Post

Cube Talks: August 21st, 2026

Cube Talks

Disclaimer: This transcript was generated with AI assistance and has been manually reviewed and edited. Despite best efforts, some inaccuracies may remain — please use your best judgement when referencing specific statements.


TL;DR / TL;DL: HTB staff answer Q&A on hiring, AD evasion, AI red teaming, and pop-culture hacking takes.

Watch on YouTube: Cube Talks – August 21st, 2026

Listen on Spotify: Cube Talks – August 21st, 2026


FalconSpy: Hi everyone, welcome to this week’s Cube Talk. I’m your host, FalconSpy. This is your opportunity to ask our panel of staff and volunteers any questions you may have about Hack the Box and any of the services we offer here, as well as InfoSec questions in general. We’ll do the best we can, answer as many of them as we can within the next hour. You can use the forward slash Cube Talk command to ask your question to our panel. You can use that same command to also upvote questions to the top of the queue. Questions are first in, first out, unless upvoted and stated otherwise. We’ll introduce everyone here on the panel, so that way, if you have any targeted questions, you can ask it and we’ll go in no particular order. And then I’ll sound like a broken record again with how to use the Cube Talk command and we’ll go to our questions. So we’ll start off with Gillette.

gill3tt3: I’m Gillette. I’m a professional red teamer with a background in bug bounty and big data analytics and all things hacking and fun.

FalconSpy: We’ll do Ryan.

0xRy4n: Ryan, I am the head of client operations. I do a lot of the internal tooling and automations and other technical business stuff that makes the company go brrr.

FalconSpy: We got Zeyad.

21y4d: Hey everyone, I’m Zeyad. I’m from the academy team and I’m in charge of academy modules, paths, exams, and certifications.

FalconSpy: And we got Jexx.

Jexx: Hey everybody, my name is Jexx. I am the creative strategist over on the marketing team at Hack the Box. And I am just a junior threat hunter that somehow got into marketing. I don’t know what I’m doing here.

FalconSpy: Oh, we got OXDF.

0xdf: Hello, OXDF. Former Hack the Box employee, currently working in AI security.

FalconSpy: We got ippsec.

ippsec: ippsec. I’m a lab architect. I just float around trying to bring value where I can. I also don’t know what I’m doing around here most of the time.

FalconSpy: ChadB is currently on mute, but they are a red teamer elsewhere, contestor, so they’ll introduce themselves later when they’re actually available. And then I am FalconSpy, one of the community specialists here and also the host, as well as a red teamer elsewhere. So, broken record part: forward slash Cube Talk command. It’ll be in the chat. You can use that same command to upvote questions to top the queue, first in, first out, unless, say, otherwise, and without further ado, we’ll just go straight to our questions.

FalconSpy: So, suppose you are all interviewers who are conducting an interview to hire people in the cybersecurity field, any field, for like red teaming, blue teaming, GRC, so on and so forth. What will you look out for in a candidate and how do you evaluate them in this current era?

gill3tt3: I’m happy to jump on this one, having just interviewed a bunch of people. Main thing I look for, certainly hiring in red team, but in general, is to try to find folks who are genuinely curious about what they’re doing, ask good questions, and have a good thought process for it. It’s very common for interviews to go sideways if they’re like a stump the chump kind of approach, where you’re just like trying to get trivia out of it. But sitting down, like talking through problems, talking through approaches to historical problems or novel things, sort of getting in the mind of how somebody actually works through this, what questions they ask, what considerations they have for the problem space, I find to be generally very valuable, both from like a team fit perspective and also just engaging the sort of maturity of their approach to the space.

ippsec: Yep, pretty much the same thing. I have like three questions that I think whenever I end an interview. The first one is, would I enjoy working with this person? The second one is, will this person make me look stupid? And then the third one is like, does this person have the skills to do the job? And it’s in that order. If they don’t have the skills, I’m confident I can help them get the skills to do it. The most important thing is I just want to continue enjoying work, so I have to enjoy working with the person.

21y4d: Yeah, I agree with this last point. I would rather take someone who’s a team player and who’s very excited to work and eager to help with room to grow, so he’s not yet there in terms of skills, than someone who is really skillful, maybe like the top in the field, but he’s definitely not a team player and the rest. So I’d rather the first than the latter.

Jexx: There’s definitely something that I read recently. I don’t know if y’all had seen the post that Jason Haddick’s had thrown up recently that had a lot to do with like how junior spaces are changing due to AI. I personally, I’ve been interviewed before, but I see these constraints that everybody sees when it comes to like what HR is looking for and like what that pipeline looks like. And I really, I hope for a future, especially when we’re talking about like that fear of like, okay, so junior roles are going to change, but what is that going to look like? As far as the hiring process, my hope in the industry is that we change into a like a journeyman’s model where people are being brought in and trained by these teams. It’s just finding like the right person in the selection to be able to fit qualities that fit their team’s persona. So, you know, I don’t know how y’all feel about that, but I think that it would be great to have. I’ve always wanted that personally, is just like to be trained on the job by the people because there’s always different stacks, there’s different, you know, missions each particular team has in individual sectors too, right? So that’s more of a hope than like what I’ve seen.

