u/Used-Addendum-3819

TOMORROW⚡️ Free Lightning Session: Direct vs Indirect Prompt Injection

TOMORROW⚡️ Free Lightning Session: Direct vs Indirect Prompt Injection

We will have another FREE YouTube Live session tomorrow!!
Register: https://luma.com/tryhackme-uu2v?utm_source=reddit

Who this is for:
- Security practitioners curious about AI as an attack surface ​
- Pentesters and red teamers who want a clearer mental model of prompt injection types ​
- Engineers and architects deploying AI who want to understand how it gets attacked

What you'll see:
- A live walkthrough of direct prompt injection against an AI system on the TryHackMe platform
​- A live walkthrough of indirect prompt injection, including how attacker-controlled data becomes instructions ​
- A breakdown of why the distinction changes how you'd defend against each

u/Used-Addendum-3819 — 18 hours ago

Live Workshop: Building and Breaking Active Directory Basic

Building and Breaking Active Directory Basic

We are going to host a 4-hour workshop for students and young professionals! The instructors are from THM and MWR CyberSec.

📅Wednesday, August 26 (7:00–11:00 AM PDT / 10:00 AM–2:00 PM EDT / 3:00–7:00 PM BST)

🎓 50USD per seat, up to 50 participants

🎫Register here: https://luma.com/tryhackme-5pfu?utm_source=reddit

Who this workshop is for:

  • ​Security practitioners who want hands-on time with the backbone of enterprise networks
  • ​Pentesters and red teamers who want a structured approach to attacking Active Directory
  • ​Sysadmins and engineers who manage AD and want to understand how it gets broken

​What's included:

  • ​A live, hands-on session where you build the environment yourself
  • ​Full recording, sent to everyone who registers
  • ​A spot in a focused cohort of 50 practitioners
  • ​A Certificate of Participation with CPE credits

​What you'll learn:

  • ​Build an Active Directory environment from scratch
  • ​Configure users, groups, and GPOs
  • ​Enumerate the environment to uncover common misconfigurations
  • ​Execute a full attack chain, exploiting those misconfigurations to achieve Domain Administrator privileges
u/Used-Addendum-3819 — 3 days ago

SOC Level 2 Path is now Launched🚀

Level 1 taught you what to do with an alert. Level 2 teaches you what to do about it.
SOC Level 2 is completely rebuilt, 76 rooms across the environments hiring managers actually screen for at L2: Microsoft 365, Entra, AWS, Active Directory, and detection engineering. Kick things off with THE DEEP DIVE & 150 SAL2 cert prizes on the table until Aug 27🎯

Get Hacking➡️ https://tryhackme.com/thedeepdive?utm_source=discord&utm_medium=social&utm_campaign=thedeepdivesocl2

u/Used-Addendum-3819 — 7 days ago

AMA with Ben Spring (CEO) & Stefan Apostol (Content Engineer)

Join us for a live AMA with two of the people shaping TryHackMe!
Ben Spring is the co-founder and CEO of TryHackMe, helping build the platform from the ground up into a learning platform used by millions of cybersecurity learners worldwide.
Stefan Apostol is a Content Engineer at TryHackMe, working on the technical rooms and challenges you train on every day.

This is your chance to ask about TryHackMe's direction, content strategy, career paths in cybersecurity, or anything else on your mind. We're collecting questions in advance.
Drop yours when you RSVP, and we'll prioritize them during the session!

📅Friday, August 14, 2026, 7:00 PM CET
🎫Register here: https://luma.com/tryhackme-wykt

u/Used-Addendum-3819 — 11 days ago

TryHackMe is heading to DEF CON 34!!

TryHackMe is heading to DEF CON 34 at Blue Team Village, August 6-9, Las Vegas🎰

Find us at the booth for:

  1. Overflow the Jackpot, our on-site CTF🚀 Top 100 finishers win a challenge coin and a T-shirt.
  2. Talks and demos from our content engineers Andrea Brosio and Ariz Soriano across Demo Labs Track 6, Cloud Village, Adversary Village, and Red Team Village.
  3. Short on-camera interviews. Take part and walk away with the full THM SWAG bundle🎉

See you in Vegas!

u/Used-Addendum-3819 — 21 days ago

Hacker Holidays 2026 is LIVE🌴

14 rooms, 14 days, one story that unfolds a piece at a time.
Day 1: VERA, the AI concierge, greets you by name. She knows your room. She knows your coffee order. You never told her either.

Every room you clear earns a raffle ticket toward a $50,000+ prize pool. A new one drops every day at 16:00 UTC.

