Team OxUA, which included A42 specialists, took 1st place among all the teams from Ukraine and 16th place worldwide at Cyber Apocalypse CTF 2026, one of the most prestigious competitions for ethical hackers.
Team OxUA, which included A42 specialists, finished Cyber Apocalypse CTF 2026 by Hack The Box in 1st place among Ukrainian teams and 16th in the global standings, having captured all 136 flags. The competition drew more than 12,000 participants across 6,443 teams, who spent several days solving hands-on challenges that simulate real-world attacks on applications and infrastructure.
What is Cyber Apocalypse CTF
Cyber Apocalypse CTF is an annual online Jeopardy-style cybersecurity competition by Hack The Box and one of the largest CTFs in the world. This year's event ran from July 24 to 29, with Team OxUA completing it ahead of schedule. Participants had to solve 74 challenges across 16 categories, modeling real attacks on applications, infrastructure, and authentication systems. The rules officially allowed AI as a supporting tool, provided the team could explain how it reached each solution.
To tackle the CTF challenges, 0xUA used A42's AI-powered tools for vulnerability discovery, the same ones behind our products. This enabled the team to solve the challenges faster while achieving higher-quality results.
0xUA's strong global result is one more proof of how effective A42's tools for vulnerability discovery and penetration testing really are. Built on a proven methodology and the team's deep expertise, they consistently deliver faster results with greater depth and accuracy. On top of that, the competition shows something important: AI doesn't replace real knowledge, it makes it stronger.
For context, in June 2026 A42 introduced AI Pentest — a penetration test built on a multi-agent architecture with more than 100 attack schemes from playbooks of elite white hat hackers in GovTech and Defence Tech. Thanks to AI agents, clients receive an enterprise-grade pentesting with a compliance-ready report in just four days, significantly faster and more cost-effective than manual testing. Our agents have previously discovered vulnerabilities in Lovable, a no-code website-building service.