0xRy4n: I would agree with basically everything everyone said. I’ve hired like 10 or something people to the company and I always do pretty much the exact same thing, which is I hire based on vibes. So I don’t have like a set list of questions that I ask or some like standard criteria that I evaluate everybody on. I usually just talk about like past projects that you’ve had, challenges that you faced, et cetera, et cetera. I just have a conversation with the person, and you have an hour long conversation with a person, by the end of that hour long conversation, you should have a pretty good idea of like, do you vibe with this person? Do they actually understand the things that they’ve been talking about? It becomes really apparent quickly if they just have like answers memorized or if they’re like talking to ChatGPT, you can tell pretty quickly in the early interview. So what I’m looking for is basically the same thing that I’ve said: I’m looking for that you can work with me, but I’m going to enjoy working with you. And that also you have whatever it takes to be able to learn. I don’t really care if you already have the skills, but I need some demonstration that you are a person who can pick up skills and learn them. If I have some demonstration of that, that’s pretty much good enough for me.

FalconSpy: We’ll go to our next one. Okay.

Jexx: All right, we’re doing—

0xRy4n: —this, Jax.

gill3tt3: Yeah, we’re on the side chatting here. Like the journeyman model is super interesting to me because that’s basically been how I’ve done my pivots for my entire career, but like the trick is still getting in the door to begin with. And one of the things that I… and the reason I want to take up the whole hour on this, like this comes up every single time we do one of these chats and every other venue where I talk about career stuff is: hey, how do I get into red teaming? Like I just finished school or I got my certs and I’ve got no related job experience and I want to pivot over to this or pen testing or whatever, right? And the reality so often is you’re going to be so well-served doing something else and finding opportunities to shadow folks or find mentors to help push in that direction rather than just trying to come in like completely fresh to something. So I would say like the perfect spot that we have now, for better or worse, is like a mix of these two things of yeah, finding somebody who’s willing to take you on as an apprentice, so to speak, but perhaps not as a formal job role where this is the only thing you’re doing. But definitely, like always as you’re trying to explore that space, always try to seek out folks who can help you go in that direction, whether it’s like in your company, in the community, whatever.

Jexx: Right, I have a question about that too because I don’t know… I’ve never had to run a team or hire for a team, so I wouldn’t know this, but how amenable is HR to doing things like this? Like are there any kind of constraints that they have that they have to abide by, or is it up to the security team to sort of set those standards for hiring practices?

gill3tt3: I can answer in a very generic sense, having no relation to my current employer, previous employer, or Hack the Box. I think in general, you will find that HR is not going to be a roadblock on that kind of stuff, especially if it’s internal already. That’s in having done this across many different companies, both as the person doing mentorship or like managing teams that are bringing folks on board. A lot of it is sort of a negotiation with whoever your current manager is and the other team to say, hey, are you willing to do the time carve out in both directions to make this happen? And in my experience, if you are not like completely sucking at your current job, or certainly if you’re excelling at your current job, it tends to be a pretty easy discussion of like, hey, we can free up 20% capacity from your schedule or whatever for you to go off and shadow for a week here and there, and that kind of stuff. So it’s one of those things as well where if you never ask the question, you never get the answer. So for everyone here, I would certainly encourage that question to be asked if you’re given the opportunity or see it as a possibility.

ippsec: Yeah, I’d follow it up. I have the same experience. In previous jobs, there’s been like requirements to have certain certifications because some, like, if you’re working forensics, you can go to court cases. And some companies say like, all of the people have the GIAC certification, which is like a reverse malware type of thing. Just some certifications where they can do that work in court. So lawyers don’t like destroy you in cross-examination. And there’s been cases where like, we’ve referred people that didn’t have those certifications. The company is like, well, okay, we’ll just hire them. We’ll say within four to six months, you’ll have the certification and we’ll be good. Like as long as you have the buy-in from the internal team, HR is not going to like fight that battle. Keep in mind like, HR probably doesn’t love their job. They don’t want to fight with employees. They’re there to like make employees happy. So if like, you have two employees saying, I want to hire this guy, HR is not going to be like, well, they don’t have the certification, I’m going to veto this. That’s just not how it works. If that’s how it works at the company, you don’t want to work for the company.

FalconSpy: Amen. All right, we’ll go to our next question here. Another question: is there any plan to have a combined subscription for Academy and main platform? I think I’ve talked—

0xRy4n: —about this in the past before. And also, Chap answered this like publicly, so it’s not really a secret. There is a desire to do this. There is a significant number of technical roadblocks to doing so, which we are slowly like overcoming piece by piece. But it’s a lot more difficult than you might expect. Billing systems are complicated and migrating information in billing systems is also quite complicated.

FalconSpy: Next question: why Hack the Box? Why not Hack the Box?

