Cube Talks: July 17th, 2026
Disclaimer: This transcript was generated with AI assistance and has been manually reviewed and edited. Despite best efforts, some inaccuracies may remain — please use your best judgement when referencing specific statements.
TL;DR / TL;DL: HTB panel covers CTF design, $8/mo student plans, career networking tips, AI policies, seasonal fairness rules, and upcoming events
Watch on YouTube: Cube Talks – July 17th, 2026
Listen on Spotify: Cube Talks – July 17th, 2026
Transcript:
FalconSpy: Hi everyone. Welcome to this week’s Cube Talk. I am your host, FalconSpy. This is your opportunity to ask our panel of staff and volunteers any questions you might have about Hack the Box and the services we offer, as well as InfoSec questions in general. We’ll do the best we can to answer as many of your questions as we can within the next hour. You can use the forward slash Cube Talk command to ask your question to the panel. You can use that same command to also upvote questions to the top of the queue. Questions are first in, first out, unless upvoted and said otherwise.
You can find the command in the chat. We’ll introduce everyone here on the panel so that way you know who they are, what they do, if you have any targeted questions, and then I’ll sound like a broken record again, and then we can go to our questions. So we’ll start off with Chad B. Who are you and what do you do?
ChadB: Chad B here. Hey, good morning or afternoon everyone. Noob former pen tester and SOC analyst, current routine operator learning from a fire hose, and I am very confused.
21y4d: Hi everyone. I’m Zeyad. I’m from the academy team, and I’m in charge of academy modules, paths, exams and certifications.
FalconSpy: Currently my favorite person. Then we have Ryan.
0xRy4n: I’m Ryan. I am the head of tech ops. I do like internal animations and business software and such, and now mostly we build like the internal tooling.
FalconSpy: And I am FalconSpy, one of the community specialists here, also full-time red team elsewhere. I realized that the command wasn’t working. It should be working now. So sorry for everyone who’s trying to put their command in, but broken record time. You can use that command forward slash cube talk to ask your question to the panel, and you can use that same command to put questions that you like to the top of the queue, and questions are typically first in, first out unless they are outvoted otherwise.
I will put the disclaimer out there now. We typically don’t discuss things that we’re working on or timelines in case we either miss a deadline and we don’t want to give anything to our competitors. You can still ask your questions. We’ll probably fall back on the disclaimer, and you know we’ll go from there.
So our first question to kick things off for this week will be: what’s the hardest part of designing a challenge that’s difficult without feeling unfair to others?
0xRy4n: Well no one here is on the challenge team. The closest person here to content is Zeyad. So I don’t know if Zeyad has any specific thoughts. I have some general thoughts.
21y4d: Yeah, so on Academy what we try to do is try and make it as realistic as possible and away from a CTF as possible. It would be similar to something you would find in a real engagement. But one of the key things we try to keep in mind is we call it the variance between what is shown in the section, the demo, and the actual exercise.
For fundamental and easy modules there’s usually little variance. So it will not be a copy paste from the demo that is shown but there will be very little change in the exercise you will face because you know it is meant for beginners and so on. But when you go to medium there will be some change, and in hard modules there will be significant changes.
Sometimes it’s the same concept but completely different example so you have to thoroughly understand what was shown to be able to answer and solve the challenge of the exercise.
0xRy4n: I’ll extrapolate slightly to general challenges. I think it’s mostly what Zeyad said. From what I understand, the biggest thing you have to look out for is you want to make something hard or at least appropriate for the difficulty rating that you’re aiming for. So if you’re making something that’s hard then you want to make it hard. If you want to make it easy then don’t want to make it too easy but do this in a way that realistic and also satisfying.
Just pulling like a CVE and being like oh okay you pop the CVE and then that’s RC and that’s the box is not very satisfying though potentially realistic. It’s generally you have to find a balance between building an exploit chain that’s satisfying, realistic, feels like it could actually exist but is also appropriate for difficulty level.
And also hasn’t been done in our backlog of content too many times because you don’t want to be too repetitive. It’s perfectly fine to submit the same exploit technique many times but present it in a new way giving something new. You generally just want copy paste exact same exploit chain on 20 different challenges or boxes because that gets kind old quite quickly.
