C
Cybersecurity Academy
Sign in
MetaInstagramGoogleXGitHubSlackFigmaStripeNotionAppleAirbnbAtlassian
Bug bounty + pentest training

Train on real disclosed bugs, in their real-world targets.

100+ hands-on labs and high-fidelity simulators that reproduce actual reported bugs at Meta, Instagram, Google, X, GitHub, and more. Pick a plan and start hunting.

See plansSign in
0+

Hands-on labs

0+

Vulnerability simulators

0

Real companies reproduced

0+

Bugs solved by trainees

Hands-on Labs

Drill IDOR, XSS, SSRF, SQLi, RCE, and auth bypass in clean isolated environments. Each lab has a server-graded flag, so completion is provable and sharing a flag with a friend never works.

Vulnerability Simulators

High-fidelity recreations of actual reported bugs at real companies. Same target, same vulnerable endpoint, same impact path the original researcher walked. The closest thing to real engagement work, with none of the legal risk.

Frequently asked

Labs are technique-focused environments where you drill IDOR, XSS, SQLi, and so on in isolation. Simulators are higher-fidelity recreations of an actual reported bug in a real target, so the practice mirrors a real engagement.
Every challenge issues a per-user flag computed server-side via HMAC. Sharing a flag with a friend never works because the hash binds it to your account. Completion is provable and account-bound.
Yes. Your completed challenges and progress stay on your account permanently. You just lose the ability to launch new labs until you renew or buy another plan. We don't auto-charge.
Account-bound by default. Reach out about team / classroom pricing if you need bulk seats with instructor-led boards and CSV onboarding.
Contact us within 7 days of purchase and we'll work it out. Any refund (full or partial) revokes access immediately.
No. Labs and simulators run in the browser. You get a launch button, the environment loads, and the server checks your flag when you solve.

Ready to train on real bugs?

Every minute on the platform is hands-on. You exploit, you submit the flag, the server confirms.

See plans

Pick a plan, start solving today

Monthly or yearly. Cancel anytime. Server-graded everything.

See plans
© Cybersecurity Academy · Built for practitioners.
Sign inPlans

Reproductions of real disclosures from

Recreations include real disclosures from

Brands you actually use, day to day

  • AMD
  • Adobe
  • Airbnb
  • Amazon
  • Atlassian
  • Barmajino-testing
  • Cisco
  • Cloudflare
  • Coinbase
  • AMD
  • Adobe
  • Airbnb
  • Amazon
  • Atlassian
  • Barmajino-testing
  • Cisco
  • Cloudflare
  • Coinbase
  • DigitalOcean
  • Discord
  • Dropbox
  • Etsy
  • GitHub
  • Google
  • Heroku
  • IBM
  • Instagram
  • DigitalOcean
  • Discord
  • Dropbox
  • Etsy
  • GitHub
  • Google
  • Heroku
  • IBM
  • Instagram

Featured simulators

Pick one and try to reproduce the original bug.

Barmajino-testing

Barmajino-simulator

Auth BypassMedium

Barmajino Simulator test

GitHub

Bulk Simulator #73

Auth BypassLow

Auto-generated simulator #73 for UI load testing (severity + company + filter coverage).

Dropbox

Bulk Simulator #72

Auth BypassLow

Auto-generated simulator #72 for UI load testing (severity + company + filter coverage).

See plans to access the full catalog