0xRy4n: I saw this when it was in quotes, right? Why is it called Hack the Box?

0xdf: I don’t know. I’d like to take this time to complain that putting spaces in the name of the company was the dumbest thing we ever did. And I still object to it, and we’ll never… and we’ll never write it out that way myself.

Jexx: Spaces in names. I think that’s what… like, every before, like machines is called boxes, right? Like you go to like VirtualBox or something and download something. And that was the standard way to play before there were any sort of like online infrastructures. Yeah, so it’s just like that’s the thing. Do the thing.

0xRy4n: Box means server, or like machine, computer, whatever. You hack the box. Virtual machine. Why is it called that? You’ll have to ask Chap. You know, you’ll have to go back to 2017 when it was just Chap in his garage and ask him what his inspiration for the name was.

FalconSpy: I imagine if you can catch Goblin in the chat, he would answer too. I bet it didn’t have a space. It was already hackthebox.

ippsec: Yeah, Goblin found out about it on IRC after it existed. But I mean, I like Hack the Box because it’s a community platform where people just submit machines. And then we have people that just make them somewhat more realistic. And I think that’s kind of like the best approach. A lot of CTFs I play… I used to enjoy this and OXDF actually convinced me otherwise many years ago, where like the challenge itself kind of had these meta hints where it talked to the player kind of guiding them. So if you did some type of technique, it wasn’t the right technique, it guided you to the right way. That’s how things used to exist, let’s say a decade ago. I kind of like that. But now that I’ve played the alternative a long time where there’s just realistic ways to find the intended path, I think that’s the best way to go. And that’s what Hack the Box really focuses on. I think what sets Hack the Box unique. There’s part of me that kind of wishes instead of spaces, we used tabs in the name.

FalconSpy: That’s the only thing that’s gonna be worse.

0xRy4n: So much better. I don’t know how that would play. When you have to register the name, you have to like write up like the Unicode representation of the tab.

ippsec: Go with backslash t. Hack backslash t, backslash t, box. Yeah, there we—

FalconSpy: —go.

ippsec: There—

FalconSpy: —we go. Do you end it with a backslash r, backslash n too? No, just backslash—

0xRy4n: —r. Return carriage? Gross.

FalconSpy: I don’t know. I’m so used to adding the return. All right. Our next question, a photo question. Are you guys tired of questions like, “will AI take over the cybersecurity field” or “my cybersecurity job”? Oh, I have something for this.

gill3tt3: Well, Ryan’s finding props. I mean, I don’t know. There’s a diatribe to be had on this, but in general, I think it’s a great tool.

Jexx: Yeah, there you go. Yeah.

gill3tt3: We’re seeing that—

Jexx: —certain backfire. Oh, you got one of—

gill3tt3: —those.

FalconSpy: That was a tough concher. Who is that? Who’s giving that one? It’s Deskrips, Deskrips, Deskmartials.

0xRy4n: Marshall’s company. He gave me one of these and he gave me like their very last, like, comic book they have.

gill3tt3: We got these as well. I don’t know how else to… Zero D. That was actually—

Jexx: —really funny because that was over at the New Village and everybody had, like, some form of, like, I guess, marketing material that was out, and somebody came by and just like, no, turn it all around. There’s no marketing here. Like everybody had, like, barren booths besides all their stickers and stuff. It—

0xRy4n: —wasn’t Defcon who did that. It was LVCC themselves because that area was not licensed to have marketing materials. So they’re like, all brand, all brand recognition, needs to be turned around so you can’t see any brands or something. Or like, dude, like—

Jexx: —or you have to pay a $20,000 fine. They were going to get their money one way or another.

FalconSpy: All right. This one’s an upvoted one, but throwing some shade at us. But all right. What are your thoughts about getting GTA 6 before the TrustFall box?

ippsec: I’m pretty sure TrustFall is going to come out before GTA 6. If you’re considering the leaks, well, TrustFall got leaked before GTA 6 also, technically.

0xRy4n: GTA 6 doesn’t come out for me because I don’t play on console. So I’m going to have to wait another year anyway. So nothing is coming out before GTA 6 for me. Everything—

FalconSpy: —is coming out before GTA 6, I should say, actually. I don’t think that’ll ever come out.

0xRy4n: I think it will. I think there’s movement on it now.

Jexx: Okay. Pray to Gaben.

FalconSpy: Okay. Based Gaben. All right. Next question’s an upvoted one. This person’s learning Active Directory. One of their seniors also does some Active Directory and pentesting in their role to be certified, so I guess where they work. He said he got access to RDP on a machine, CrowdStrike blocked him when they were able to extract passwords on and so forth. His question is: what is evasion? How do you go about doing it if you’re trying to do Mimikatz and other malware? So I guess we’ll just start off with: what is evasion and how do you evade?

gill3tt3: The sort of tongue-in-cheek answer: the best way to not get caught for these things is to not use Mimikatz, but to understand what it’s trying to do and then actually do that instead. It’s, I say this with absolutely no disrespect, especially as folks are learning, but that is part of what separates being a script kitty and actually being good at what you’re doing. Tools are fantastic and there’s a lot of times where they are absolutely valuable to use. There’s also a lot of situations where using the tool as a grader, in this example, is exactly how you’re going to get caught as well. So when there are opportunities to take a different path to get to your goal that is not something that’s necessarily going to be an obvious solution to it, that tends to be a very good way. Like I’m putting on the red teaming hat for this, not necessarily like a CTF kind of hat, but yeah, understanding the different ways that you can get to your end goal and then understanding how that can be done in a way that is not going to set off known alert paths, whether that be from vendors like CrowdStrike or whatever, or just are not going to generate significant compromising telemetry, good things to consider.