FalconSpy: I don’t think I have anything to add. I mean, I’ve made one or two boxes myself but they were targeted towards easy things and aren’t on Hack the Box. Yeah, to Ryan and Zeyad’s point you know figure out what your demographic is going to be when targeting individuals who are going to perform your machine or challenge and go from there right? If it supposed to be an easy machine don’t litter thing full of rabbit holes that might take someone in different direction obviously those rabbit holes may be real world situation but if you’re gonna throw a rabbit hole maybe throw one instead of 20. Obviously I’m exaggerating on the 20 but try keep realistic, think your demographic something that might easy to you and really considered hard content might be hard for someone else right like so just or sorry someone you may think it’s easy but might be hard for someone else so just know think of your demographic.
I will go ahead and go to our next question here this one an upvated question. So there is a student in India, many students live around $80 per month. Academy path costs nearly $700 which impossible for someone afford in India. For people who want learn anything we can recommend? Do we have student discounts regional pricing scholarships alternative ways to access content?
21y4d: I mean for students specifically expert level exams and above are not technically meant for students that’s why price taken into consideration that someone actually an employee but CPTS level CJCA level these covered in student subscription which quite affordable. I’m not really up date on regional pricing but think this is something HDB considering so could may coming I’m sure to be honest but yeah for students any certification same level as CPTS and CJCA should be affordable through student subscription.
0xRy4n: All of the student subscription is $8 per month USD and gives you access all content up to including Tier 2 which includes everything from CPTS path, CWES path, CDSA, CJT I think that’s it or might forgetting one but includes everything up to including Tier 2 for $8 USD per month. So effectively same as silver annual just minus well one it’s monthly subscription not annual subscriptions and also minus included exam vouchers.
21y4d: And like the longer feature.
FalconSpy: Make sure you add your student email if have EDU email. If university doesn’t have EDU email contact our support they’ll do some verification steps to make sure that are true student at a university and then get set up.
21y4d: Sorry…
FalconSpy: You’re good all right next question here is an upvated one. So how do you make transition from labs modern web apps especially as new pen tester? While research while can do research try new techniques during test happen happens, how keep improving so get more hits per engagement?
21y4d: I’d say just do it. Just jump in.
ChadB: You can spend like I always say you can spend weeks and months planning for stuff. I have notebooks back there with all kinds of plans nothing’s going to happen until you just do it go for it will absolutely learn along way don’t any detailed specific insight on path talking about but lot us get our heads need plan thing or pick up keyboard just go for stop thinking like Nike used say: Just Do It.
FalconSpy: Guess answer your question right if transitioning from what doing here platform to might do during actual pen test think all machines may interact with challenges had web app then how did you about deploying methodology against those and use that for pen tests assessments try use learned apply every new machine comes out should hopefully theory teach something new about web apps look for something so right never interacted API system before we have like machines API go look ipsec.rocks sure there plenty there can just type in API something might pop up but retired machine take what available and techniques you’ve learned on that then apply assessment.
0xRy4n: I’ll add slightly to this think doing machines challenges academy inherently valuable want catch because so much of things quickly is like have ever seen before? It’s very difficult if never even heard XXE it’s very difficult from first principles derive XXE thing can do web app pen testing when’ve never seen before but if’ve seen then know you can catch fact might something attempt exploit rather quickly.
So more things seen done, more things able catch rather quickly generally think this only problem early on because been doing long enough probably seen most common exploit techniques going find out real world at least once. Once just been doing like there’s not infinite number them. There are infinite ways they can show up but finite number actual techniques so if’ve been doing for while still finding trouble finding everything then would say go back basics focus enumeration because aware techniques just not finding need enumerate more yeah I’d those two things: Just do stuff to aware that exist and then focus on enumerating find places use them.
FalconSpy: We have another upvated question here will probably fall disclaimer but’ll ask anyway will be getting malware analysis certifications from Hack the Box soon?
21y4d: Yeah like you said we cannot talk about any upcoming content or unreleased content whether do it unfortunately I comment.
