The content is not final - To be updated soon The registration is not yet OPEN
FSKM · UiTM Shah Alam

iHack 2026

Cybersecurity Event & Capture The Flag

A two-day cybersecurity gathering featuring CTF competitions, expert keynote talks, hands-on workshops, and industrial pitching — organized by FSKM, UiTM Shah Alam.

Registration Not Yet Open Learn More
17–18 Nov Main Event
30 Finalists
5 Program Tracks
ihack@fskm:~

$ ./start_ihack.sh --event 2026

[*] Loading: CTF, Keynote, Workshops...

[*] Preliminary: 12hr Jeopardy | Finals Attack & Defence + Jeopardy Defence

[+] iHack 2026 — 17-18 November (Tuesday & Wednesday). See you there!

{ SUPPORTING SPONSOR }
Eclogic

What is iHack?

iHack 2026 is an biennial cybersecurity event organized by the Faculty of Computer and Mathematical Sciences (FSKM), Universiti Teknologi MARA (UiTM) Shah Alam. Held on 17–18 November 2026 (Tuesday & Wednesday), the event brings together students, industry professionals, and security enthusiasts for an immersive two-day experience.

Beyond the flagship Capture The Flag (CTF) competition, iHack features a keynote talk from industry experts, three specialized workshops, and an industrial pitching session — connecting academic talent with real-world cybersecurity opportunities.

  • Main event: 17–18 November 2026 (Tuesday & Wednesday) at Dewan Mawar Qaseh, UiTM Shah Alam
  • Preliminary round: 26 September 2026 (12-hour online Jeopardy) · RM 50 per team
  • Teams of 3–4 members (3 active + 1 reserved slot) · Undergraduate university students
  • Top 30 teams advance to the 24-hour final (Attack & Defence + Jeopardy Defence)
🎯

Our Mission

To cultivate cybersecurity talent, promote ethical hacking practices, and build a vibrant community of security enthusiasts within Malaysia's academic landscape.

Event Program

iHack 2026 comprises five core components across two days of learning, competition, and industry engagement.

🎤

Keynote Talk

An inspiring session delivered by a leading cybersecurity expert, sharing insights on industry trends, career pathways, and the evolving threat landscape.

🔍

Technical Workshop 1: The Receipts Don't Lie

Investigate digital evidence through Linux and Windows log analysis. Learn to identify suspicious activities using grep, awk, and SIEM concepts while developing the investigative mindset of a Blue Team analyst.

🤖

Technical Workshop 2: Social Media Data Analysis

Harness the power of AI to transform public social media data into actionable intelligence. Explore SOCMINT techniques, web scraping, and Large Language Models (LLMs) to collect, classify, and analyze information with confidence.

🎓

Hacking Workshop for Secondary School

An introductory cybersecurity workshop designed for secondary school students, sparking early interest in ethical hacking and digital safety.

💼

Industrial Pitching

Students showcase their Final Year Project related to Cybersecurity solutions to industry player and security community.

iHack 2026 Training Workshops

Hands-on cybersecurity and data analysis sessions

📊

Social Media Data Analysis with LLMs

Learn SOCMINT techniques, scraping, and AI-based sentiment analysis using LLMs.

  • Date: 17 November 2026
  • Level: Beginner
  • Venue: Dewan Mawar Qaseh, UiTM Shah Alam
Registration Not Yet Open
🧠

The Receipts Don’t Lie: Log Analysis

Hands-on Linux/Windows log analysis using grep, awk, and SIEM concepts.

  • Date: 17 November 2026
  • Level: Beginner
  • Venue: Dewan Mawar Qaseh, UiTM Shah Alam
Registration Not Yet Open

CTF Competition

Two rounds — a 12-hour online Jeopardy qualifying round, then a 24-hour on-site final for the top 30 teams.

Round 1

Preliminary Round

  • Date: 26 September 2026
  • Format: Online · Challenge-based
  • Duration: 12 hours
  • Style: Jeopardy
  • Fee: RM 50 per team

All registered teams compete remotely in a Jeopardy-style CTF. Solve a series of challenges to qualify for the final round. Scoring is based on both correctness and speed of completion.

Round 2

Final Round

  • Date: 17–18 November 2026 (Tuesday & Wednesday)
  • Format: Face-to-face at Dewan Mawar Qaseh, UiTM Shah Alam
  • Duration: 24 hours (2 × 12-hour phases)
  • Qualifiers: Top 30 teams from preliminary
  • Fee: RM 200 per team

Finalists compete on-site across two 12-hour phases: Attack and Defence, followed by Jeopardy Defence focused on defensive cybersecurity skills.

Preliminary Round Challenges

Jeopardy-style challenges in the 12-hour preliminary round cover these domains.

01

Web Security

SQL injection, XSS, SSRF, authentication flaws, and modern web vulnerabilities.

02

Reverse Engineering

Disassembly, decompilation, and binary analysis.

03

Digital Forensics

Memory dumps, disk images, and digital evidence analysis.

04

Cryptography

Classical ciphers, RSA, hashing, and encoding challenges.

05

Binary Exploitation

Buffer overflows, ROP, heap exploits, and memory corruption.

