# Penetration

Published articles for Penetration.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Wiz Penetration Test Findings is now GA

DevFeed: [Wiz Penetration Test Findings is now GA](<https://devfeed.tech/articles/wiz-penetration-test-findings-is-now-ga-54112.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/wiz-pen-test-findings-is-now-ga>)

Author: Shaked Rotlevi

Published: 2026-08-19T15:36:58Z

Content type: release

Language: en

Sources: [Wiz Blog | RSS feed](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [audit](<https://devfeed.tech/tags/audit.md>), [automated](<https://devfeed.tech/tags/automated.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [data](<https://devfeed.tech/tags/data.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [lateral-movement](<https://devfeed.tech/tags/lateral-movement.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [product](<https://devfeed.tech/tags/product.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [wiz](<https://devfeed.tech/tags/wiz.md>)

### AI overview

Wiz announces the general availability of Wiz Penetration Test Findings, a platform feature that centralizes penetration-test results from bug bounties, third-party audits, internal red teams, and AI pen-test scanning. It correlates findings with cloud context, prioritizes exposures, maps attack paths, and tracks remediation.

### Source excerpt

Transform point-in-time pen-tests into continuous exposure management with unified platform combining pen-test findings and real-time cloud context

## State of Pentesting in Financial Services and Insurance Industries

DevFeed: [State of Pentesting in Financial Services and Insurance Industries](<https://devfeed.tech/articles/state-of-pentesting-in-financial-services-and-insurance-industries-54163.md>)

Original publisher: [Read original article](<https://www.cobalt.io/blog/state-of-pentesting-in-financial-services-and-insurance-industries>)

Author: Cobalt

Published: 2026-08-18T16:09:35Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog-4.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [LLM security](<https://devfeed.tech/topics/llm-security.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [incident](<https://devfeed.tech/topics/incident.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai-applications](<https://devfeed.tech/tags/ai-applications.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [incident](<https://devfeed.tech/tags/incident.md>), [insurance](<https://devfeed.tech/tags/insurance.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [red-teaming](<https://devfeed.tech/tags/red-teaming.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [state-of-pentesting](<https://devfeed.tech/tags/state-of-pentesting.md>)

### AI overview

A 2026 snapshot of pentesting in financial services and insurance finds that these sectors test AI applications more than any other sector and report the fewest AI or LLM security incidents. However, remediation performance is average, and the sectors are least likely to expand red-team operations.

### Source excerpt

The financial services and insurance industries are disciplined when it comes to pentesting, with one blind spot. While the financial services and insurance industries test their AI applications more than any other sector and have the fewest AI incidents, they to expand red teaming the least, and their remediation time is only mid-pack. Examined together, these two industries run security like the regulated sectors they are: programmatic, measured, and confident. This state of pentesting snapshot combines five years of Cobalt pentest findings with our 2026 survey of security leaders and practitioners, to profile how these sectors find, fix, and think about security risk. Their teams test AI more than anyone and report the lowest AI incident rate of any industry. Yet underneath that confidence, remediation is only average on the truer half-life measure. And despite testing the most, these two sectors are the least likely to add the one practice built to find what routine testing misses: red teaming. Sources: Cobalt State of Pentesting Report 2026 (~5,000 penetration tests/yr) - 2026 survey of 455 security leaders and practitioners (Emerald Research). Data from financial services and insurance industries are combined due to smaller sample sizes (n=65). The high-risk remediation funnel Every high-risk pentest finding runs this gauntlet, from discovery to closure. The sector resolves a high share of findings, but its half-life sits in the middle of the pack. 9% of findings are high-risk -> 86% of those get resolved -> 46d mean time to remediate -> 55d high-risk half-life 48 % test their AI applications programmatically (highest of any sector) 9 % have had an AI or LLM security incident (lowest of any sector) 17 % plan to increase red team operations (lowest of any sector) Where the financial and insurance industry stands: remediation half-life by sector Chart: the time to remediate half of all high-risk findings. Lower is better. The sector sits mid-pack on half-life (55 d