0xRy4n: We baited them by starting that sentence off with yeah…
FalconSpy: Again probably disclaimer here but will be getting mobile app anytime soon? Possible for Academy side to help study learn on go? And we’ll just fall back disclaimer if working not going say are or aren’t, not going say when release date.
0xRy4n: So want address something from malware fact that I smile does mean anything. I smile at every question…
FalconSpy: I would say just look social media do release one ever then’ll know yeah’d go for anything right worried about coming out with new certifications, paths just look social media whenever something happens happen it’ll be there and it’ll announcement here Discord too all right this is another individual Pakistan they’re really enjoying platform but need cubes ways can go getting cubes themselves excited meet us asking free ways potentially get cubes paying them?
0xRy4n: You’d one answer come Mr Community Guy…
FalconSpy: Well outside doing tier zero content as perform parts of it will award you cubes just completing exercises long do them. Outside that we have some regular giveaways in giveaway channel where can potentially win free cubes depends much want give away how often think usually once every three months decide to give away cubes, usually VIP plus but depends community team feeling month as we do giveaway every month.
We now have new competition thing which is guess another giveaway but guess every month just did first one this month: Every month post question you must give best wrong answer. Question that has best wrong answer or most outvated wrong answer will receive whatever prize gives away for that too so’ll be giving two giveaways each month outside believe there are cubes given place silver above season main platform get Kraken all need four flags silver receive however many decide to give out for season otherwise don’t really other way get free cubes.
21y4d: All right moving on…
FalconSpy: This is another question person earned CPTS have one year work experience ET, one pending CVE achievements yet having issues remote pen testing jobs either closed require US citizenship five plus years experience nothing changed email replies other than you know we regret inform selected before after CPTS what realistic way get remote pen testing job internet everywhere says millions cyber jobs long thing basically using bunch different systems Indeed LinkedIn Glassdoor so recommendations someone has CPTS land themselves remote pen testing job?
ChadB: Networking. Ryan going follow anything I say this but human networking just important if not more than actual skills do thing myself have had I’m my third cybersecurity job and’ve not gotten even one interview even interviews I’ve had that didn’t successful getting a job none happened without person usually internally extra another human referring me to job which where’ll fall back on saying other line will always say everything you do, everything study so make it were publicly accessible someone else find when eventually meet interviewer they say tell what have done know can say no let show here’s my YouTube channel GitHub this that forth generally far actually finding work cybersecurity as someone chat making fun me right now will human networking. Make sure put yourself there easy for me to say but here start you’re already with us Discord keep talking meeting people jump VCs you know put name out there so on and so forth easy for me to say also not easy for me to say where’m at took long time just happen know lot good people that know well enough say yeah Chad would good this Ryan would good laughing maybe not bad this or whatever but definitely human networking pass…
21y4d: Yeah I don’t have ton of that.
__0xRy4n: That’s correct answer is networking okay so there few other points guess can touch on millions jobs cybersecurity thing know true long time know lot public discourse number disparity between cognitive disconnect and perceived entry level market think lot isn’t necessarily entry-level quite hard get foot into door easiest way get foot in door as Chad said network meet people form connections leverage to get job.
With must be US citizen thing probably stems two facets well one applying job based U.S trying remote not US citizen reason don’t either doing sort work government agencies require certain levels clearances risk profiles appetites they’re fond non American citizens involved or company simply want sponsor visa so if company international only have U.S office then forced to sponsor visa because can hire from international office workaround apply more companies that are international apply companies offices in UK ones have offices EU even American company apply for companies these places means get employed by subsidiary much less deal with terms visa friction such.
FalconSpy: Other side yes there very few red teamer pen tester roles junior level open can outside networking obviously going help tremendously, you apply organizations if they remote jobs where doing IT work or help desk even like NOC SOC and then if have internal red team internal testing team always pivot into teams at least foot door yeah pretty hard land yourself junior role because so few them field most companies looking senior levels up architects things like outside networking look other ways get your foot in door yeah I mean think all these AI job application services too know great take grain salt you’re going use definitely look how operate before start spending money on apply different places for and then someone chat made good mention there are some risks fake job listings also always thing.