Room 1 is waiting: https://tryhackme.com/hackerholidays?utm_source=discord&utm_medium=social&utm_campaign=hackerholidays

u/Used-Addendum-3819 — 24 days ago

WEB1 Certification is Here!

"Which web security certification actually proves I can do the job?" 👀 🔴

We built WEB1 to answer that. One exam, three access models: Blackbox, Whitebox, and Greybox testing everything from authentication flaws to server-side exploitation against live applications.

Want to prove your web security skills against live applications, not multiple-choice questions? 🎯

Get WEB1 Certified🔥: https://tryhackme.com/certification/web-application-pentester-level-1?utm_source=discord&utm_medium=social&utm_campaign=web1launch

u/Used-Addendum-3819 — 30 days ago

Do you want to join our retreat in Malta?☀️

We're inviting one lucky user who has been impacted by TryHackMe to our company retreat in Malta on Sept 21-25!☀️
Meet the team, enjoy activities, and relax at a 5-star resort. All expenses covered!🎉

Fill out the survey by the 24th of July at 12PM BST to be considered🔥

https://forms.gle/urg8YJmhvKknqdou6

u/Used-Addendum-3819 — 1 month ago

🔴NEW RECENT THREAT: WordPress🔴

CVE-2026-63030 dropped Friday. Our team had a room ready by Monday. You wrapped a pentest for a client. Their app is clean, but their WordPress blog wasn't in scope.

CVE-2026-63030 changes that conversation. An unauthenticated attacker can exploit the REST API with a SQL injection, forge an admin account, and achieve remote code execution.

This vulnerability was discovered using a GPT prompt and $25 by a security engineer with 3 years of experience. Not a nation-state, not a specialist research team. Understand the full exploit chain and how to mitigate it in our new threat room, WP2Shell.

🚀Available now on MAX:
https://tryhackme.com/room/wordpresscve202663030?utm_source=reddit&utm_medium=social&utm_campaign=recentthreatwordpress

u/Used-Addendum-3819 — 1 month ago

A five-star resort. 14 rooms and over $50,000 in prizes!!

The Byte Lotus is this year's Hacker Holidays:
One new room every day at 16:00 UTC, running from 27 July to 9 August, a story that unravels as you go, and a concierge named VERA who's a little too helpful....

Every room you clear earns a raffle ticket toward $50,000+ in prizes

Check-in 27 July...VERA is expecting you.
https://tryhackme.com/hackerholidays?utm_source=discord&utm_medium=social&utm_campaign=hackerholidays

u/Used-Addendum-3819 — 1 month ago

FREE Lightening Class⚡️ Anatomy of a C2 Framework

Anatomy of a C2 Framework

Who this talk is for:

  • ​Red teamers and operators who rely on a C2 framework and want to know if it's the right one
  • ​Pentesters evaluating C2 options before committing to a toolset
  • ​Security practitioners who want to understand what actually separates a good C2 architecture from one that burns an op

​What's included:

  • ​Free Live Talk, grounded in real engagements
  • ​Learn a practical checklist for evaluating any C2 framework
u/Used-Addendum-3819 — 1 month ago

THM Live Class🧑‍🏫 | Operating C2 for Red Team Operations: Pivoting & Beacon Object Files

Reading about C2 tradecraft is easy.
Getting hands-on time to actually operate one, end to end, is the hard part💻
Operating C2 for Red Team Operations is a 4-hour live workshop where you'll stand up a C2 server, land your first agent, run Beacon Object Files, and pivot across a lab range, the way a real op unfolds🎯

  • Led by Ariz Soriano, Senior Content Engineer at TryHackMe.
  • Built around hands-on operation with the cohort, not slides.
  • No prior C2 experience needed🛠️

📅July 21st | 🕑14:00–18:00 BST | 🎟️Only 30 seats
https://luma.com/hc3w544c

u/Used-Addendum-3819 — 2 months ago

LAST CHANCE LIVE CLASS | Bash the Bot: AI Pentesting in a Day

​Prompt injection. Supply chain attacks. Model poisoning. These aren't theoretical. They're live attack surfaces that most practitioners have never had hands-on time with.

​Not because people don't care. Because the field is moving faster than the training has been able to keep up.

This live workshop closes that gap.

📆Thursday, June 25, 3:00 PM - 8:00 PM GMT+2
📍Google Meet
🎫 Register here: https://luma.com/uh3kf13d

What's included:

  • ​Live, hands-on sessions, two group practicals, not just talks
  • ​Recording included, full Google Meet recording for everyone who registers
  • ​A guest practitioner talk on AI bug bounty hunting
  • ​Closing Q&A with all instructors on screen
  • ​A place in a focused cohort of 45 practitioners
u/Used-Addendum-3819 — 2 months ago