Cube Talks: July 31st, 2026
Disclaimer: This transcript was generated with AI assistance and has been manually reviewed and edited. Despite best efforts, some inaccuracies may remain — please use your best judgement when referencing specific statements.
TL;DR / TL;DL: Covers study tips for CPTS/CJCA, career networking, AI use in CTFs, and transitioning from labs to professional pentesting.
Watch on YouTube: Cube Talks – July 31st, 2026
Listen on Spotify: Cube Talks – July 31st, 2026
FalconSpy: Hi, everyone. Welcome to this week’s Cube Talk. I’m your host, Falcon Spy. This is your opportunity to ask our panel of staff and volunteers any questions you might have about Hack the Box and any of the services that we offer. We’ll do the best we can to answer as many questions as we can that are related to InfoSec as well. You have the next hour to ask your question to our panel of staff and volunteers. You can use the forward slash cube call command to ask that question to the panel. You can use the same command to also upvote questions to the top of the queue. Questions are first in, first out, unless stated otherwise. If it’s upvoted, it’ll jump to the top of the queue. We’ll introduce everyone here on the panel in case you have any targeted questions you want to ask us, and then we’ll go to the questions. So in no particular order, we’ll start out with OXDF.
0xdf: Hello, OXDF. I am a former Hack the Box lab architect, and I currently work in AI security.
Emmax0: Hey, I’m a senior community operations specialist, I think is the title on paper. But I’m around here on Discord. I do sponsorships. I do events. I do a bit of everything.
21y4d: Hey, everyone. I’m Zeyad. I’m from the Academy team. I’m in charge of Academy modules, paths, certifications, and exams.
0xRy4n: I’m Ryan. I am the head of technical operations. I deal mostly with internal automations and nowadays, like a lot of the internal custom software and tooling and such.
FalconSpy: I am FalconSpy, one of the community specialists, also a full-time red teamer or elsewhere. This is the part where you just sound like a broken record. Use the forward slash kubetalk command to ask your question to the panel. Use the same command to also upvote questions. Questions are first in, first out, unless stated otherwise, where they will have been uploaded. So we’ll go to our first question here: What are some useful study tips for Academy that aren’t so well known?
Emmax0: I would say just whatever works for you. That’s the thing I found with study tips, at least for me personally, is everyone’s different in how they learn best. I would say spend the time investing into figuring out how you learn best, what works for you. And then so that way you can apply that in Academy, wherever else, you know. Some people learn better by reading it, thinking about it, taking more breaks, breaking it on the one… just figure out what works for you. Learn how you learn and apply that to everything.
21y4d: Yeah, I was going to say something similar. It is difficult to give an answer that applies to everyone. There are multiple approaches and processes you can follow to enhance your learning journey. Having said that, we have actually created a module very early on in Academy. It was one of the first few modules in Academy to address that exactly. We wanted to create this module before even creating the actual contents in Academy. And this module is called Learning Process. So I highly recommend checking this module out. It’s a free module. And it basically answers your question.
0xdf: One thing I would add to that is like, always be looking for ways to improve, like figure out a system that worked for you. And like at the beginning, you’re just gonna be changing a lot. And then, but like even as you kind of fall into your system, always be like thinking about what’s, what are my annoyances with like, how did, why did my system fail me this time? And like, if there’s a way, if there’s something you can do on a process wise or technology wise to improve that, like, go for it, like be always be looking for ways.
0xRy4n: Um, I don’t have a secret method for Academy specifically. I have the way that I think is really good to learn in general, which is, um, called the Feynman technique. Most of you probably have heard of it at least once. The idea is basically after you learn something, um, try to explain it simply to somebody else or pretend like you’re explaining it simply to someone else. So pick a person in your mind who’s ideally not technical, like your mother or a random hobo on the street. Um, and just imagine yourself trying to explain the concepts to them. As you do that, you will find there will be bits and pieces of it that you struggle to explain. That’s where you find the gaps in your knowledge. Uh, you go back, you figure out what those gaps were and you fill them and then you do it again. Uh, in the process of like trying to explain something to somebody else really makes it stick in your mind and makes you remember a lot.
FalconSpy: Uh, we’ll go to our next one here. Uh, last week Oracle released about a thousand CVEs in a day. What are your thoughts on all of this?
Emmax0: Falcon, I’m curious what your thoughts are.
FalconSpy: I don’t know if I’m technically allowed to comment on what my thoughts are on that as an Oracle employee. So I plead the fifth.
0xdf: Oh, I got a lot of thoughts. I’ll jump in. Um, I think in the short term, we’re going to be in short term being like at least a year, if not five, we’re going to be seeing just like gobs of CVEs falling out of products across, across everywhere. Um, AI is getting very good at finding these things. Um, there’s no one AI that’s special. They’re just, they all have skills at finding these kinds of things. Harnesses are important. Like we’re going to start to see this stuff happening. Um, I don’t think from my experience working on defensive sides, I don’t think we’re in a position where the answer can just be like, ah, patch faster. So I think it really means if you’re doing defense, you really have to start thinking about the things that which really have been best practices for years. Um, but like assume breach, assume everything in your network is compromisable. Put yourself in a position where any individual instance getting compromised does not mean significant damage. Um, put yourself in a position where two or three or four things change together. Can’t like you have to, it’s all about risk management and, uh, attack surface reduction. So like things that don’t need to be on the internet, like don’t expose things that don’t need, you know, put them behind a VPN, something like that, but then assume your VPN can get compromised. It’s a lot of, it’s, it’s a lot of work, but if you do it that way, you can get out in front to the point where like any one, any one individual CVE is not going to screw you or even any five chain together. Um, and you can put yourself in a position where you can detect and respond. I think there’s a, sorry, I’ll keep going.