ChadB: I would only add that articles million jobs cybersecurity should do right now just go stop reading stuff study practice network call it none those sensational articles headlines going help makes you excited probably not good headline depresses you probably also good if boring like hey moderate chance getting job in cybersecurity this great life advice general.
0xRy4n: Any headline that make feel emotion strongly is probably not a good headline takeaway…
ChadB: For anyone sent phishing email all have to do get someone emotionally riled up enough stop thinking just click link you’re good put passwords like hey offering if it’s emotionally charged feel anything thing reading probably advice. If excited depressed either direction go find something else read. Like go find boring one white paper just break down level but just thing keep head study network talk people call sorry…
FalconSpy: Send me whatever phishing links click link fine click anything anyway all right’ll move on this is another upvated question think pretty much questions point have been upvated context red teaming careers concerning actual market would rather favor AI oriented red teaming more classical red teaming active directory things like that or both? Chad since latest resident red teamer want answer first…
ChadB: Can you say again heard half of it. All right in context red teaming terms furthering career better go after AI-oriented do more classical where hey I do active directory stuff rely not on should do both? First off looking Ryan so AI AI terms red teaming or pen testing SOC analyst Linux guess up there Active Directory, Linux is thing that now right can use use AD work. Can use Windows Linux forth know how abuse it just like Active Directory, Windows and Linux know how take full advantage absolutely abuse heck out of lot marketing happening right now going wake decide which model need for today put on laptops gonna keep going all this marketing hopefully gone by then but as far what to do AI is thing technology stack world leverage abuse if have to take advantage get further into network system forth where Red TV part comes in know how leverage write script so forth back whole thing headlines make feel something stop reading gain knowledge use document and moving really Ryan pent up can see he’s expanding…
0xRy4n: No no got nothing I pin going pop balloon got add here.
FalconSpy: Think this kind good segue Zeyad could probably talk little you know AI path things like that yeah so Zeyad it’s if want go route otherwise’ll chime experiences red teaming what think people should do…
21y4d: Yeah so the path under COAE certification about attacking AI models rather than using for actual from currently have CPTS CAPE on and also we have few modules recently released utilizing basically know kind tools use when doing pentesting on yet anything red teaming absolutely.
FalconSpy: I think helpful right sense point another you’re red team going to some type model whether Frontier local models created different organizations right sure seen maybe haven’t like someone’s hey want place order chicken nuggets something McDonald website then they know this Python library then their model spit out right don’t using Frontier or local but at point or another on red team going have to redteam some kind model so path would help that Brad was something…
ChadB: No agreeing everything guys saying.
FalconSpy: Got you okay as someone who’s on a red team played around Mythos Fable whatever else want go ChatGPT cyber models yeah tools they’re part tool’ll probably included techniques used could also help with running engagements or multiple deploy agents going babysitting if not company team doing properly know when’ve used Cyber treated junior red teamer did great job couple things don’t set loose YOLO mode against production basically sitting there approve every little command want run YOLO you’re having knock something shouldn’t touched yeah think to point question answer for me both knowing classical good then using AI and redteaming AI definitely going learn.
21y4d: It’s like Active Directory exactly all right anyone else move on…
FalconSpy: Moving another upvated here how much use of allowed in seasonal machines because people get blood around sub 4 minute times even sub3 and 2 just spawn machine before first it?
0xRy4n: Yeah mean always been able to like crazy fast times ever A-team birds aren’t real funny enough AI generated predated LLM craze all these teams have histories having ridiculously fast bloods because automated scripts for everything you could imagine now’s not say none seasonal are policy that allowed chuck harness at Hack the Box directly so it is against Terms Service just be like hey Claude hack this technically against terms say hey I’m looking website see things can try but can’t have agent directly interact with infrastructure otherwise violating which lead account being banned then progress deleted yeah enforcement really talk about plans for…
21y4d: Another photo question here.
FalconSpy: This person is new in field just finished high school exploring preparing CompTIA Sec Plus CJCA exam recommendations find additional resources advice how go doing pass?
21y4d: Path self-contained definitely enough for you to pass don’t worry external focus path itself try understand content within each module try exercises skills assessments solving even use provided solutions other kind help make sure that well have good understanding of module itself should able pass exam.