Jexx: They’re like putting on a vision.

gill3tt3: Yeah, I mean, in general, right? Like, are there ways to do this that don’t require you to load external binaries? Are there other ways that you can do the sys calls that you need to accomplish something, to get persistence in a way that is not going to immediately jump out as being malicious, that kind of stuff?

21y4d: In Academy, we have— yep. No, you can go. So I was going to say, in Academy, we have a module about evasion in the CAPE certification, but I think to be really advanced in evasion, you need to understand the blue side of it. So we have, I think about more than 10 modules we have released over the past year about detection engineering. And these are very advanced topics in blue teaming, or rather in defending, let’s say, that allow you to basically understand how to capture the various things from red teaming and pentesting. So once you have this understanding, you should be able to develop the understanding or the skills necessary to be able to evade them. But then actually evading them, you will actually need the other side of it, the red teaming. I would actually start from the blue teaming, to be honest.

ippsec: Yeah, a lot of evasion mainly comes from just like knowing how tools work. A lot of tools are dual use. So like in the sense of Mimikatz, a lot of tools may have a legitimate reason to read LSASS, maybe not LSASS in particular, but like there’s legitimate use cases that red teams take advantage of. And open source tools typically always do something in a somewhat stupid or repeatable way that stands out. So like the way Mimikatz acquires LSASS, what flags it processes, only Mimikatz really ever uses those flags. So you can easily detect what a legitimate tool versus Mimikatz is if someone just uses like standard off the shelf binary. Same thing with like call stacks, things like that. Just think of it like you’re running GoBuster. The user agent says GoBuster. You know someone’s using GoBuster. There’s nothing that says they can’t just mimic a regular user agent. If someone just copies and pastes something off the internet, they’re probably going to take a user agent of Firefox or Chrome that is multiple years old because people don’t update that stuff in blog posts. Like a person that actually knows will be like, oh, I’m going to use a user agent from my browser, or just download a browser and use one that I think won’t stand out. So that to me is evasion.

FalconSpy: I’ll take the silence as a move on. So I’ll throw out a disclaimer for this question. We typically try not to compare ourselves to competitors, but for those who are going to talk, talk to them if they want to do the thing. So how does the CPTS compare to the OSCP in your opinion regarding knowledge difficulty and career value? Purely, purely subjective.

0xRy4n: This is not the official stance of Hack the Box nor—

FalconSpy: —Hack the Box Academy. I think it’s about double the difficulty. I got to go do it now. I have no further elaboration. I think it’s about twice as hard. Take the silence and go ahead.

ippsec: I was just going to say that the standard disclaimer: you should never really tie a certification to getting a job. If you do, a lot of employers, a lot of people have certification nowadays. That mentality kind of worked a decade ago, but now if you just tie getting a certification to a job, if you get that certification, you’re going to work your butt off. You may not get the job right away, and that can seriously demotivate you. So in my mind, just treat the certification as a way to measure your growth over a time period. Not that I’m going to do this to get a job. Also, if you go into an interview and you give me the attitude that you have these certifications so you qualify for the job, that doesn’t qualify as good vibing to me. And like many of us have said, the most important trait to come out of an interview is—

FalconSpy: —you fit well on the team. I will now take this opportunity, I guess, to realize that we’re good here on that question. So I’ll move on. This one’s a very long-winded question. I’m going to do my best to paraphrase it. I mean, everyone can see it in the chat there. But more or less, we used to have the Hack the Box forums. We’ve since just discontinued them, shuttered the doors in terms of being able to register and sign up, need to make posts on there. Basically, the person who’s asking this question is right. Have you seen, since this downgrade from moving from the forums to here on Discord where multiple people are chatting and the chat is always going, do we feel that there’s a downgrade in community support, specifically with regards to module support that’s been noted by our team here? Then would we be able to replicate something similar to the forums within Discord, for example, setting something up with our Atom section structured where posting guidelines includes standard subject structure and so on and so forth, similar to how you’d see an actual forum. So I guess: why did we shut down the forums and then what can we do here on Discord to, I guess, bring that back?