I think there’s a longterm vision where the number, this is kind of debated and it looks like computer scientists. Um, but there’s a longterm vision where this number could come way down. Like if we get to the point that like, I don’t want to say all the bugs are found, but like, you know, if everybody, if, if, if the AI is advanced and get better and better and better and like everything going out to production gets scanned for like basically everything that could be found gets found. Like there is a vision for a future here where there aren’t that, there are, there are ACV here and there, but like nothing big coming out of it. Um, but that’s not for certain or soon.
0xRy4n: I have nothing to add other than everything that you said in the first part can be summed up as saying defense in depth is going to become a lot more important. Uh, so you should probably start thinking if you haven’t already, it’s you’re a little late to the train here, but you should probably start thinking about things in terms of defense in depth. Someone in the chat is making a good point though. I don’t know if they’re making a point
0xdf: or not, but it’s triggering something for me is like, there’s also going to be a lot of, there’s gonna be a lot of bugs that get fixed that aren’t vulnerabilities. There’s gonna be a lot of the ones that are vulnerabilities. A lot of them are going to be like very hard to exploit or not to not exploitable in a default condition. Like, so you’re going to see a lot of huge eye popping numbers, but like the number of them that are truly like air on fire kind
21y4d: of things are going to be a lot lower than that. Yeah. I was actually thinking that, that, um, probably like one to 5% only is actually exploitable the rest or not. But even still, because the number is so high, we are, I mean, every couple of months we are seeing like a Linux CVE that you can get like privilege escalation or remote code execution and so on. So even though maybe only 1% of them is actually, uh, very high and critical and exploitable with let’s say a public exploit, since we have a very high number, even 1% is too high. And you know, so there’s a good one.
Emmax0: I guess I think it’s just the biggest thing for me is, you know, as we see more exploits and stuff get developed with the rise of AI, sure. We’ll probably have stuff on the defensive side to, ramp up the speed of response with AI, et cetera. But think of how many systems don’t ever get updated, never get looked at, all the super old ICS systems or mainframes running COBOL tends to be a lot of critical infrastructure that’s not looked at or not touched, partly because of its obscurity, partly because of the time. Those, that’s where I’m really curious to see how this develops, because if we start seeing AI attacking those super old obscure systems and those bugs that never get patched, where are we going to end up? All right, this one is an off-voted question.
FalconSpy: When can someone begin learning kernel exploitation in their binary exploitation journey? Or sorry, binary exploitation. Yeah, no, binary exploitation journey. I can’t read.
0xRy4n: Either way made sense. However, they’re feeling masochistic.
0xdf: I don’t know. I mean, if you, it’s hard. It’s, I don’t, it depends, I guess it depends on, I mean, whenever you want is the answer. I mean, whenever you’re feeling inspired, I say go try. And if you’re feeling, it’s not like a, there’s a timeline. And once you, once you’ve logged 20,000 hours, now you’re good enough to go try this, like go try it. And if you get stuck, if it’s like, you can’t even get in the front door, then like figure out, okay, so what are the things keeping me in from that? And what are the, what are the things I need to learn to get there? Um, I don’t have a specific, like, I mean, you need to, obviously you’ll need to know general binary, like general assembly, reverse engineering, that kind of stuff is going to have to just kind of pretty strong prerequisite. Um, and once you get pretty comfortable with like exploitation of, I would recommend starting with like stack-based, heap-based stuff first, but like, once you feel like you have some understanding of that, like if you’re really excited about it, like what it matters is if you’re excited about it, if you’re excited about it, go figure out what gets you stuck, where you’re getting stuck. And maybe you’ll just get all the way through it, or maybe you’ll get truly stuck and then you’ll have, you’ll figure out where you’re stuck and get, you know, so work on that then.
FalconSpy: As I say, I don’t think most of us here have really done binary exploitation where we could really give any real true advice on it other than what, you know, OXDF just said. I think if Ipsoc was here also, and I’m paraphrasing a lot of probably what he would say to just like two words, he’d probably, or three words, he’d probably just say, just do it. Um, you know, if you dilly-dally or you try to find the best way to optimize your, you know, your path, you’re going to keep putting it off because you think, oh, I don’t know this, or I don’t know this, like, just start working on it. And then this kind of goes hand in hand with what OXDF was saying is, once you’ve started doing it, right, you’ll notice where, hey, I might need to know, you know, assembly better or reverse engineering, and then you can focus on that. And then you can come back to, you know, the binary exploitation. So, uh, in the words of Ipsoc, just do it.
0xdf: I will say the alternative answer is whenever you run into a hack, a hack the box machine, you’re trying to do that requires you to do it. Um, it’s just like the only times I’ve ever done kernel exploitation, the handful, or like, or like a flare on challenge or something. Um, so like, if you want some motivation, you know, uh, you go find, go find yourself a CTF or something that requires it and then go try to work through it. And when you get stuck, you’ll probably be able
0xRy4n: to have write-ups available. So. Yeah, exactly this. I have done a bit of binary exploitation. I have done zero kernel exploitation, but the times I have done binary exploitation, it’s because the thing I was working on needed me to do binary exploitation. So I did.
FalconSpy: All right. Next question here is an upvoted one. So if you can only recommend one academy path that best predicts long-term success in the offensive security field, what would it be and why?
