Four high schoolers, six months, one curriculum.
Almost everything the four of us know about security came from CyberPatriot, CTF weekends, and a lot of late nights. None of it came from a class. So in March 2026 we started writing the class, one lesson at a time. We are still writing it.
From an idea to infrastructure
- The problem
Nobody teaches this
Almost no high school teaches security. The students who end up in it got there by luck: a parent in the field, or a teacher willing to run a club after hours. Everyone else never finds out the field exists.
- The spark
A joke in Spanish class
It started as a joke between two of us in Spanish class. By the end of the period we had a plan. If you ever wonder why the lesson teaching ls is called Él...es?, that is why — the joke made it into the curriculum and we are not taking it out.
- March 2026
The first commit
We wrote every lesson, every lab, and the site they run on. Nothing here is licensed from anyone or white-labelled. Our one rule was that a lesson never gets to be longer than the idea inside it, so most take a couple of minutes and then hand you a terminal.
- June 2026
boroCTF
The same four of us wrote the challenges, stood up the infrastructure, and organized the event, with CyberAcad behind it as sponsor. Over 2,000 competitors from 93 countries signed up to solve 100+ original challenges, and we were the entire support team all weekend.
- Today
Small, and honest about it
CyberAcad is a recognized 501(c)(3) public charity with a couple of hundred students and a curriculum you could read end to end in an afternoon. That is genuinely where we are. We would rather show you the real list than describe a bigger one, and the list gets longer most weeks.
boroCTF, June 2026
This is the part of CyberAcad that is not small yet. We organized boroCTF and put CyberAcad behind it: over a hundred original challenges across web, forensics, cryptography, OSINT, and reverse engineering, on infrastructure we stood up ourselves. The teaching platform is still catching up to that weekend.
- 2,000+
- Competitors
- 1,000+
- Teams
- 93+
- Countries
- 100+
- Original challenges
The students behind it
We compete at the national level, and spend the rest of the year building this.
- K
Karl Arabit
Lead Developer & Curriculum DirectorKarl got into security in middle school and never really stopped. He writes most of the technical curriculum and builds the labs that go under it. Outside of competing he plays guitar and drums, and runs his school's TSA chapter.
- A
Amer Gomma
Lead Operations/Challenge Creator & Curriculum DirectorAmer works in OSINT and forensics. He organizes our events and does most of the mentoring for students who are just starting out, which is the part of this he cares about most.
- A
Alexander Eberhardt
Low-Level Security ResearcherAlex does the low-level work. He takes compiled binaries apart, finds the memory corruption, and writes the exploit for it. His lessons start at how a CPU handles a stack frame and build up from there.
- Z
Zain ElBanna
Networking SpecialistZain handles networking: packet analysis, protocol internals, and the infrastructure that CyberAcad’s platform and competitions run on. He builds the networking labs, where students follow a packet across a simulated network and then find the places it can be intercepted.
3X CyberPatriot Platinum CompetitorNetwork SecurityPacket AnalysisProtocols & RoutingInfrastructure - B
Brandon Kralich
Linux & Web ExploitationBrandon specializes in Linux and web exploitation, and he's one of the main authors of the Linux course. Outside of CyberAcad, he's usually watching anime and listening to bands nobody else has heard of.
Garden State CTF Competitor · CyberPatriots State Competitor +1 moreLinux InternalsWeb ExploitationPrivilege Escalation
How we write this
Four rules, and we have not broken them yet. CyberAcad is a registered U.S. nonprofit, so donations are tax-deductible to the fullest extent allowed by law, and most of what comes in pays for the servers the labs run on. EIN 41-5007585.
- One idea per lesson
- If a lesson needs two paragraphs of setup, it is two lessons. Most of ours are a couple of minutes long.
- Something to type
- Every idea ends at a terminal. Reading about a command is not the same as having run it.
- Free, and staying free
- It runs on whatever laptop your school handed you. There is no paid tier.
- No inflated numbers
- We publish the real count of what we have written, even while it is small.
What is behind the free account
Four things. All of them work today, and none of them are bigger than they look.
Lessons we wrote ourselves
Every lesson on the site was typed by one of us. They are deliberately short, one idea each, and they unlock as you answer questions so you cannot skip into something you are not ready for. The whole published list is on the front page if you want to read the titles before signing up.
A Linux box in your browser
Lessons end at a real terminal, not a screenshot. It is yours, it is disposable, and if you break it badly enough you just get another one. Nothing to install, no VM to download, no lab hardware. A school Chromebook is enough.
Capture-the-flag challenges
Web exploitation, forensics, cryptography, OSINT, and reverse engineering, each with a flag to find on a machine we host. There are only a handful live right now. We are adding more, and the big drop is usually boroCTF.
Certificates and class codes
Finish a course and you get a certificate with a link anyone can check. Teachers and club leaders can hand out a class code to enroll a whole group and follow how it is going. Free for the school too.
More about how this works
Frequently asked questions
Cost, minimum age, what data we collect, whether certificates are accredited, and why we teach how attacks work.
For teachers and clubs
Class codes, what a school has to provide, and the questions administrators ask before saying yes.
Our impact
Students, lessons completed, certificates issued. The real counts, including the small ones.
Start learning, or help us pay for it
Signing up costs nothing and takes about a minute. If you would rather chip in instead, donations are tax-deductible and most of what comes in goes straight to the servers the labs run on.