Jexx: I’ve been answering a lot of questions on Reddit recently, so that’s kind of where I’ve seen everybody move over to. Why did we shut down the forums? I think that was more of like a…

0xRy4n: There’s a lot of reasons why the forums got shut down. I mean, most of them are fairly benign and not interesting. One of them is because it was incredibly hard to moderate it. And that a lot of the people whose the forum was their original passion project and were maintaining that were no longer at the company. Yeah, and it was also kind of dead and kind of overrun with bots. There was a number of various reasons that contributed, but there was no really big interesting answer to it. It was just an amalgamation of a bunch of small reasons.

0xdf: Whenever you try to do multiple things that achieve the same purpose, some of them end up getting underloved and just kind of wasted, and I think that’s what happened to the forums. There wasn’t moderation there. There wasn’t that many people there. There was a lot of bots. There was a lot of cheat, just blatant answers. The good thing about the forums is that if you’re going to find help with a box, you can read through what other questions people have already asked, which you can’t really easily do in Discord. The bad thing about the forums is, if people put up like just straight up answers, like unless you have like really good moderation looking at that, it just gets left up there. And I think my impression is that we just like, people moved to Discord, and most there wasn’t just any critical mass left in the forums. I think, I don’t know, I mean, I’m not— I defer to this community team on this, but like there are things you could do. Other Discord, where I’ve seen other Discord where each box has a thread associated with it that you can create sub-threads and things like that, and you could do some organization if that was something that people really wanted, but I don’t know, it seems like it might be working for a lot of people.

FalconSpy: Go ahead, I’ll answer after you.

ippsec: I was going to say, yeah, I think there’s a lot of things we could be doing on Discord that will probably focus on probably not in the immediate future, but that’s probably going to be more like a 2027 goal of just improving what stuff you can do on Discord and how help is given. Like I think right now the company’s focus is kind of on like the AI coach, and then once like we get the platform better with support, then I’m assuming we’ll focus more on like the Discord itself. There’s a lot of just things going on behind the scene before we approve, like before we make improvements to that, we want to make sure all the other processes are good, because let’s say we wanted to just open up more discussion about what machine released. Well, technically that’s a spoiler, so we need a better way to moderate that. There’s a lot of just various things we want to think through first before we improve that experience.

FalconSpy: Yeah, so outside of what has already been said about the forums, at least here on Discord, right, there is that forum feature, similar to what you would see under the Academy section for Aradam. We’ve played around with turning a couple of sections here on Discord into forums. I think it was maybe a year or two ago, we tried to make that transition, and everyone here on Discord absolutely hated the transition. Obviously, we gave it like 24 to 48 hours to see how everyone liked it, and everyone absolutely hated it. We didn’t delete everything, so we just transitioned back, and we see the status quo that we’re at today. Can we revisit using forums for newer boxes or just using it for talks in general? Sure, but yeah, like Jexx was saying, I think most people now are using Reddit for their long-term standing posts that you can actually search online for rather than just here on Discord, where the search function may or may not work as intended, or it doesn’t provide you with what you’re looking for because Discord’s search function is so rigid. I think we’ll move on, or does anyone else have anything you want to add?

Jexx: All right, moving on.

FalconSpy: Go ahead.

Jexx: I was going to just say, always open to suggestions. The community has a way that they prefer to have these conversations or places. If it is a Discord channel, make a case, and we’ll listen to it. I’ll listen to it for sure.

FalconSpy: Yeah, you can use the forward slash feedback command. It’ll go to all the major stakeholders in the company. Something’s very specific to the community, you can always direct message me. My DMs are open to everybody and anyone. Yeah. All right. Next question, is enough a photo question: do you have any tips for someone that likes reversing and binary exploitation, has a strong ability to understand and code in C and assembly knowledge, and wants to get into kernel vulnerability research or vulnerability research in general? That is one of the fields that scares me just because AI—

ippsec: —does that stuff so well. I would probably look at the kernel CTF and things like that and try to recreate things off of issues, but AI has been doing that really, really well. It’s very hard for me to find something on kernel CTF that Claude wouldn’t just make a—

FalconSpy: —POC for me right off the bat.

ippsec: What’s OXDF saying?

FalconSpy: Still, if you love—

0xdf: —it, I say, just go do it. Like, go do kernel CTF, go find yourself a project you’re interested in, dive in, and see where you get stuck. And the fact that AI is good at it just means when you get stuck, you have something to talk to about it. I don’t have great advice because this is not an area I’m an expert in. But I guess the universal advice is find a project that gets you excited, that you want to work on and that you are excited to put your time into, and then just start—

FalconSpy: —challenging yourself. I will move on. This is another voted question here. Given the AI red teaming path, do you all foresee local language models and testing becoming mainstream? Why does the COAE have this as its focus? It seems that simply using agents for pen testing is more popular right now.

