
Cyber Apocalypse 2026: The Salt Crown
Source: YouTube · Hack The Box · published Jul 23, 2026 · 2:46:27
This HTB Cyber Apocalypse workshop covers CTF design, AI's security impact, and deep dives into SSRF, XS-leaks, heap exploitation, and HTTP request smuggling 56:33-56:40
Key Takeaways:
• AI-augmented teams solve more (70% vs 44%), but AI struggles with pivoting—elite operators gain ~4.1x more leverage 12:04-12:14
• SSRF extends beyond blacklist bypasses—attackers leverage DNS rebinding, parser disagreements, CRLF injection, and gopher smuggling 31:04-31:16
• XS-Search bypasses SOP/CORS by inferring true/false responses through error events, redirect limits, timing, and frame counting 1:21:51-1:22:03
• UAF exploitation differs across glibc: 2.31 allows free hook overwrite, 2.35+ requires safe-linking key recovery and GOT overwrites 1:52:14-1:52:24
• HTTP request smuggling stems from components disagreeing on request boundaries—through length, framing, early exit, or H2/H3 translation 2:14:09-2:15:03
Good CTFs prioritize realistic chaining over guesswork, and AI accelerates skilled operators rather than replacing foundational understanding.
Sources:
- 56:33-56:40 Workshop overview
- 12:04-12:14 AI impact on CTF solve rates
- 31:04-31:16 SSRF exploitation techniques
- 1:21:51-1:22:03 Cross-site leak primitives
- 1:52:14-1:52:24 Use-after-free across glibc versions
- 2:14:09-2:15:03 HTTP request smuggling fundamen
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 2 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] [music] [music] Heat. Heat. [music] Heat. Heat. [music] [music] [music] Heat. Heat. Heat. [music] [music] [music] >> [music] [music] >> Heat. Heat. [music] >> [music] [music] [music] [music] >> Heat. Heat. Heat. [music] [music] Heat. [music] >> [music] >> Heat. Heat. [music] [music] Heat. Heat. [music] [music] [music] >> [music] >> Heat. Heat. [music] Heat. Heat. [music] [music] [music] [music] >> [music] >> Hi everyone, welcome to the cyber apocalypse. Uh I am your host Falcon Spy. Uh we have a bunch of workshops ahead for all of you to participate and listen to. Uh we do have a couple of presentations where there'll be a live Q&A after the presentation uh wraps up. Uh so we'll start off here with uh our CTF development 101 back to our basics. So this is with Malaris. Uh we'll hav…