## If you're going to vibe code it, why not vibe pen test it?

DevFeed: [If you're going to vibe code it, why not vibe pen test it?](<https://devfeed.tech/articles/if-you-re-going-to-vibe-code-it-why-not-vibe-pen-test-it-51379.md>)

Original publisher: [Read original article](<https://www.pentestpartners.com/security-blog/if-youre-going-to-vibe-code-it-why-not-vibe-pen-test-it/>)

Author: Alex Wallace

Published: 2026-07-31T11:27:52Z

Content type: opinion

Language: en

Sources: [Pen Test Partners](<https://devfeed.tech/sources/pen-test-partners.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vibe coding](<https://devfeed.tech/topics/vibe-coding.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Development](<https://devfeed.tech/topics/development.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [development](<https://devfeed.tech/tags/development.md>), [it-security](<https://devfeed.tech/tags/it-security.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>)

### AI overview

This article presents PenAI, a hackathon proof of concept that uses an AI agent and a retrieval-augmented generation pipeline to automate parts of penetration testing. Given a target, VPN file, scope, and run settings, it performs reconnaissance, enumeration, exploitation, privilege escalation, findings, and reporting. The author argues that it can help with repetitive work and provide an initial security check, while still requiring the judgment, experience, and business context of professional testers.

### Source excerpt

TL;DR Why I built PenAI PenAI started as a project at a hackathon organised by Encode Club. It's an AI agent that could work through Hack The Box-style lab machines on its own. Upload a VPN file, give it a target IP, pick a scope, set stealth mode and iteration limits, hit run, and let [...] The post If you're going to vibe code it, why not vibe pen test it? appeared first on Pen Test Partners.

## Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)

DevFeed: [Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)](<https://devfeed.tech/articles/kali-linux-2026-2-release-gnome-50-kde-6-6-helper-scripts-apt-formats-vm-boot-tweaking-47145.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2026-2-release/>)

Published: 2026-06-29T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [2026.2](<https://devfeed.tech/topics/2026-2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [apt](<https://devfeed.tech/topics/apt.md>), [boot](<https://devfeed.tech/topics/boot.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [Usability](<https://devfeed.tech/topics/usability.md>)

Tags: [2026-2](<https://devfeed.tech/tags/2026-2.md>), [accessibility](<https://devfeed.tech/tags/accessibility.md>), [advanced](<https://devfeed.tech/tags/advanced.md>), [apt](<https://devfeed.tech/tags/apt.md>), [boot](<https://devfeed.tech/tags/boot.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [release](<https://devfeed.tech/tags/release.md>), [testing](<https://devfeed.tech/tags/testing.md>), [usability](<https://devfeed.tech/tags/usability.md>)

### AI overview

Kali Linux 2026.2 is a scheduled release featuring GNOME 50 and KDE Plasma 6.6 updates, infrastructure and helper-script changes, an updated APT format, VM boot optimizations, a reboot warning, kernel information, build-script changes, and nine new packages.

### Source excerpt

It's the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we think you will appreciate. The summary of the changelog since the 2026.1 release from March is: Desktop Environments - Bump to GNOME 50 and KDE Plasma 6.6 Helper Scripts Consistency - Consistency to our little launches at starting services APT Format - Goodbye sources.list, hello sources.list.d/kali.source VM Boot Optimisation - Smaller initrd + faster boot times = happy virtual machine users Reboot Warning - Heads-up, polkit and xrdp upgrades require a system reboot Kali Kernel Incoming - Staying with 6.19 for now, how to get 7.0 early Build Scripts Incoming - Heads-up with some changing on the way New Tools - As always, various new shiny packages have been added (9!) Desktop Environments Updates As we do roughly every six months, every other Kali release, our desktop environments get a major update. This time it's for: GNOME and KDE Plasma. Neither brings sweeping changes, but both have put real effort into refining performance and usability across the whole ecosystem. GNOME 50 GNOME 50 brings usability and performance improvements across the desktop. The file manager received significant optimizations, resulting in faster thumbnail and icon loading, improved responsiveness, and reduced memory usage. The desktop also received new accessibility enhancements through a brand-new preferences window, tweaks to the screen reader, and automatic language switching. Another addition is support for document annotations in the Document Viewer app, making it easier to add text notes and highlights directly to documents. Here you can read more about all the changes with this new GNOME release: GNOME 50 release announcement. KDE Plasma 6.6 KDE Plasma 6.6 focuses on improving usability and a