21y4d: So there are two sides of the coin. The first is red teaming AI models and AI agents and so on, which is the focus of COAE. And then there’s actual pen testing, which nowadays, just like coding and software engineering, you should use AI to help you with it. So I’d call the second one just pen testing these days or red teaming. You have to use AI to help you along the way. Obviously not just prompt the AI to do everything. You have to understand what it is doing and just let it help you along the way, just like you do with coding. But yeah, the actual focus of COAE is actually pen testing the AI models and actually pen testing any tools that run or rely on AI. And that’s how you learn how to break them and so on, not actually—

FalconSpy: —the general pen testing. Yeah,

ippsec: I haven’t done the whole path for the Offensive AI Expert, but I would go on a limb just based upon other certifications I’ve done. The Academy team generally tries to build a good foundation before it goes into any attack. So maybe that’s why you’re getting that type of impression. Also, I think the way it’s architected is more resilient to future changes. Like I don’t know a good way to do a lot of AI courses just because how quickly the field changes. Like I knew, if you go back like two or three months, a lot of people were complaining that just created courses on Claude when Claude was building a lot of momentum. And then everything changed, just how it works in general, because so many improvements came overnight. So if your focus is on how to use AI, you become dated very, very quickly in this field. And it’s something I don’t think a lot of people have figured a good way to battle. So I like the standpoint of just learning how it works, like learning how to attack it, and focusing on what isn’t—

FalconSpy: —changing overnight. All right. Anyone else? All right, we’ll move on. Moving on. All right. For the Silver Annual subscription, the CJA-CA comes added, but if someone already has that certification acquired, why not an option to maybe swap it for another exam, even if it includes some type of top-up?

21y4d: So yeah, we don’t have another exam at the same level as CJA-CA. It is our most beginner exam. So that’s the reason you cannot swap it with anything. I’m not sure about the top-up and so on, but that’s the main reason. For the other exams, for example, if you get the Gold Annual subscription, and let’s say you pick CPTS, you can later on swap it with CWES and so on.

ippsec: I would also say it’s kind of hard to just top it up because how the certifications work is like, you get to unlock all the courses relevant to that exam based upon the level. So I would imagine if you have the lowest level and get the CJA-CA, that wouldn’t unlock all the courses for the CPTS. And you have to take all the courses in order to take the exam. So I don’t see a way to really just top up from that, if that makes sense.

0xRy4n: I can elaborate slightly further. So Silver Annual subscription, historically, all content up to and including Tier 2, which includes, right now, five separate certification paths, all the content from five separate certification paths. Historically, you would buy that, you get all of that content, and you get to take one exam with two attempts. We added on the CJA-CA, which is also the cheapest exam. We added that on as a bonus, but historically, Silver Annual was only, you never got one. Getting the CJA-CA is a bonus thing we’ve done. But it’s also, again, the cheapest exam. So it would be a different thing to then say, okay, you’re going to get, you can get two of any choice—

FalconSpy: —of the higher-priced exams. We’ll move on. This is another photo question. This person’s a, I guess, literal fresh person to the cybersecurity field. They’ve only been learning for the past three days. Is cybersecurity worth getting into, especially red teaming? Yes. If you love it? Yeah. Yeah,

gill3tt3: Just be aware, it’s a journey. It takes a long… if you’re in it, enjoy it. Be passionate about it, and you’ll have a lot more fun with it. But yeah, you’re going to be with it for a while.

0xRy4n: It’s worth getting into if you like it. It’s not like what some people who don’t work in security or who aren’t technical think, where it’s like, ooh, you learned the secret, the super secret forbidden knowledge, and now you can hack anything. It’s just a skill like anything else that you get better at over time. Nobody expects that they’re going to pick up a hammer, and they’re going to learn the super secret knowledge from the carpenter, and now they’re going to be able to build the Taj Mahal. No, you get better at it over time just like anything else. So you do have to put in a lot of hours if you want to get good. So you do it if you want to do it and you enjoy it. Now, is it worth it as a return on investment for your career? I think so, yes. But it’s also very hard to make predictions about how the job market will move forward. So—

FalconSpy: We have just some timekeeping. We have a little over 10 minutes left. We’ll try to get through as many questions as we can within that time. So this next question is a photo question. Will there be any plan to allow CTFs to count towards streaks? It was the first time that question has ever even occurred to me ever.

0xRy4n: Current plans, I don’t think the answer is yes. I don’t think there’s any active plan in our current roadmap. Future plan?

0xdf: We don’t comment on future plans.

FalconSpy: It is now on Ryan’s roadmap. All right, another photo question here. Which field of cybersecurity is predicted to be the least, sorry, which field of cybersecurity is least predicted to be damaged by AI, as in what would AI be the worst at?

21y4d: I’d say in general, AI is the worst at whatever there is a lack of information on, so it wasn’t trained on. So just look for a field that, for example, let’s say coding, there are so many… there’s a lot of stuff to train it on, so it’s very good at this stuff. But if you look at certain stuff that, nothing’s coming to mind, but you can’t find a lot of stuff that it can be trained on, then the AI would not be as good at. So I’d say this is like the generic answer.

gill3tt3: Yeah, I think there’s a lot of stuff as well. Looking at current state, AI is fantastic as an augment to red teaming, but it’s also very, very bad about being quiet and subtle at things. So better for pen testing, not so great for red teaming necessarily. But there’s also practical limitations. Like if you’re going in and poking at PLCs or ICS systems or something, which I guess that’s a double ATM machine. Anyway, if you’re poking yourself where you need physical access, obviously much more difficult. It can arm you with the right information, but you still need to actually be able to do it and execute the other parts of that sort of operation, literally getting into a secure facility, that kind of stuff. So there’s a lot of aspects like around cybersecurity that also build on that, but yeah.

gill3tt3: Yeah, I think that’s going to be the constant in all of this, right? Like it’s a force multiplier, it speeds things up. If you’re relying on AI to literally do the job for you, you’re not going to last long or get very far.

