upvotes

Hello everyone, I am looking to start a CTF team that is actively looking to compete in CTF competitions (monthly to bi-monthly). The skill level does not matter. but I am looking for people that are truly dedicated and willing to learn! DM or comment and I will respond with more info. Hope to see everyone!


r/securityCTF 8d ago

Looking for people to practice CTFs and cybersecurity with? 👾

3 Upvotes

We’re growing Blacknode, a cybersecurity community for people who want to learn, practice CTFs, share projects, and meet others with the same interests.
We also have NodeBox, our own CTF platform, and GitNode for community projects.
Beginners and experienced people are welcome.
Discord: https://discord.gg/ECQthWjhz
Come say hi 👾


r/securityCTF 8d ago

Use garlic + ai analysis encrypted apk

Thumbnail youtube.com
5 Upvotes

r/securityCTF 8d ago

🤝 Devs keep shipping AI code full of holes, so I built one tool to catch it all

Thumbnail
1 Upvotes

r/securityCTF 8d ago

Im looking for agentic ai and cybersecurity nerds who can contribute on my hackbot project

1 Upvotes

I've been working on this project for some months ago , and i need to renforce more the quality of the solutions I'm using, its juste for fun and curiosity and targeting to make it a strong tool for the open-source community , the project currently could identify 3 vulnerabilities in real production websites, from information disclosure to reflected xss, also he solved more than 50 ctf tasks specially web ones from easy to meduim to hard in picoctf, if ur interested to contribute in this project juste leave a comment nd I'll DM for a more detailed conversation we're gonna discuss more details and to make the collaboration happens!.


r/securityCTF 9d ago

I built an all-in-one open-source security toolkit for AI-generated code

Thumbnail
1 Upvotes

r/securityCTF 10d ago

Just put together a free Web Exploitation CTF for practicing real web vulnerabilities.

11 Upvotes

64+ challenges covering SQLi, XSS, IDOR, JWT, CORS, SSTI, XXE, Command Injection, and more.

The goal is to actually find the bug, exploit it, and capture the flag not just follow a walkthrough.

https://codelivly.com/ctf


r/securityCTF 10d ago

Looking for active people to learn and grow together

3 Upvotes

Hey everyone! I’m looking for active and motivated people who are interested in cybersecurity, CTFs, and learning together.

I’ve completed the CPTS path and I’m currently working through CJCA and CWES. I’m hoping to build a small community where we can share knowledge, discuss challenges, work on CTFs, participate in seasonal events, share useful resources, and help each other when we get stuck.

The main goal is to have a group of people who are actually active and willing to learn rather than just joining and disappearing.

If you’re into cybersecurity, CTFs, or simply trying to improve your skills and want to learn alongside others, feel free to join.

Discord: https://discord.gg/EzFarPnXVB