06

Networking

Packet analysis, protocol abuse, and network-based challenge solving.

07

Blockchain

Smart contract flaws, on-chain analysis, and blockchain security challenges.

New
08

Cloud Security

Misconfigured cloud services, IAM issues, and exposed cloud functions.

New
09

AI Security

Prompt injection, LLM abuse, and AI-assisted attack and defence scenarios.

New

Preliminary Scoring Criteria

  • Correctness in completing challenges
  • Fastest to complete challenges
  • Scoring and writeup points differ by team category (Human / Humanoid / Robot)

Final Round Phases

The 24-hour on-site final is split into two 12-hour phases on 17–18 November 2026.

⚔️

Phase 1 — Attack and Defense

Duration: 12 hours. Teams attack and defend simultaneously — exploit opponents while securing their own systems under live competition conditions.

🛡️

Phase 2 — Jeopardy Defense

Duration: 12 hours. Teams solve defensive-focused challenges involving: Active Directory, threat analysis, log analysis, incident response, system hardening, and defensive scripting.

Final Round Notes

  • Only Human and Humanoid categories are expected to advance to the final round
  • During the onsite final, only AI tools approved or provided by the organiser are allowed

Event Details

📅

Date

17–18 November 2026

Tuesday & Wednesday/span>
📍

Venue

Dewan Mawar Qaseh, UiTM Shah Alam

CTF Finals · Workshops · Keynote · Pitching
👥

Team Size

3–4 Members

3 active members + 1 reserved slot (min. 3 to register)
💰

Registration Fee

RM 50 / team

Preliminary round · Finals: RM 200 per team (top 30)
🏆

CTF Finals

Top 30 Teams

24-hour final · 17–18 Nov (Tuesday & Wednesday)
🎓

Eligibility

Undergraduate Students

Age 26 or below · Valid student ID required

Competition Guidelines

🎓

Eligibility Criteria

  • Current students at a public or private university
  • Undergraduate students enrolled in a degree program
  • 26 years old or below at the time of registration
  • Must still be enrolled upon registering for the competition
📄

Documentation

Participants must provide proof of university enrollment and age during registration:

  • Matrix Card: University-issued student ID card
  • Other: Any official university document verifying enrollment and age
🤖

Team Categories

  • Human: No AI usage
  • Humanoid: AI chat usage allowed, not agentic
  • Robot: Full AI usage, including agents and AI-assisted tools

Rules and Regulations

The competition follows standard online and onsite CTF rules commonly adopted in cybersecurity competitions. Additional technical and operational rules may be provided prior to the competition.

General Rules

  • No attacking the CTF infrastructure
  • No attacking organiser systems
  • No denial-of-service against other teams unless explicitly permitted
  • No sharing flags across teams
  • No sabotage outside intended competition mechanics
  • No intentional disruption of competition availability
  • Teams must follow organiser instructions throughout the event

AI Usage Policy

As artificial intelligence tools become increasingly integrated into cybersecurity workflows, the competition aims to balance innovation, fairness, and human skill assessment.

  • Every team must declare the use of AI tools during participation.
  • Usage of MCPs, agents, automated workflows, and AI-assisted tooling must be disclosed.
  • Fully autonomous AI gameplay may not be accepted for final round participation.
  • Teams relying heavily on autonomous agents may be subject to review.
  • Writeups generated primarily using AI may not qualify for additional bonus points.
  • Priority and recognition may be given to teams demonstrating stronger human-driven gameplay.
  • During the onsite final round, only AI tools approved or provided by the organiser are allowed.
  • Use of external unauthorised AI systems during the final round may result in disqualification.

Policy on Cheating and Misconduct

Integrity and sportsmanship are critical components of the competition. Any participant or team found involved in cheating, misconduct, collusion, exploitation outside intended scope, plagiarism, or suspicious activity may be investigated by the organisers.

This includes incidents discovered:

  • During gameplay
  • During writeup submissions
  • During interviews or verification sessions
  • After the competition concludes

Following investigation and organiser review:

  • Teams or participants may be disqualified.
  • Participants may be banned from future REHACK-organised competitions or events.
  • Public disclosure of the participant name, team, and institution may be conducted where necessary to preserve competition integrity.

The organizer reserves the right to make final decisions regarding competition enforcement.

Schedule

1 Jun 2026

Registration Opens

Team registration and payment via the online form.

1 Sep 2026

Registration Closes

Final deadline to register for the preliminary round.

26 Sep 2026

Preliminary Round

12-hour online Jeopardy CTF (RM 50 per team). Top 30 teams qualify for the final round.

17 Nov 2026

iHack 2026 — Day 1 (Tuesday)

Opening ceremony, keynote talk, workshops, and final Phase 1 — Attack and Defense begins (RM 200 per team).

18 Nov 2026

iHack 2026 — Day 2 (Wednesday) & Closing

Phase 2 — Jeopardy Defense, industrial pitching, secondary school workshop, and prize ceremony.

Ready to Hack?

CTF and event registration will open soon. Stay tuned for the official announcement — content on this site is not final and will be updated.

Registration Not Yet Open