0xdf: I mean, so I agree. I think the things, to take the question at face value, I think the things that are least well known are like OPSEC, defense evasion, things that, frankly, we don’t teach publicly very often. Like at Hack the Box, I don’t know if Academy has a defense evasion class section now, but it wouldn’t surprise me if we don’t. And these are just not things that are taught really broadly. I also, I take a little issue with the question though, because like I don’t think AI is damaging security at all. I think AI is making it, is improving it. And I think it’s honestly like a potentially a path towards some really good, I mean, I guess damaging in the sense that like things could get a lot more secure. And I think it’s going to be a real mess before we get there. But like, I don’t think AI is a reason I would say like, don’t get good at, don’t go learn how to do things. Like learn how to do things with AI and you’ll be better at it. It’s not, it’s not replacing security jobs anytime soon.

ippsec: I’d imagine the field that’s going to be the most resilient is something like hacking into something biomedical, because you’re like fighting all the guardrails there. And a lot of companies will be probably like putting resistance to do hacking plus biomedical. But I’m with David. I don’t think like AI’s hurt security. It’s improved it mostly. It’s a mess. I think the worst thing is all the GitHub issues that it creates and all like that, just AI spam dealing with. But eventually—

FalconSpy: —people will get better at handling that. I’m struggling to put what my thought here is into like a—

0xRy4n: —cohesive sentence. I’ll give you an example of something that AI struggles at in general. And it’s not really because the AI struggles. AI will struggle to do things where it has limited capability to act in the ways that it wants to act. So for example, if it needs to interact with third-party systems and those systems have very poor interoperability, they don’t have a published API. They don’t have an MCP. You know, it’s some sort of like click-based software or something. AI struggles to deal with systems that it can’t get access to in a programmatic way that you as a user might be able to. So a lot of companies run on like cloud infrastructure. A lot of companies have dozens of different SaaS tooling where a lot of the company exists in SaaS. Not all of those are going to be accessible in an easy way from the AI. And then you also get into, in terms of a pen test, you also get into these really gray areas with scope creep and what’s out of scope and such. I am struggling to make that into a nice neat sentence for pen testing, but I think the main times where I run up against limitations with what can be done with AI, it’s because the AI doesn’t have a good mechanism to do the things that it wants to do programmatically. The world was, the internet was not made to be perfectly interoperable, particularly when proprietary stuff started coming out. That’s changing slightly because they are adapting for AI. But there’s still a lot of cases where interoperability between things is low. And that does have some level of security benefit when you’re trying to prevent something from—

FalconSpy: —programmatically accessing your stuff. I don’t know if that makes sense.

ippsec: Unrelated, but my favorite thing AI has done is start killing SaaS. Like, there’s so many products nowadays that are just coming out that are just AI clones of SaaS products, like the one I found out today with Sparky Fitness, which is like an on-premise MyFitnessPal. It is amazing.

0xdf: Yeah, you’ve been talking to Control Zero.

ippsec: Indeed.

FalconSpy: Sorry, I was pretty much laughing at this next question, which has been surprisingly outvoted. Is watching Mr. Robot going to make you a better larper?

0xRy4n: I only remember the first season, but I remember thinking that the first season was not that bad in terms of representation. I remember thinking of all of the hacking stuff I’ve watched, this is probably the one most grounded. But then the later seasons happened, and it very quickly became no longer grounded. I was going to say,—

ippsec: When you started that sentence, I was like, have you finished the series?

0xRy4n: Yeah, the drama started over. I remember that.

gill3tt3: I would take away as well. Focusing on the first season, a lot of it is indeed quite accurate. They had a lot of really good consulting for it, but the timelines are wildly unrealistic. Like you’re not just going to randomly show up and hack a machine or salt. Like when he walks into that CTF, he’s like, oh, here’s your solution as he’s walking past. Like, okay, sure, bud.

ippsec: Yeah. Well, I will say Silicon Valley is the most grounded IT shell.

gill3tt3: It is depressingly realistic.

ippsec: The only thing ungrounded about Silicon Valley when it came out was AI, and it turns out it’s actually true.

0xRy4n: This is not super relatable. You know what really gets me? It’s whenever they talk about encryption, and like, oh, this is military grade encryption, but I can still hack it. It’ll just take me a little longer. It’s like, dude, no. So encryption either works or it doesn’t, right? You’ve either properly implemented the algorithm or you’ve improperly implemented the algorithm, but if it’s a proper implementation, it doesn’t matter. You’re not cracking it. For a second, I was just trying—

0xdf: —to say, no, you can’t crack military grade encryption.