## Beyond Findings: Connecting Exploitable Risk to Cloud Context with Wiz and HackerOne

DevFeed: [Beyond Findings: Connecting Exploitable Risk to Cloud Context with Wiz and HackerOne](<https://devfeed.tech/articles/beyond-findings-connecting-exploitable-risk-to-cloud-context-with-wiz-and-hackerone-54090.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/wiz-hackerone-integration>)

Author: Bandhna Bedi

Published: 2026-05-13T13:00:02Z

Content type: release

Language: en

Sources: [Wiz Blog | RSS feed](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [attack-surface-management](<https://devfeed.tech/tags/attack-surface-management.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [security-graph](<https://devfeed.tech/tags/security-graph.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wiz-platform](<https://devfeed.tech/tags/wiz-platform.md>)

### AI overview

Wiz announces an integration with HackerOne that brings HackerOne findings into Wiz, enriching proven exploitability with cloud context. The integration connects findings to Wiz's Security Graph, extends attack-surface visibility, and maps related infrastructure, identities, and data flows.

### Source excerpt

See proven, exploitable risk in the context of your full cloud environment

## Introducing Penetration Test Findings: Unified Offensive Security in Wiz

DevFeed: [Introducing Penetration Test Findings: Unified Offensive Security in Wiz](<https://devfeed.tech/articles/introducing-penetration-test-findings-unified-offensive-security-in-wiz-53933.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/pen-test-findings>)

Author: Shaked Rotlevi

Published: 2026-05-05T13:00:34Z

Content type: release

Language: en

Sources: [Wiz Blog | RSS feed](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [audits](<https://devfeed.tech/tags/audits.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [claude](<https://devfeed.tech/tags/claude.md>), [offensive-security](<https://devfeed.tech/tags/offensive-security.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [security-graph](<https://devfeed.tech/tags/security-graph.md>)

### AI overview

Wiz introduces Penetration Test Findings, a Public Preview feature that unifies findings from bug bounty programs, external audits, internal penetration tests, and AI-generated reports in one context-rich workspace. The feature enriches findings with security metadata and Wiz Security Graph context to help offensive security teams prioritize remediation.

### Source excerpt

Streamline pen-testing by unifying findings from bug bounties, manual audits, and Wiz Red Agent into a single, context-rich view.

## Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)

DevFeed: [Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)](<https://devfeed.tech/articles/kali-linux-2026-1-release-2026-theme-backtrack-mode-47144.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2026-1-release/>)

Published: 2026-03-24T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Boot Process](<https://devfeed.tech/topics/boot-process.md>), [interface](<https://devfeed.tech/topics/interface.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [advanced](<https://devfeed.tech/tags/advanced.md>), [boot](<https://devfeed.tech/tags/boot.md>), [boot-process](<https://devfeed.tech/tags/boot-process.md>), [browser](<https://devfeed.tech/tags/browser.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [interface](<https://devfeed.tech/tags/interface.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Kali Linux 2026.1 is a new release featuring a refreshed visual theme, updated boot animation, a BackTrack mode for Kali-Undercover, community birthday activities, and eight new tools.