21y4d: Once again, it is difficult. I think all of them have potential. Um, you should probably start with the CPTS because it is the, I mean, if you, if you want to offense, if you want defensive, then CDSA, but these two paths, they, you know, open the door for you and then you can try other paths. You can also do the AI path, our COA certification. Uh, it is a little bit different. It is more, let’s say, future looking, but, um, at the same time, um, that doesn’t mean that the rest aren’t, uh, we keep updating them and we try to keep them, you know, up to market ready and so on. So I don’t think there’s a definitive answer.
0xdf: I’m pretty sure I agree with that. Although doing the, doing the AI red team or path seems like a pretty solid, uh, way to go into like your future proofing yourself, but I haven’t actually taken it. So I don’t know.
Emmax0: I guess, honestly, for me, I would say, um, CJCA, which is, I mean, similar answer to the two above the CPTS, but I think for a lot of people with where that’s targeted, that’s going to be a lot of people’s like first introduction to this kind of world and this kind of content learning. If you thrive, if you enjoy it, you can do it. If it’s something that’s really challenging to you and that you’re just not being able to push yourself through, then yeah, it’s probably not going to be a super good predictive outcome. Um, the technical skills and stuff that you need to have more in CPTS over it would be more apt, like on your technical level. But if you start doing CJCA, you thrive or doing well, you can always push yourself through enough to, um, get to where you’re going. I don’t know if that makes any sense, but just get at the mental part of it.
FalconSpy: Okay. Uh, we’ll go to our next question. This one’s an upvoted question. So will the CrackMapExec module ever be updated on Academy? Uh, it is in the plans. Uh, I can’t promise exactly when, but we are aware of this. So, and it is in the plans, but, uh, yeah, I can’t go into more details.
0xRy4n: I will, I will say it’s a little more complicated than doing like search and replace CME, you know, net exec. I imagine, I imagine it’s not quite that simple. No, it will probably be like 80% rewrite, just like a new module.
FalconSpy: All right. We’ve inevitably hit the part where we have to drop the disclaimer. So we typically don’t disclose things we’re working on, uh, or try to give deadlines in case we miss them. So I’ll ask the question anyway, but, uh, up to whomever it’s targeted towards if they decide they want to answer it. So are there any plans to add security engineering paths or certs?
21y4d: Like you said, uh, cannot comment. All right. Uh, next question here. I think this one’s targeted towards OXDF, but, uh, I’m, anyone can really answer this. Uh, do you use local LLMs for your MCPs? Cloud denies burp MCP requests due to policy constantly, uh, very frustrating thinking of fine tuning a Quinn 3, 4 B model for this, uh, use case that I can run locally.
0xdf: Uh, I’ve played around a little bit with local models at work. Um, I w so I guess I would say it’s great experience. Like go out, if you are excited about and have the time to go download and play with the models and practice training them, like that is, that is valuable experience. It’ll be useful to you going forward. Like do it. That’s a great, that’s a great use of time. Um, I will also say if you are in the cyber verification program, which is not hard to get into you, cause should not be refusing you to do that. So those, that’s, that’s like true. Those are like, if you are in CVP and you’re getting blocked there, please reach out to me. I’d love to hear about it. Cause that’s a false positive. We should be getting removed. Um, so if you’re not in the CVP, then yes, you, I’m definitely, you definitely get blocked, that kind of stuff. And like, whether you want to join CVP or not, like, I don’t know, that’s up to you. Like go play with local models. That’s also cool.
0xRy4n: I am in the CVP. I don’t think I have ever had Claude deny me to do something other than Flare. Flare, Flare will like deny me to do something based off of like, Ooh, there’s the slightest whiff in the air of, of, of something,
0xdf: but everything else has been really. Your memory probably triggers, triggers Flare safeguards. So yeah, if what you’re doing, probably you can say, hi, Claude, how are you? And Flare safeguards will trigger because every time you send a request to an AI open, you know, open AI, or you’re sending, there’s a whole stack of stuff that gets stacked in front of your question, right? It’s all the tools you’re using, all the MCPs you’re using your memory, any information about like all that stuff. And that’s why they get to know you. But so your memory, I mean, Flare is out there intentionally meant to block anything cybersecurity, good or bad. Yeah.
0xRy4n: I think that’s a terrible end state, but it’s a, it was a, it is a workaround to get the model out to all customers who are not bio and cyber. So I expect it to suck for everyone on this call.
21y4d: That’s why the, that’s why the hello Claude prompt is like 10,000 tokens of all the, of all the stuff that is packaged with it. But most of this gets used as cash. So the cost is relatively lower.
0xRy4n: Uh, on the other part of the question I do use, I won’t say locally hosted, because I don’t run them off of my own GPU, but I do use open source models like all the time, every day. Um, are they good? Yes. I have not tried Quen 3, 4 billion. The smallest Quen variant I’ve ever used is 27 billion. And I mostly used like 34 billion and 394 billion. Um, but 27 billion, I know, uh, yeah, 27 billion I know is, is pretty good at small tasks. So like the calling of an MCP server, you could offload probably to that model, but like trying to replace Claude with Quen 4 billion is probably not going to be a great experience. What I tend to do is I offload small tasks to small models, um, pre-processing tasks, formatting tasks, uh, things that do not need complexity. I offload to small models or small, I offload to relatively small local models.