0xRy4n: Well, no, it’s just like, if it’s implemented, if they correctly implemented the algorithm, they didn’t roll their own crypto. It’s like, look, man, I don’t know what to tell you. That data is not retrievable. It’s not just, oh, I’m going to type faster on my keyboard and suddenly it’s going to be cracked.

gill3tt3: But what if you’re quantuming it? Oh,

FalconSpy: Okay. I got one. I posted my favorite one, but it’s in the chat. So it’s from NCIS. It’s the four-handed hackers one keyboard. What’s your favorite hacking scene in a show or a movie that is so unrealistic?

gill3tt3: There was a movie. I’m trying to remember the name of it. Masterminds? I think it was. Anyway, at the beginning of the movie, they were hacking some game company, and it’s like a 3D maze with skeletons and stuff, and they got to fly through it and get to the end to get root access on the machine that’s hosting their game they want to pirate. Patrick Stewart was there. I don’t know. Somebody can find it. Every hacking—

21y4d: scene—

gill3tt3: sorry.

21y4d: Any scene that ends with, “I’m in.” Yeah.

ippsec: Yeah, I was going to say it’s hard to beat the Hackers, telephone booth, virtual reality hacking the Gibson.

FalconSpy: I’ll tell you what, I’ve been at work. I’ve been going—

gill3tt3: Well, I’m just hacking the wrong machines, I guess, man.

0xRy4n: I love it when all security is abstracted to just some weird cyberpunk UI. Everything can just be this weird virtual reality UI, and there should be no actual anything. It should all be UI. It’s great. That’s the world I live in.

ippsec: I mean, Pac-Man doesn’t tell you to use a flu shot when you get infected with the rabbit, so.

0xRy4n: You know what it is? It’s the cyber equivalent of the dungeon crawler movies where they like, oh, in order to get into this tomb, you have to solve the puzzle and do some crazy task. It’s like, okay, so whoever mentioned security for this vault didn’t want to just use any sort of actual security. They just wanted to make sure the person who solved it had to go through some clever puzzle. They’ve taken that trope and they’ve just applied it to security. So it’s like, ooh, we’re not going to apply actual security, but whoever did this, whoever hacks this, they have to be really good at mazes. They better be really good at Pac-Man.

FalconSpy: Okay, I think we have enough time to answer this last question. One—

ippsec: —second. I have something to add on to Ryan. One year at CCDC, we may have reflashed a lot of firmware on people’s VMs to now the OS booted straight to Flappy Bird with no OS. And in order to get it back, they had to play Flappy Bird and get a certain score.

0xRy4n: See, perfect. This is how security should be.

FalconSpy: Do you remember when people were paying like $1,000 for iPhones on eBay just to have a copy of Flappy Bird? Like what? Like the good old days. All right. I—

0xRy4n: understood that. Unless,—

FalconSpy: what’s that?

0xRy4n: They started banning people. So I got around it by selling a phone. I said, I’ll install Flappy Birds after you own it.

FalconSpy: All right, last question for this week. For the CWES on Academy, is it still worth it to learn web exploitation? And do you think the lab materials still hold valid in today’s day and age?

21y4d: I’ve reviewed it recently and I’d say it is still valid. We do actually review our certifications from time to time to make sure they are up to date. And we tend or try to update them whenever they are not. So in terms of content and validity, the attacks themselves are still valid. In terms of using AI, like I said earlier, you have to use the same techniques taught in CPTS, CWES, and all of those, and learn how to utilize AI to boost your speed and boost your skills basically whenever you are doing whatever you’re interested in from those, rather than actually just prompting the AI and letting it do everything.

FalconSpy: Yes.

gill3tt3: All—

FalconSpy: —right, thank you. Anyone—

gill3tt3: —else? Chad’s comment is actually a good throwback to the question earlier about just getting started. There’s always something new to learn in this. There’s always things that are going to be interesting and worthwhile. Sort of how you structure that is, of course, to choose your own adventure thing that’s going to wind up with you dying in the Goosebumps book 50 times, but lots of opportunities—

FalconSpy: —to, of course, correct from there. Anyone else? Cool, all right. Thank you, everyone, for joining us for this week’s Cube Talk. Hopefully you enjoyed our session here. If you’re interested in future sessions, you can take a look at the top of Discord at the event section. You’ll see when these happen in your local time zone. They’re every Friday unless stated otherwise. You can also see other events that we’re going to be hosting here in Discord as well. We do have the Home CTF in September. It’s one of our team’s CTFs. So if you’re interested in that, feel free to say you’re interested as soon as the event goes live. You’ll see the notification and all that other good stuff. But you’ll get this recording for this week’s Cube Talk on Spotify and YouTube next week. We hope to see you next week.

This post is licensed under CC BY 4.0 by the author.