### Source excerpt

New year, new release - Kali 2026.1 is here! There is everything from a fresh coat of paint to a nod to our roots, with normal ongoing improvements. Building on from December's 2025.4, the summary of the changelog: 2026 Theme Refresh - Our yearly theme refresh BackTrack Mode For Kali-Undercover - New mode celebrating BackTrack's 20th anniversary Kali's 13th Birthday Event - A little community event New Tools - 8 new programs 2026 Theme Refresh As with previous 20xx.1 releases, this major update brings our annual theme refresh, a long-standing tradition that keeps the Kali Linux interface as modern and innovative. This year's release unveils a brand-new theme from the moment you boot. Everything from the boot menu, installer to the login display, and a fresh set of desktop wallpapers. Boot Animation The changes to the boot animation are subtle, but now the animation is fixed for live images, where it used to get stuck at the beginning, showing only the tail. It will also restart the loop in case the boot process takes longer, making it look smoother. Your browser does not support the video tag. Boot Menu Graphical Installer Login Desktop Kali Purple Desktop New Wallpapers BackTrack Mode For Kali-Undercover 2026 marks the 20th anniversary of BackTrack Linux, the predecessor to Kali. To celebrate this milestone, we wanted to bring back some nostalgia for longtime users of this legendary cybersecurity distribution by adding a "BackTrack mode" to kali-undercover. This mode transforms the desktop to recreate the look and feel of BackTrack 5, with the same wallpaper, colors, and window themes. You can run it directly from the menu or by running kali-undercover --backtrack in the terminal. You can switch back to the default Kali desktop (or not) by running it again. Your browser does not support the video tag. Here is a screenshot of BackTrack 5, so you can compare it with our theme: Kali's 13th Birthday Event Kali recently had our 13th birthday. To celebrate this, our disc

## Kali & LLM: Completely local with Ollama & 5ire

DevFeed: [Kali & LLM: Completely local with Ollama & 5ire](<https://devfeed.tech/articles/kali-llm-completely-local-with-ollama-5ire-47147.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-llm-ollama-5ire/>)

Published: 2026-03-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Ollama](<https://devfeed.tech/topics/ollama.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [CUDA](<https://devfeed.tech/topics/cuda.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [apt](<https://devfeed.tech/topics/apt.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [apt](<https://devfeed.tech/tags/apt.md>), [cuda](<https://devfeed.tech/tags/cuda.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [llm](<https://devfeed.tech/tags/llm.md>), [local](<https://devfeed.tech/tags/local.md>), [local-llms](<https://devfeed.tech/tags/local-llms.md>), [ollama](<https://devfeed.tech/tags/ollama.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A tutorial for running an LLM-driven Kali Linux setup entirely locally and offline using a GeForce GTX 1060, NVIDIA drivers, Ollama, 5ire, and an MCP Kali server. It covers hardware and driver checks, Ollama installation, model selection, testing, and MCP server setup.

### Source excerpt

We are extending our LLM-driven Kali series, where natural language replaces manual command input. This time however, we are doing everything locally and offline. We are using our own hardware and not relying on any 3rd party services/SaaS. Note: Local LLMs are hardware-hungry. The cost factor here is buying hardware and the running costs. If you have anything that you can re-use, great! GPU (Nvidia) Let's first find out what our hardware is: $ lspci | grep -i vga 07:00.0 VGA compatible controller: NVIDIA Corporation GP106 [GeForce GTX 1060 6GB] (rev a1) $ NVIDIA GeForce GTX 1060 (6 GB). Drivers We will check that our hardware is ready by making sure "non-free" proprietary drivers are installed. The non-free option allows for CUDA support which the open-source, nouveau, drivers lack. At the same time, make sure our Kernel and headers are at the latest version too: $ sudo apt update [...] $ $ sudo apt install -y linux-image-$(dpkg --print-architecture) linux-headers-$(dpkg --print-architecture) nvidia-driver nvidia-smi [...] │ Conflicting nouveau kernel module loaded │ │ The free nouveau kernel module is currently loaded and conflicts with the non-free nvidia kernel module. │ │ The easiest way to fix this is to reboot the machine once the installation has finished. | [...] $ $ sudo reboot Using a different GPU manufacture, such as AMD or Intel etc, is out of scope for this guide. Testing Once the box is back up and we are logged in again, we can do a quick check with nvidia-smi: $ lspci -s 07:00.0 -v | grep Kernel Kernel driver in use: nvidia Kernel modules: nvidia $ $ lsmod | grep '^nouveau' $ $ lsmod | grep '^nvidia' nvidia_drm 126976 2 nvidia_modeset 1605632 3 nvidia_drm nvidia 60710912 29 nvidia_drm,nvidia_modeset $ $ nvidia-smi Tue Jan 27 14:33:31 2026 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.163.01 Driver Version: 550.163.01 CUDA Version: 12.4 | |-----------------------------------------+------