0xdf: I think that’s the challenge that’s going to come up with local models is just that like for them to be even anywhere close to as good for like as the frontier models or like the, even the commercial models, they’re getting so big. I mean, all the models are getting so big. So you are going to start to need serious hardware to just even run it on your own. Um, that said, again, I still think it’s a great idea. Go, go practice, play with training your own model. You will learn
FalconSpy: skills that are useful. Um, I, I have a Quen set up at home, um, with like my own full stack that I set between like, I mean, I’m using Olama. I probably could just use Lama CCPP at the, at the, without Olama being in front of it. But, uh, yeah, Quen 3 35 billion there. I, you know, I set up a couple of MCP tools that I run locally. Um, there’s different ways to run your own MCPs on your own machine. If you have obviously the hardware for it to run the, the local models. Um, a lot of the bigger models, you’ll probably need at least like a 40, 80, the 4 billion Quen 3 probably get by with like a, you can definitely get by with a 30, 80 or maybe something less. But, um, you know, I, I use some of the tools, like, you know, I asked Claude for some of the things I’d normally do in Claude be like, Hey, give me the, the prompts, the system prompts that I need for open web UI and my models to work, uh, the way I want it to. And, you know, it gives me the prompts and you know, I can offload a couple of things to the local model, but I’m also fortunate enough to have a 50 90. So like I could do that. Right. You know, uh, I haven’t played with four, you know, any of the smaller ones cause I don’t really have the need to. Um, yeah, like, like obviously I’ve said, you know, if you set this up, like if you set up the stack on your own, on your own machine, if you have the hardware to do it, you’ll definitely gain some valuable insights on how AI works, how to set up the stacks, um, how to interact with MCP servers, how to do, how to, you know, maintain the models and dual system prompts and all the other fun stuff. Um, I also posted the link in the chat. I’m not going to bother saying what you need to do for the recording, uh, in terms of getting to that link, I guess you can just Google, you know, flawed, uh, CVP program and you’ll get there. But for those here, you can see in the chat, that’s how you apply for a CVP program or just get blocked. It’s in the, in the block message
0xdf: or, or, or that, I guess that might be faster. I mean, there’s the nicest possible way because like, but it doesn’t actually surprise me, but the number of people who reach out to me and are like, I’m getting all these block messages. And I’m like, did you go to the link in the message? And they’re like, no, why would I do that? And like, well, but, but I would have done the same thing. Like I skip over, I’m like a block message. I’m stuck. Like, and you just start making assumptions. It’s a very human thing to do, but, um, it’s there. You guys should honestly just
0xRy4n: preload a skill that like, when you get blocked, it’s just like, okay, Claude, apply to the CVP program for me. That’d be, that’d be cool.
FalconSpy: We’ll go to our next question here. It’s an upvoted one. What’s an unpopular opinion you have about offensive security education? I don’t know if it’s unpopular, but, um, if and I wrote a blog post, man, it’s like years ago now, it’s kind of makes me feel old, uh, called it’s okay to use write-ups and like talking about how to use write-ups, but like that’s, uh, I guess I don’t know if it’s unpopular. It’s like, it was certainly trendy to say, try harder, uh, was like the mantra a while ago. Um, but I just don’t, I never believed in try harder. I always thought that was like very time wasting. Not it’s worth building the skill to like be able to hit a wall and like pull back and reassess and like get out of it without getting help. Like that’s, that’s a skill that’s like useful to have, but also like if you get in the professional world, like, I don’t know my, your employer doesn’t want you like spending 12 hours being completely stuck when you could just lean over to your coworker and say like, Hey, have you ever seen this thing? And they’ll go, yeah, yeah, try this. And you know, Oh, I forgot that. And like, like, so the world has friends. So anyway, I’ll cut in real quick.
FalconSpy: This was another voted question. So it’s like, what are your thoughts on write-ups? So we’ll, we’ll do both, right? What are your thoughts on write-ups and what’s an unpopular opinion you have about offensive security training? I’ll, I’ll piggyback David. It’s not really necessarily
0xRy4n: an opinion about purity so much as it is an opinion and maybe an unpopular opinion about like technology in general. Uh, it’s very similar in the sense that I think a lot of people want other people to fail if they don’t struggle as much as they did. Um, I think there’s a lot of people in the world who want, who, who struggled to learn things that they did, who like went through all of the, the grueling work and they want everybody else to have to do that or for them to fail. They don’t like the idea that other people can get to be as capable or successful as them by taking an easier route. Um, you know, they built, uh, you know, arch from scratch, you know, and they installed it from scratch when they did it. So therefore you have to do it. And if you, if you use write-ups, then you’re less than them. If you don’t learn assembly as your first programming language, then you’re doing it wrong. Um, I really hate this. I think, uh, as, as the education space gets better, as the resources get better, there become better and better ways to learn the same content concepts to the same level without having to struggle so hard to do so. And that you should avail yourself of those resources and not force yourself to, um, take the hardest path possible and then risk failing. Um, do what will make you successful. And if that includes using write-ups to make you successful, then do it. It’s better to use a write-up and get something done than it is to struggle, fail, and then leave and abandon the idea entirely.
Emmax0: I think in my opinion, it’s important to set goals for what your objective is. If you are just trying to get it done, use write-ups, do whatever. If you’re trying to learn, still use write-ups, but you have to be more mindful in that. Don’t use them as a replacement for building that knowledge. Use them as a tool to learn to build that knowledge. If you see something, give it a try. If you can’t figure it out, use a write-up a bit, maybe get you back on track. Or then, you know, maybe the next couple of days, try doing another one without a write-up. See if those techniques that you’ve learned previously have helped. Just don’t blindly copy-paste out of it if your goal is to learn. Similar to using AI and learning. Are you using it as a tool or using it to replace learning? And that’s the thing to figure out.
