AI & LLM security
Prompt injection, model abuse and data leakage from AI assistants.
Hands-on, real-world cybersecurity challenges for UAE university students. Break AI systems, web apps, crypto and industrial tech. Top performers qualify to compete live at ADIPEC 2026. Run by CyberElites with ADNOC and the UAE Cyber Security Council.
The scoreboard you will play on: score over time for the leaders, then the full ranking with every challenge. A flag is a solve; the gold hexagon is the first blood on that challenge. Sample players, played out live.
Hard, hands-on targets built around the systems that run a modern energy company. No quizzes: live machines you actually attack.
Prompt injection, model abuse and data leakage from AI assistants.
Break real-world web apps and APIs the way attackers do.
Find the weakness in custom and broken crypto.
Reconstruct an incident from logs, disks and network traffic.
Take binaries apart to find what they hide.
Energy-sector systems, protocols and telemetry.
Chain a foothold into full control: get in, look around, and escalate to root.
Keep a system standing while it is under attack: defend it, patch what breaks, and bring it back.
Hunt a live attack through a real SIEM: find every stage of the intrusion and pull the flags from the logs. Unlocked for the finalists at ADIPEC.
Fill the form. Your university email is how we confirm you are a UAE student.
Open the link we send to submit your application. It comes from [email protected].
The organisers review applications and email you when you are approved.
Choose a username, password and scoreboard name, and you are on the platform.
Solve challenges in the online qualifier. Top performers advance to the live Grand Final at ADIPEC, and the top three take the stage at the award ceremony.
You compete alone. No sharing flags, answers or instances with anyone.
AI agents, autonomous tooling and scripted solvers are prohibited. We monitor for automation across the platform and every challenge instance. Detected use means disqualification from the qualifier and the final.
Attack only the challenge targets given to you. Nothing else on the network is in scope.
Finalists may be asked to walk the judges through how they solved a challenge.
Use any tool you would normally use, and your own scripts. What you may not do is hand the challenge to something that solves it for you.
Each challenge carries points by difficulty. Equal scores are separated by who got there first, so solving early counts.
The scoreboard, the platform and other players' instances are not targets. Attacking them ends your competition.
Finalists compete on their own machine and need Emirates ID and university identification for venue access.
The Grand Final closes with an award ceremony at ADIPEC 2026. The top three finalists are honoured on stage, in front of the industry, alongside ADNOC, the UAE Cyber Security Council and CyberElites.
The things people ask us most. Anything else, write to us — the addresses are at the bottom of this page.
Students currently enrolled at a recognized UAE university, aged 18–26. You apply with your university email address, which is how we confirm you are a student. Places are limited and applications are reviewed.
Solo. One player, one account. Every challenge you solve has to be your own work — there is no team format in either round.
The online qualifier runs 12–16 October 2026, self-paced, from anywhere in the UAE. Your score is the points you collect, and ties are separated by who reached that score first. The top 24 go through to the Grand Final at ADIPEC on 5 November 2026.
You can use AI the way you would use documentation or a search engine — to learn, to read about a technique, to understand an error.
You may not use an AI agent or an automated solver that works through a challenge for you. That includes handing an agent your instance link or a terminal command and letting it find the flag.
This is monitored. The platform records how every challenge instance is used, and automated tooling does not leave the same trace as a person working. Suspected cases are reviewed by a human before any decision — but confirmed use means disqualification.
Nine categories: AI security, web, cryptography, forensics, reverse engineering, OT — industrial and operational technology — penetration testing, SIEM investigation and resilience. You do not need to be strong in all of them; the qualifier has a range of difficulty in each, and SIEM is unlocked for the finalists.
No. The qualifier starts with challenges that reward curiosity and careful reading rather than years of experience. Plenty of finalists at events like this are solving their first serious CTF.
No. Taking part is free, in both rounds. We will never ask you for payment or bank details — if anything claiming to be from us does, it is not from us.
Your own laptop and charger, your Emirates ID and your university identification, and your confirmation email. Finalists get a briefing pack with arrival times and the venue details beforehand.
Yes — everyone who competes receives a certificate of participation. The top three finalists are recognised on stage at the award ceremony at ADIPEC 2026.
Read the challenge description again, then stop and restart your instance — that fixes most of it. If it still looks wrong, email [email protected] with the challenge name and what you saw. Please do not post about it publicly while a round is open, and do not include a flag.