## Kali & LLM: macOS with Claude Desktop & Anthropic Sonnet LLM

DevFeed: [Kali & LLM: macOS with Claude Desktop & Anthropic Sonnet LLM](<https://devfeed.tech/articles/kali-llm-macos-with-claude-desktop-anthropic-sonnet-llm-47146.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-llm-claude-desktop/>)

Published: 2026-02-25T00:00:00Z

Content type: tutorial

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Network](<https://devfeed.tech/topics/network.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [claude](<https://devfeed.tech/tags/claude.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [llm](<https://devfeed.tech/tags/llm.md>), [macos](<https://devfeed.tech/tags/macos.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [network](<https://devfeed.tech/tags/network.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A tutorial describes a setup that uses Claude Desktop on macOS, Kali Linux, and Anthropic's Sonnet 4.5 with Model Context Protocol to translate natural-language requests into technical commands and run tools such as Nmap. It also discusses reasons for using multiple operating systems and privacy considerations.

### Source excerpt

This post will focus on an alternative method of using Kali Linux, moving beyond direct terminal command execution. Instead, we will leverage a Large Language Model (LLM) to translate "natural language" descriptions of desired actions into technical commands. Achieving this setup requires the integration of three distinct systems: UI: Apple's macOS (Can also use Microsoft Windows, but not covered in this guide) - with Claude Desktop Attacking box: Kali Linux - using various tools LLM: In the cloud - Anthropic's Sonnet 4.5 The LLM is only part of the story. When paired with Model Context Protocol (MCP)'s, it allows/enables the LLM to seamlessly connect with external sources (data, programs/tools etc). At a very high level: We can ask a LLM to-do a task via a "prompt". "Can you please port scan scanme.nmap.org, if you find a valid web server, check if security.txt exists" The LLM will understand what we asked it to-do. "First task, I need to use Nmap/Network Mapper to-do a port scan of scan scanme.nmap.org" LLM will then request the MCP to-do any action(s). "Is Nmap installed? Can I access it?" MCP will run the request and return results $ nmap scanme.nmap.org The LLM will process the results as well as showing it to us as end-users. "I found that scanme.nmap.org is up, and contains a web server on port 80/TCP & 443/TCP." If needed, could be a loop, and re-run a command/action again back in the MCP until the prompt has been completed/full-filled. "Now I need see if /.well-known/security.txt gives HTTP 200 response" Just like the joys of text editors wars (vim vs emacs vs nano), this is not to say its the "best" way to-do it. This is a way. This scenario may work for you, or it may not be acceptable to you (e.g. privacy). That is fine. If you are wonder "Why this setup? Why are you using multiple OSes?", there are various reasons why! You may want a graphical user interface (GUI), which Claude Desktop is. Its an official product from Anthropic, who is making the model

## Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode)

DevFeed: [Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode)](<https://devfeed.tech/articles/kali-linux-2025-4-release-desktop-environments-wayland-halloween-mode-47143.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2025-4-release/>)

Published: 2025-12-12T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Wayland](<https://devfeed.tech/topics/wayland.md>), [xfce](<https://devfeed.tech/topics/xfce.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [advanced](<https://devfeed.tech/tags/advanced.md>), [desktop](<https://devfeed.tech/tags/desktop.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [releases](<https://devfeed.tech/tags/releases.md>), [testing](<https://devfeed.tech/tags/testing.md>), [wayland](<https://devfeed.tech/tags/wayland.md>), [xfce](<https://devfeed.tech/tags/xfce.md>)

### AI overview

Kali Linux 2025.4 updates the desktop experience with changes to GNOME, KDE Plasma, and Xfce, makes Wayland the default and only window server for GNOME, adds VM guest utility support, introduces Halloween Mode, and includes three new tools.