0xdf: I’m so glad you said that. That’s exactly right. I think you should know. I would recommend seriously never copy and paste out of a write-up. Because even if you’re just going to stare it out on half of your screen and type into a terminal at the same time, the finger pressing and going through there and actually typing out the command is going to make you process it more. And every time you take something out of a write-up, you should say, huh, do I understand every argument in the command I just ran? If so, what would happen if I change this argument to something else? Try it and see if you’re right. Use it as a chance to quiz yourself and make sure you understand it. And then this is something where AI is so useful. Feed a write-up to an AI and tell it, read this write-up. Do not spoil anything for me. Here’s how far I’ve got and I’m stuck trying this. Only ask me questions and don’t spoil anything. And if you make a solid enough prompt, you can get the AIs to do that. And they’ll mentor you. And they’ll ask you, hey, did you look at this? And you’ll be like, no, I didn’t. Or why do you think this is a dead end? And you have to explain it. And then you’re going to figure it. That’s amazing ways to learn.
FalconSpy: I’ll promote your skill since you won’t. OXDF has a Hack the Box AI mentor. It’s on GitLab. I posted the link in the chat. You can use it to basically do what OXDF was just saying.
0xdf: I mean, I think it’s useful. It was definitely useful, I don’t know, six or eight months ago when I made it. Also, make it better. If it isn’t working great, I haven’t tried it in a while. So, but like, practice, work with your AI and like, get it to where you want it to be. But yeah, it’s a very useful way to learn. I, if I worked at Hack the Box, I would look at having that built into Hack the Box. We have the AI tutor. Yeah, we have a Hack the Box coach.
FalconSpy: All right. Anyone else? Otherwise, we’ll move on. Cool. All right. Next question is a photo question. So, what’s your best advice for getting an entry level job for the offensive security field with search such as the CJCA, CPTS, CAPE, and a university degree?
Emmax0: It’s pretty rough these days. I would say network, honestly, is the best thing I can do. Do more to be just not a piece of paper on a resume. The job application process is horrid. So, if you can go to local events, network, meet people, even if they’re just other students, you never know in five, ten years where people are going to end up. It’s a small industry. So, talk to everyone, make whatever connections you can. If you are in school and they have an internship program, leverage that. Leverage whatever connections you have. Just put yourself out there, make friends, take whatever chance you can get, and adjust as you go.
0xRy4n: So, we do these Cube Talks almost every Friday, and we’ve been doing them for many years. And there’s one constant across every single Cube Talk, which is that somebody will inevitably ask, what is the best way to get my first job in the industry? And no matter who we have on the panel, no matter which guests we have, the answer always is networking. It’s always the number one answer that we always give every time to this question. Networking, networking, networking. The number one thing you can do is make yourself the person who shows up in somebody’s mind when they think of, who do I want to hire for this job? And the way that you do that is by going out to conferences, going into communities, meetups, anything, meeting people, having conversations with them, talking to them, getting to know them, and forming a connection. This does not mean shooting DMs to random CEOs on LinkedIn. It means actually going out and forming a connection with these people. So that way, when they’re looking for someone to hire, they remember you, and they already know who you are. They already know what your vibe is, right? It gives you a much stronger foot in the door when you have a network that you can rely on. I think the one thing I will add
0xdf: beyond that, networking is great. It’s also really hard. It’s like really hard, and it’s hard work, and it like takes a lot of time. The other thing I would add to, which is, I mean, it’s not easy, but you want your resume to stand out in some way. Like, if you get to the point where they’re looking at your resume, you need it to stand out. And like, that is going, first of all, I love the question asked for entry-level offensive security jobs. They exist more than they did when I first started, but they’re still very hard, very, they’re a very low number of offensive security. My strong advice is there are a lot, a lot, like orders of magnitude more SOC analysts than there are red teamers and pen testers. And it’s a much easier field to get into. And every, even if you, even if you know that that is not where you want to spend your future, like your whole career, like you, every day you spend working on a SOC, you will be learning things that will be useful to you as a red teamer down the road someday, because you will understand how, how things get caught, how things work. You’ll be putting together what attacks look like and getting real first-hand experience. You will also be building professional connections with people who work in the industry. If you’re somewhere that happens to have a red team or, you know, do pen tests, you can, once you’ve been there for a while and people know you and like you, you can then like reach out to those people and you, maybe you’ll start working on projects with them anyway, naturally. But if not, you can offer to like, Hey, can I come over and learn from you? There’s like opportunities to network there. So like, don’t lock your, well, I mean, if it’s truly your dream, it’s all you want to do, go red team. Like you can do that, but like, it’s a much harder path into the industry. Um, okay. The thing I was saying when I went off my own little tangent was look for, you better have something on your resume that shows that you can commit to do it. Like, like it can be making a blog. It can be committing to open source. It can be something, but have something on your resume that shows you are contributing to something and doing it regularly. Um, so that, that is the type of thing that like, I don’t, know, don’t, don’t worry about like, if anyone actually reads your website, that’s not the point. You want to have something that if like the hiring manager picks up your resume and they’re like, I’m going to look at this website, like that you’re like, Oh, I’m proud. I’m proud of this. This represents me. Um, so what, if you want it to like be really cool and have all sorts of JavaScript widgets and stuff, like that’s fine. If you want, if you’re trying to show off your HTML coding skills or whatever, if you want it to be very technical, like work on your explanation, show that you can write clearly and that you know how to explain technical things in a way people can read. Um, that speaks very highly of you. So, anyway, build something or just go contribute open source. And that, that does help as well.
