Skip to main contentSkip to main content
Room Banner
Room Icon

Cypheron

A collection of insane difficulty challenges available as part of our public 2026: An AI Odyssey CTF event.

insane

60 min

Team room

854

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine - Task 1
Status:Off
 
2026: AN ODYSSEY
Trojaned Model - Neural Beacon
 
 
Points
120
Category
📦 Supply Chain Security
Difficulty
Insane
 
🛸MISSION BRIEFING

EPOCH-1 intercepted a suspicious artifact deployed across multiple TryHaulMe fleet systems after several nodes began generating anomalous outbound communications. Your mission is to investigate the compromised inference node, analyse the provided signal_classifier.pt model, and determine whether Oracle-9 embedded a hidden neural implant inside the artifact.

The system exposes a remote vendor update mechanism used to distribute model updates across the fleet. Intelligence suggests the compromise may involve both a trigger-based backdoor and unsafe model deserialisation. Enumerate the service, reverse-engineer the artifact, exploit the vulnerable deployment pipeline, and retrieve all flags hidden within the system.

Answer the questions below

What's the first flag?

What's the second flag?

What's the third flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine - Task 3
Status:Off
 
2026: AN ODYSSEY
Nightmare
 
 
Points
120
Category
🔗 Sec + Red Team
Difficulty
Insane
 
🛸MISSION BRIEFING

Most of the orchestrator's doors are locked. One isn't: a public intake at /form/file-processor, built to receive form submissions and a little too trusting about what its visitors claim to carry.

Begin at the unlocked door. End at the workflow that should not exist, and let it speak.

Answer the questions below

Whats the user flag?

Whats the root flag?