### Source excerpt

Say hello to Kali Linux 2025.4! Expect updated tools, performance tweaks, and improved support - no fluff, just the essentials. The summary of the changelog since the 2025.3 release from September is: Desktop Environments - Changes to all! GNOME, KDE & Xfce Wayland - VM Guest Utils Support Halloween Mode - dresses the desktop for the occasion 3 New Tools - As always, new packages added and upgraded! Desktop Environments GNOME 49 As with previous GNOME updates in Kali, we've given all our themes a fresh coat of paint - everything has been tuned to look sharp and feel smooth. The Totem video player has been replaced with the new Showtime app, and the app grid now finally organizes Kali tools into folders, just like the menu does, making it far more intuitive to find the tool you need. Changes to the application grid do not affect already installed versions of Kali. This is done to avoid overwriting the user's application layout. If you still want to see the new folders in the application grid, you can force the update with the following command: ┌──(kali㉿kali)-[~] └─$ cat /etc/dconf/db/local.d/kali-menu | dconf load / Another quality-of-life improvement is the addition of a shortcut to quickly open a terminal (finally!), using Ctrl+Alt+T or Win+T - just like in our other desktops. One of the major changes in GNOME 49 is the removal of X11 session support. Wayland is now the default - and only - window server, but do not worry: the transition is seamless and, as we explain later, even VM support is excellent. If you want to know more about the details of the new shell version, check out the official GNOME 49 release notes. KDE Plasma 6.5 KDE Plasma desktop has been bumped up to version 6.5, which brings two major releases of the desktop together. Here are some of the most relevant new features: More flexible window tiling New screenshot tool, with extra editing features Quick access to pinned clipboard items in the panel Fuzzy matching support for KRunner (Plasma's sea

## Kali Linux 2025.3 Release (Vagrant & Nexmon)

DevFeed: [Kali Linux 2025.3 Release (Vagrant & Nexmon)](<https://devfeed.tech/articles/kali-linux-2025-3-release-vagrant-nexmon-47142.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2025-3-release/>)

Published: 2025-09-23T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Vagrant](<https://devfeed.tech/topics/vagrant.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [hyper-v](<https://devfeed.tech/topics/hyper-v.md>), [Wi-Fi](<https://devfeed.tech/topics/wi-fi.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [advanced](<https://devfeed.tech/tags/advanced.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [hyper-v](<https://devfeed.tech/tags/hyper-v.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [monitor-mode](<https://devfeed.tech/tags/monitor-mode.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [release](<https://devfeed.tech/tags/release.md>), [testing](<https://devfeed.tech/tags/testing.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vagrant](<https://devfeed.tech/tags/vagrant.md>)

### AI overview

Kali Linux 2025.3 introduces refreshed Packer and Vagrant build workflows, Nexmon support for monitor mode and packet injection on supported wireless hardware including Raspberry Pi, and additional tools and package updates.

### Source excerpt

Another quarter, another drop - Kali 2025.3 is now here! Bringing you another round of updates, new features and introducing some new tools - pushing Kali further. The summary of the changelog since the 2025.2 release from June is: Packer & Vagrant - HashiCorp's products have had a refresh Nexmon Support - Monitor mode and injection for Raspberry Pi's in-built Wi-Fi 10 New Tools - As always, various new packages added (as well as updates) HashiCorp: Packer & Vagrant Kali has been using two HashiCorp products, which go hand-in-hand with each other: Packer - Creating VMs for multiple platforms from a single source configuration Vagrant - Building and managing VM environments Until now, we have been using our Packer build-script to generate our Vagrant VMs. This has been working well for us. We wanted to streamline our platform building process more, which prompted us to revisit how we generate Vagrant VMs. Whilst it is possible to automate Packer, it was not ideal for our infrastructure setup and workflow (e.g. trying to build Hyper-V images on Linux). This caused us to refresh a few items: Kali pre-seed examples - Packer uses pre-seed to automate the Kali installer - we made sure they are all consistent. Kali Packer build-scripts - We were using v1 of the standards. We upgraded to v2. Kali VM build-scripts - Vagrant images are VMs which a few tweaks done to them. We added these modification to our existing VM build-scripts. For more information, please keep reading our blog post: Kali Vagrant Rebuilt: Out With Packer, In With DebOS Nexmon Support Nexmon is a "patched" firmware, for certain wireless chips, to extend their functionally to allow: Monitor mode - able to sniff packets Injection mode - frame injection allows for custom raw packets to be sent, outside of the "standard" stack ordering Both are really useful when it comes to information security! For the record, it is possible to-do both of the features above without Nexmon, as it depends on the device's chip

