
Improving soft skills, handling out-of-scope bugs and pricing changes | Cube Talks 0x10
Source: YouTube · Hack The Box · published Sep 8, 2026 · 54:19
[BLUF]
Hack the Box staff discuss the nuances of offensive security careers, the strategic use of AI in pentesting, and updates to the Academy platform, emphasizing that foundational blue team knowledge and strong communication skills are critical for long-term success in both red teaming and bug bounty hunting 13:58 31:37 40:19.
Key Takeaways:
• AI in Pentesting: While AI agents are not currently used for live engagement due to privacy and safety risks, they are valuable for building internal tooling and automating low-hanging fruit in bug bounty hunting, though manual orchestration remains difficult 04:23 46:52.
• Career Paths: Bug bounty is increasingly an engineering challenge requiring automation, whereas red teaming offers more stable income; staff recommend starting with blue team fundamentals (like Security+) to become a better offensive security practitioner 14:02 31:37.
• Soft Skills: Effective communication is vital for pentesters to deliver bad news constructively without damaging client relationships; staff suggest practicing by explaining technical concepts to non-technical friends or family 40:19 43:33.
• Platform Updates: Hack the Box is considering bundling subscriptions and has improved accessibility for blind users via alt text, while clarifying that writeup rules for migrated content remain in a gray area 34:17 35:45 07:31.
• Learning Advice: For beginners, focusing on networking and operating systems is more valuable than deep programming skills, and students should utilize the Academy catalog to guide their lab practice 49:11 16:39.
[Closing statement]
The panelists encourage viewers to engage with the community through Discord VCs and to focus on foundational skills before specializing. Future updates regarding cloud content and subscription structures will be announced via official channels.
Sources:
- 13:58 Discussion on bug bounty vs. red teaming careers.
- 31:37 Importance of blue team knowledge for offensive roles.
- 40:19 Advice on improving soft skills and communication.
- 34:17 Updates on accessibility and platform features.
- 07:31 Clarification on writeup rules for migrated content.
- 49:11 Recommendations for learning fundamentals.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] Hi everyone, welcome to this week's Cube Talk. I am your host Falcon Spy. This is your opportunity to ask our panel and staff ask our panel of staff and volunteers any questions you might have about any of the services we offer here at Hack the Box as well as infosc in general. We'll do the best we can to answer as many of your questions within the next hour. Questions are typically first in first out unless they are upvoted and stated otherwise. You can use the forward slashcube talk comm uh command to ask your question. You can use that same command to also upvote questions to the top of the queue. We'll introduce everyone here on the panel in case you have any targeted questions you would like to ask any of us and then I'll sound like a broken record again about the cube talk co…