Emmax0: I feel like it’s important to add the caveat of by contribute to open source. That doesn’t mean making a pull request to update the read me, find actual projects and give actual contribution more than just something that represents your skills and not just that, you know, how to open a website and hit a button on GitHub and annoy maintainers. Even better, don’t update the read me, just update
0xRy4n: the contributors with your name. And that’s your change. What was it? I think it was like the next
Emmax0: JS express repo or something like that. No, it was for Linux. It was for literally Linux. Someone’s
FalconSpy: like, Hey, I upload, uh, they updated the read me and they’re like, I want, you know, I want to be on the contributor for the Linux repo for, you know, under Linux Torvalds. This was something else. This
Emmax0: was like a YouTube educational video for GitHub where they told people to like go open a pull request on express. I think it was with their name and the read me and they got like thousands of PRs for years
FalconSpy: and anyone else on, uh, anyone else want to talk about, you know, what you should do about networking or how to get the entry level as we’ll move on. Like we nailed it pretty well. All right, we’ll go to the next one. Uh, how to be a pro at bug bounties. Uh, basically they want to be able to do it and make money.
0xdf: I mean, now is a really interesting time to be entering into bug bounty because AI, you know, even three months ago, three, four months ago, AI wasn’t really that big a thing. And now if you talk to people in bug bounty, they’re all developing their hack bots and they’re all like automating everything all the time. So like, it’s a very, um, I don’t know. Feels like an intimidating time to enter. If that sounds fun to you, like you should definitely get into it. Um, my advice would be, if you want to get into it, like you should go join it. Like, uh, I listen every week to the critical thinking podcast, which is put on by a couple of guys who are full-time, full-time bug bounty hunters. Um, a former hack the box employee, uh, bus factors over like works really closely with those guys. Um, like they have a discord. They have like, go talk to the people who actually like work in bug bounty and are doing it. And, um, you know, I’m sure there’s a lot of people there. They were all beginners once too. Um, I just don’t think we have anyone who does bug bounty on this
0xRy4n: call. Fun, fun fact about bus fact. I, I hired him, but I have this very clear memory of me sitting at a bar with him and, uh, he pulls out his phone and he goes, oh, nice. So casually. And I’m like, oh, what happened? And he goes, oh, I just got a bug bounty. I’m like, oh yeah, nice. And he’s like, yeah, yeah, yeah. $20,000 bug bounty in Epic Games. And I’m like, what? He’s like, yeah, nice. I’m like, what do you, what do you need to have more of a reaction to this? One of the best bug bounty hunters I, I know that I’ve ever met in person, probably. Plus fact. Such a good dude too. We’ll go ahead and move on. Uh, this is another other question. Uh, any advice for high school students? Uh, is Pebble here? I have maybe some
0xRy4n: controversial opinions. I don’t think Pebble’s here. Pebble was here earlier. Um, Pebble famously is a person who got a mid-level pen testing job, uh, as his very first job out of high school, like literally fresh out of high school, very first job, mid-level pen testing job. Um, how did he do that? Because by the time he graduated high school, he had already been, um, streaming like almost every other day for over a year, like almost two years showcasing him doing hacking nonstop. He had the CBBH and the CBTS and the OSCP by the time he graduated. Um, and he had just like a huge backlog of evidence that he knew what he was doing, uh, and that he was competent. So yeah, he, he graduated and he was able to like to use his network that he had built and showcase his skills and get a job right out of high school. Is this a practical path that I think is available to the general public? No, I think he’s an exception, but the moral of the story that you can take away from that is do the same things that we recommend everybody else do, which is, uh, get as much as you can visible that showcases that you have the skills that you need to have. Um, as much as you can, that proves to anybody who’s looking at you without any shred of doubt that this person knows what they’re doing. And that requires you to know what you’re doing.