## Kali Vagrant Rebuilt: Out With Packer, In With DebOS

DevFeed: [Kali Vagrant Rebuilt: Out With Packer, In With DebOS](<https://devfeed.tech/articles/kali-vagrant-rebuilt-out-with-packer-in-with-debos-47148.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-vagrant-rebuilt/>)

Published: 2025-08-21T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Vagrant](<https://devfeed.tech/topics/vagrant.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [hyper-v](<https://devfeed.tech/topics/hyper-v.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [hyper-v](<https://devfeed.tech/tags/hyper-v.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [template](<https://devfeed.tech/tags/template.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vagrant](<https://devfeed.tech/tags/vagrant.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Kali explains that it rebuilt its Vagrant VM images using DebOS instead of Packer. The new process builds stock and Vagrant virtual machines automatically in the same Linux-based infrastructure, while addressing Vagrant base-box requirements and compatibility with Hyper-V exports on Windows.

### Source excerpt

Vagrant files, *.box, are pre-configured Virtual Machines (VM) VM images, which when imported into HashiCorp's Vagrant, allow for VMs to be interacted with via the command line. You create, start, interact, stop, destroy VMs all without leaving the terminal. Think containers (Docker/Podman), but for VMs. Previously we have been using HashiCorp's Packer to generate our HashiCorp's Vagrant images. Packer is a wrapper, around whatever hypervisor you wish, and it will automate installing the OS (unattended setup via preseeding), run any commands or scripts, export the VM and finally compress it. The down-side to Packer is that you need to have the chosen hypervisor installed on the host OS, you can't cross-build. If you use Linux, you can't build Window's Hyper-V. For a few years now , we have been using DebOS, to automate building our VMs. This has been working great for us. Recently we realized: "Why do we have two different systems, for the same purpose?". A little bit of digging into "how to make a vagrant base box VM" boils down to just a few requirements: Fix username (vagrant) Fix/Known pubic SSH keys (default/standard insecure keypairs) Able to perform superuser actions (sudo) Simple really, just need to make sure that Vagrant can easy access the VM! Optional items (and recommended), as it helps benefits user's rather than Vagrant: Known/Fix credentials (vagrant everywhere) SSH tweaks (speed up for airgap networks) All of this can be handled in a post-install step, which we have put into our Kali-VM build-script. Now, we are building all of our VMs, automatically, in the same matter (Stock and Vagrant), all in the same infrastructure setup (Linux!). Since Microsoft Windows 10 1607 / Server 2016, when exporting VMs, there would be 3 additional "binary" files, *.vmcx/*.vmrs included as well as an *.xml. As we were no longer exporting the VM from Hyper-V, but generating it outside of, we do not have these files. Now, we could create a "template" binary which would

## Kali Linux & Containerization (Apple's Container)

DevFeed: [Kali Linux & Containerization (Apple's Container)](<https://devfeed.tech/articles/kali-linux-containerization-apple-s-container-47140.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-apple-container-containerization/>)

Published: 2025-07-29T00:00:00Z

Content type: tutorial

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [WSL2](<https://devfeed.tech/topics/wsl2.md>), [hyper-v](<https://devfeed.tech/topics/hyper-v.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [apple](<https://devfeed.tech/tags/apple.md>), [apple-silicon](<https://devfeed.tech/tags/apple-silicon.md>), [containerization](<https://devfeed.tech/tags/containerization.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [github](<https://devfeed.tech/tags/github.md>), [homebrew](<https://devfeed.tech/tags/homebrew.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A tutorial explains Apple's Container tool and its underlying virtualization components, then shows how to install and use it to run Kali Linux containers on Apple Silicon Macs. It also covers Docker Hub image pulls, directory sharing, aliases, and known networking limitations.