FalconSpy: We’ll go next upvoted question seasonal machines 100% fair? Some people got flag impossible amounts times no human get think goes back just what saying earlier…
0xRy4n: That’s I said mean know have policy also true even before AI people also got bloods in stupid amounts of time, stupidly small do we additional plans ways can try improve integrity make things fair? Yes. Can tell those plans No…
FalconSpy: Maybe maybe one day get XCT here doubt though due to timezone differences but sure’d interesting hear how would first blood lot machines think he placed you know first place couple seasons before became part team.
0xRy4n: Some of XCT’s like historical times are stop two minutes yeah sub2 absolutely ridiculous pre AI…
FalconSpy: And by magic I mean Ipsak claiming sub one minute so…
0xRy4n: Yeah but Ipsec’s sub1 was Eternal Blue barely. All right now Ipsec link us which got sub 1 that way can uh Oh it was Eternal all right yeah. And because he knows like oh’ve to load up even before spawn second IP comes pushes button…
FalconSpy: Alright yeah maybe one day get XCT but said due timezone differences doubt alright’ll move on question here do networking have plus connections so referring connecting other people number connections LinkedIn cold email?
ChadB: South Korean CEO CEO South Korean company yes. That person following up response gave earlier 1500 people great you’ll exposure post something many those people DM how had conversation actually followed typing minute ago wanted say CGCA when saying networking meeting I’ll go further said before every three jobs’ve gotten interview met between Twitch, Discord real life to include Hack the Box right meet network like talk ask answer places are doing tracking Arslan think doing get know email CEO all day guarantee never going response because probably weirdo that’s how isn’t bad person has interest me Falcon say hey I know guy Chad great fit talking. Meet people actually 1500 LinkedIn absolutely outstanding job expanding exposure field of expose some be here hang Hack the Box Discord talk where was tracking you’re doing right versus just having big network doesn mean anything legitimately vouch for would Falcon Ryan Zeyad boss right now seem knowledgeable one guys gave resume right give to my know same chat couple people done two with because know saying meet get someone social engineering practice knowing well enough feel good about taking their handing it’s credibility place work.
0xRy4n: Yeah I’ll follow up whole point networking not make number go website have some artificial says oh connections people point to actual human serve almost pre interview right go conference somebody sit down conversation 30-40 minutes drinks talk subjects projects worked get know now knows connection when start thinking want fill job role going think okay first thing hire random don’t know gonna think do I anybody who’ll good fit they’re going people networked with obviously still Hack have accepted offers but two best ever got one dinner security event pure chance person sat down had few hours other best offer worked long time reason both these out of blue offered because known connection knew skill type looking fill spot thought doesn’t work if just send connection request LinkedIn actually forge bond makes them you way they think generally say better things in person can’t online certainly won by sending someone request with like high…
FalconSpy: I don’t want add much but guess real quick forgive remember correctly Zeyad were referred did cold apply Hack the Box? Explain going after well imagine sounds from well had interactions know of three staff here panel right all three have interacted made name interacting people platform, other staff like Ryan got hired because just be on time then Emma reached him’s like work and you one senior mods back before joined Offstack little came they’re we new position open want in Zeyad case right was interacting with platform thought hey what do and…
0xRy4n: Yeah I would say accurate single interactions Hack the Box worked staff knew were even had job offer.
FalconSpy: Yeah think nailed one doing little timekeeping we have under 10 minutes left’ll best get through remaining questions here another outvated make sense take part next ETF guessing Cyber Apocalypse beginner only studied half year…
0xRy4n: Yes. There’s nuance it just yes participate costs nothing would not?
ChadB: Quick CTS story one of intros getting into thing streams starting friend named call out bugged heck Mayor Eleven Discord join them in he you should I don’t know what talking Mbapp no understand do that’s keep saying grab keyboard right jump doesn matter better take something away repeat day step up leap faith whatever go Full speed ahead Damn torpedoes full forward.