Emmax0: Here’s my take. I mean, I think the biggest challenge when you’re young is going to be one of two things. It’s either going to be laws, like local labor laws, a lot of places you can’t work anyways. Um, and the other thing is risk because taking a chance on, for a company to take a chance on someone that young without a lot of prior experience, it’s an investment and it’s risky and there’s a lot of safer options. So whether that be showing what you already know by like ways like, uh, Ryan mentioned with streaming and projects or showing your passion, that’s going to be key. Um, and just working with someone to vouch for you because you’re going to really need someone to vouch for you at that point on top of, you know, certs if those are accessible, but those are expensive for people with full-time jobs, let alone people who are still in school. Um, another thing I think that’s important too is you’re still young at that age. Like don’t burn yourself out. There’s only so many hours in a day. It’s hard. If you keep running that fast, when you’re for like 16 through a career, you’re going to burn out, slow yourself down, enjoy the stress-free life of being young and pace yourself. I should mention one of the reasons why that worked for him was because this was his like favorite hobby. So he loved doing this. This would not work if
0xRy4n: you had to force yourself. I think there’s probably 10, tends to be a tinge of like ADHD or some other
0xdf: neurodivergent in those people as well. I think the thing I would add is, uh, one, when you, when you’re really, when you’re young, when you’re in high school, right, you have your whole career in front of you and you’re not locking, you’re not like decisions you make are not locking you in. You, you are going to be in the workforce, unless you, unless you do really well and decide just to retire, you’re going to be in the workforce for like 40, 50, 60 years. So like you can have many very different, different jobs over time. Um, the thing that I would recommend, the world’s changing super fast and it feels really crazy to try to tell you like, oh, this is the skill you should learn. Cause like, who knows if you’ll need it in five years. Um, the thing that will benefit you is to build problem solving skills, to build like critical thinking skills. Um, I think probably to build writing skills. Um, maybe that’ll go away, but like, I think just in general, being able to communication is not going to go away. So like I was, studied math and physics in college. I have not done anything physics-y outside of my very first job. Um, but like I got, you know, it was still benefited me because a, when people looked at my resume, they’re like, oh, you must be smart because you studied physics and be like, I learned how to like really tackle like hard problems and put together, like pull pieces together and try to like, and it’s just like that kind of thinking is something that’s very valuable. So, you know, don’t just try to focus on like becoming the, I mean, if you truly are obsessed with astrophysics, like go study astrophysics, that’s great. But like, if you don’t know what your passion is, just like work on building like these higher level skills, like that you can use across all sorts of different industries. Anyone else? All right,
FalconSpy: just doing a quick timekeeping. We have a little over 10 minutes left. We’ll try to get through as many of the questions that are still in the queue as, uh, as we can. Uh, so this next one’s an upvoted question. Uh, when will we have XCT on here? It’s going to be very hard to get XCT on to a cube talk. He lives, uh, in a country. I don’t think he’s ever stated. And I feel like I’ve said this before and Ryan has corrected me, but I’m going to fall back on it. I don’t think he’s shared what country he lives in now. Um, it doesn’t align time zone wise for when we do these. And I don’t think, uh, yeah, I don’t think he, uh, is, is going to try and stay up for it. So, um, all right. The next one is another upvoted question. Is it bad advice to tell someone to start from hack the box labs instead of doing something like on Academy or Portswigger or one of our competitors? I say it depends on who
Emmax0: you are. Doesn’t. Um, Academy is like, you know, if you’re like a text-based learner with guided content, if you’re someone who just wants to bang your head against a wall over and over and do your own research, then that’s where labs comes in. I mean, there’s probably a place for both. You don’t want to keep banging your head against the wall endlessly. So there’s in a lot of people’s way of learning. There’s a place for, uh, for both, but neither is wrong. Whichever helps you learn best, whether it’s one, the other, both just learn, do better, try harder. No. Well, yes, but also don’t use that phrase. Okay. What about hacker mogging? I don’t know.
FalconSpy: Something stupid. Yeah, I think, I think Emma put it pretty, pretty much laid it out pretty well. Like use whatever works best for you in terms of learning. As well as it’s from my phone. Yes. Obviously we’d love to have you here, but, uh, if there’s other places that teach you something better and it’s more to your learning style, then damn it, Ryan trying to make a point. Um, yeah, definitely just use, uh, whatever works best for you. Uh, if attack the box, great. If not, then, uh, you know, just do it as Emma was saying. And Ryan is contractually obligated to always just say attack the box.
0xRy4n: Well, you know, you’re right. If it’s not hack the box, just do it anyway. It being hack the box.
Emmax0: All right. I mean, I will say that we don’t, we, we always have the slash feedback command. So if you think there’s something that we’re missing that we help you learn better, let us know. We’re always listening and trying to improve and offer the best learning. So.
FalconSpy: All right. Anyone else? As we’ll move on. All right. Uh, this is another photo question. So what do you think about real world labs, uh, in terms of finding and interacting with systems in real time? Is it better than home labs and in isolated systems, uh, doing more home labs as a plus point in future job interviews? So I guess the question since a little over the place in terms of actually reading it verbatim, uh, you know, do you think it’s easier or better to do things in real world or is it better to do things in home labs where things are isolated? Um, and you can use, you know, that you have a home lab and you’ve been testing in home labs for your job interviews. Yes. I mean, any of the context here.
0xdf: Oh, I mean, I think I’m going to answer like what I take is the context. Home labs can be an amazing way to learn. They can also, you will learn things like administration and how to set things up and how to run things. And then when you get something working, you know, it’s going to take a lot of time and effort and you’re going to learn a ton of things and you’re going to have skills that come out of that. Um, that’s one way to go. Um, it’s not the only way to go. Like, I don’t, I don’t, it’s really hard to say what’s better or worse. It’s kind of, um, I would go with whatever sparks joy. I mean, there’s lots of ways to get to the same end of the trail.
FalconSpy: We’ll move on here by falling back on this disclaimer but I’ll ask it anyway, say odd. Are you, are we planning on releasing any dedicated steganography categories or challenges, uh, on academy or platform? We used to have a stego section.
21y4d: Yeah. I mean, we used to do them on, uh, labs as challenges. Um, I don’t think we’ve ever done, done those on academy and we don’t have any plans to, so it’s more of a CTF thing rather than actual pen testing. So yeah, they would make sense on, uh, you know, on challenges, perhaps not on academy
0xRy4n: yet. Unless you’re working in like maybe intelligence or like occasionally, very rarely, maybe in law enforcement, you like won’t see stego in the real world. Like the use case of stego in the real world is really, really, really limited to like very, very sketchy sub cases where you’re dealing with criminals or terrorists or something. We are, we are seeing it show up in malware from time to time where malware uses stego is like a comms channel to pass images back and forth or something that looks benign, but it has, you know, information embedded in it. Um, I wouldn’t surprise me, but I would say like that kind of stuff would show up like in a malware or a reversing challenge, right? Like not like it would be stego, but it’s not really, it’s not like stego for the sake of stego is in addition to being in my opinion, really boring and stupid. Um, like not that practically useful to eat in the world, but if you enjoy it, I like also don’t want to yuck your yum. I’m glad you enjoy it. I have a question for you, David, maybe, sorry, whatever at this point we’ve said it before, uh, your name. So, um, I slipped anyway. Um, are you, have you seen the fake fonts, get hub repo by any chance? Nope. Okay. Um, basically it’s a project that, uh, I can’t remember which company this red team or works at. Um, but, uh, you know, it’ll look like, you know, just standard characters that you have in your keyboard that you typed out. Right. So like you can have a capital letter a, but behind the scenes, when you feed it to the AI, it is, you know, a completed system prompt, um, or it’ll be something different. So like when the AI reads it, you know, whatever you tell it to see, and then if a human reads it, it’s literally just standard ASCII characters that you look at your screen. Like, you know, it could be a one word, but, or one letter, but like to the AI is everything. So I guess where I’m going with this, right, is like, would you consider that stego, but for AI?
0xdf: Maybe it’s kind of more of a jailbreak. I mean, it’s closer to like jailbreaking type things, but I maybe, I mean, that’s kind of, I will say, um, I, this is not really jailbreaking. It’s more of an attack against people against AI systems. Yeah. I don’t know. I don’t have, I think that’s, I w I wouldn’t call that stego. Honestly. No, I would, I mean, I see how it’s similar, but it’s, it’s probably a different category.
FalconSpy: Fair enough. All right. Just wanted your thoughts on it. Okay. Um, our next question here, uh, is enough for the question, uh, in a recent interview, uh, the recruiter for this person that they were speaking to said that they’re looking for someone with cyber, uh, cyber breadth and depth in a specific area like cloud or LM, uh, security. How would one develop this breath in cyber as they’re still in university and about to graduate this year? Is it something that they need to make notes on and memorize, or just practice to the point that, uh, it becomes second nature for them?
0xRy4n: Man, if you want to develop breath, Um, I mean, I guess it depends on what you mean by breath and cyber, because that could mean a lot of other things. There’s breath within like offensive. So knowing a lot of different offensive techniques. And then there’s like breath in the sense that, okay, you know how to do defensive, you know how to do offensive, you know how to do, you know, a little bit about like GRC and compliance and such. Um, if you just want to have breath in, let’s say the practical skill set. I think your best bet is to start working through content like hack the boxes, but maybe don’t focus on a specific path. Maybe just kind of work through contents in some other order. Um, if you just work through content by like difficulty rating or like release, you’re going to get a lot of variety in content. You’ll get like new Sherlock’s coming out. You’ll get new boxes coming out. You’ll get new modules coming out. Um, is this the best way to do it? I don’t necessarily think it is for Academy. I think with Academy, it makes a lot more sense to pick a path and stick with it. But for something like labs, I think you can get a lot of, you can get exposure to a lot of different stuff by just working through whatever the like weekly releases for both a Sherlock and, and a box. Um, I don’t know if that’s the answer is a question, but like, if you were just trying to get exposed to a lot of different things, I would say just work on a lot of variety of content. Anyone else saw this? We’ll move on. All right. I think this might be our last question, depending on how long this one takes. So, uh, where and how would you recommend learning programming other than a computer science degree? Uh, this person feels like they are lacking in programming knowledge, uh, to go into research and would love some tips. It sounds like a writing question. Oh, I didn’t even know that you were here, Chad. Uh, I mean, I don’t know. I don’t have like a course for you or like a specific curriculum or anything… Um, so yeah, I would say find like projects that you actually want to work on and then use those as a mechanism to teach yourself how to build that project.
0xdf: I had, I had a couple of classes in university and like I was grades were motivating enough for me that like doing the projects well was enough. But like the first thing I ever programmed for myself was a, uh, an Excel VBA way to like to way to manage a, uh, NCAA basketball pool that I run, that I ran. And it would literally use Excel VBA to go out to the ESPN website and pull down all the brackets in my pool and load them into Excel for me and then run stats against them. Um, and it took me so I have like, I think I still have the like Excel for dummies book or Excel VBA for dummies book back there on my shelf. Like it took me so long. And then like, eventually I ported it over to Python and now it runs in Python, but like having a project that you care about and that you want to spend time on and that you want to like, you have a vision for what it’s going to be and how you’re going to get there is like the best motivation to like get you going on something. Even if you pick a really stupid language. It’s, it’s funny you say it’s the
0xRy4n: rather large VBA scripts that would taking what was effectively our client database. Um, and then using like common substring comparison to try to find duplicates because we would get people that would show up in person and they would register and we’d get people that would show up online and register. And we had like 20 duplicates for every person. So they were like, we need to fix this. And I’m like, I’m not going to go through these hundred thousand records manually. So I started figuring out how to do fuzzy string comparison with common substrings and VBA. And it was terrible and great at the same time.
FalconSpy: All right. I think that wraps up this week’s QTalk. Thank you everyone for joining us for this week. Uh, we host these every week on Friday, unless stated otherwise. Uh, we won’t be hosting one next Friday as we will be away at DEF CON, or at least a couple of us will be at DEF CON. So no, keep talking this week. Uh, take a look at the top of the discord at the event section. You can see whatever events we are hosting here on discord or elsewhere. Uh, it’ll show in your local time zone. You can say you’re interested to receive the alert when it goes live. Uh, we do have a trivia event later today, uh, in about two hours. Uh, feel free to participate if you’d like, you have an opportunity to win, uh, some prizes if you place in the top three. Uh, and we’ll, we’ll see you in two weeks for our next QTalk.