21y4d: Go Navy…
FalconSpy: Next one another outvated think point What is process for becoming Hack the Box community meetup ambassador? Any advice giving into getting that send email to community at hackthebox.com Community team will take look probably invite interview see explain requirements No from our here right now answer Ryan also posted link chat so hackthebox.com slash host Google people listening later recording purposes yeah community hackthebox.com visit link all right next another outvated how start research finding CVEs zero days based that work? How do we start research or finding what tripping over my words today…
21y4d: How find is question pretty much.
0xRy4n: I mean look man if there nice three step plan could get you I would be very rich.
Zeyad: And don’t know answer this.
FalconSpy: I mean need read code static analysis other things can help look at interested zero day aspect where start looking different libraries applications published immediately pick then work see find usually typically only found soon something released…
21y4d: I mean I give you three step process: Number one get lot money, number two subscription access to Mythos, number fire Linux repo profit okay.
0xRy4n: Actually take back do have guaranteed quick way farm CVEs know even leak right now just go exploit DB search something name is like web wedding planner app 1 Excel sheet then Google that website going once a week publish new demo thing generic name 1 and set up script scrapes site every single time downloads feeds to AI model find in two seconds things are student apps count get legitimate literally farm nonstop doing there you go quality ones? No all WordPress modules.
FalconSpy: Is technically considered unethical life pro tip kind like ChadB depends profile or…
0xRy4n: I but do they accepted so easy find them all have bugs Life pro tip…
FalconSpy: Do what Ryan said Zeyad spend lot money on Mytho sorry Fable.
0xRy4n: Yeah I misinterpreted question actually wanting legitimate if want farmable ones ChadB WordPress modules…
FalconSpy: Alright uh next another voted you could erase one piece cybersecurity internet what would be?
21y4d: One just gave search equals jobs think.
ChadB: Um third cybersecurity what the hell is flag Um uh third job don’t have OSCP any offset yet CRTO need know main thing I Security Plus CYSA plus other certs most people wouldn’t recognize even were Human networking so search get this cert get you’d all of that…
FalconSpy: I agree, you need X cert to get a job get rid it. Have one specific mind but will not talk ill about other orgs their certs so ChadB yeah also versus uh don’t work Hector Box OSCP CPTS yes well what should I OCPS or which better difference two things literally different stop comparing they’re all first study knowledge achieve now benchmark can market that’s comparison painful listen CWES BSCP cover materials overlap greatly are things it kind tell bit painful to think about normally Discord server calmly remain calm would explain like one CPS other thing employer knows ready do day these well known I’ll there.
FalconSpy: I’d point out how Zeyad hasn’t answered yet but want this question evoked strong emotional response Chad didn’t listen own advice alright uh…
21y4d: Um nothing comes mind honestly Speaker undefined Right.
FalconSpy: All right anyway I think we have time for one last question isn’t an upvated don’t think can answer but’ll ask out Hack the Box retain information about people work through machines as metrics collected unintended paths anything if so used?
0xRy4n: I can answer take look privacy policy outlines quite significant level detail exactly data collect how do find there mention currently ever would reflected extremely compliant GDPR uh probably one most companies compliance officer takes deadly seriously far more seriously think EU…
21y4d: Maybe we have time for more hold on let see next is.
FalconSpy: This one simple enough answer alright does CPTS require any previous knowledge before work path?
Zeyad: Um depends your previous cybersecurity usually CJCA first step coming absolute zero ground you don’t have any previous knowledge infosec computer science usually should start if do basics then can with and see how…
FalconSpy: Cool I think wraps this week thank everyone joining us for kubetalk host these every week around same time take look top discord to see when event occurs local in your timezone also say interested future cube talks receive alert them we have other events coming up end month Cyber Apocalypse ETF happening starting Friday July 24th you can start local as part of Discord event also trivia event happening July 31st take look there see happens local time zone um and then we also Cube Cast recording going happen August bunch new events happening uh in discord here as well on platform.
0xRy4n: And’ll be at Defcon…
FalconSpy: Will also have own exhibitor booth Parrot team Hack Box think’ll blue team village Yep 0xRy4n We’ll two separate maybe three within LV find besides that wraps things up get recording out to everyone Tuesday thank everyone attending this week see next week.
21y4d: Thanks everyone…