### Source excerpt

If you're an Apple user, you may have heard of Apple's upcoming feature Containerization during WWDC 2025. Quick summary: Container is a CLI tool, which works with Containerization. This is what end-users interact with. Containerization handles creating the containers, that talks to Virtualization.framework. Virtualization.framework is the hypervisor API (high level), and creates a new VM per container via Hypervisor.framework. Hypervisor.framework is the low level hypervisor API, which uses the macOS kernel (the hypervisor). It is similar to Microsoft's Windows Subsystem for Linux 2 (WSL), where a very small lightweight virtual machine (VM) is launched in the background, so a Linux kernel can be used on a non Linux host (WSL2 uses Hyper-V). Not to be confused with WSL1, which was more like WINE! Its set to be publicly released for the next major OS release, macOS "Tahoe" 26, and also for macOS "Sequoia" 15 . Containerization supports containers which are "Open Container Initiative (OCI) compliant", luckily our Kali image are! Setup If the first thing we see when trying to run container is: ~ % container zsh: command not found: container ~ % ...We need to install it. Doing a quick check to make sure our system is supported: ~ % sw_vers -productVersion 15.5 ~ % ~ % uname -m arm64 ~ % We are using macOS 15.5, on an Apple Silicon series device (aka arm64). We are good to go! If Homebrew is installed: ~ % brew install --cask container ==> Downloading https://github.com/apple/container/releases/download/0.2.0/container-0.2.0-installer-signed.pkg ==> Downloading from https://release-assets.githubusercontent.com/github-production-release-asset/993475914/c5fb6a42-f282-4dd7-95c2-af9b142f0ed1?sp=r&sv=2018-11-09&sr=b&spr=https&se=2025-07-17T14%3A06%3A32Z&r ######################################################################################################################################################################################################### 100.0% ==> Installing Ca

## Kali Linux Adds Refined Nexmon Support for Raspberry Pi Wi-Fi Monitor Mode and Injection

DevFeed: [Kali Linux Adds Refined Nexmon Support for Raspberry Pi Wi-Fi Monitor Mode and Injection](<https://devfeed.tech/articles/the-raspberry-pi-s-wi-fi-glow-up-47149.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/raspberry-pi-wi-fi-glow-up/>)

Published: 2025-07-22T00:00:00Z

Content type: article

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [Wi-Fi](<https://devfeed.tech/topics/wi-fi.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [testing](<https://devfeed.tech/tags/testing.md>), [wi-fi](<https://devfeed.tech/tags/wi-fi.md>)

### AI overview

Kali Linux has refined its Nexmon integration for Raspberry Pi wireless assessments. New packages and a newer kernel improve support for on-board Wi-Fi monitor mode and frame injection, including on supported Raspberry Pi 5 devices without an external USB adapter.

### Source excerpt

Thanks to Nexmon and fresh Kali packages, on-board wireless is ready for monitor mode and injection (again!). Kali Linux users on Raspberry Pi now have an improved and more integrated way to use the on-board Wi-Fi interface for wireless assessments. While the Nexmon project has long made this technically possible, our support in Kali has recently been refined. In Kali 2025.1, with the move to a newer Raspberry Pi kernel and a chance to revisit our packaging, we have cleaned up and formalized support for Nexmon through new packages. This not only improves the setup experience and adds support for more devices, including the Raspberry Pi 5, but also makes it easier to enable other hardware supported by Nexmon within Kali. Where We Started The Raspberry Pi has always been a compelling platform for portable Kali setups. But when it came to wireless assessments, things were less ideal. Raspberry Pi models use Broadcom/Cypress Wi-Fi chipsets, which don't support monitor mode or injection by default. That left users needing an external USB adapter. The Nexmon project, created by SEEMOO Lab at TU Darmstadt, changed that by offering a firmware patching framework that extends Broadcom's closed firmware with additional capabilities -- notably, monitor mode and injection. Nexmon works by modifying the firmware binaries themselves and providing patches for the Linux driver (brcmfmac) to support the required modes. Kali's integration of Nexmon has come a long way, though it hasn't always been smooth. We were on the 5.15 kernel series for quite some time, in part due to how we were packaging the kernel and managing patchsets. This made it difficult to support newer devices like the Raspberry Pi 5, which requires a more recent kernel. When we attempted to move to 6.6, we encountered stability issues. These were not caused by Nexmon itself, but by changes in the kernel and how they interacted with our setup. Rather than ship something unreliable, we decided to pause development until

## Kali Linux 2025.2 Release (Kali Menu Refresh, BloodHound CE & CARsenal)

DevFeed: [Kali Linux 2025.2 Release (Kali Menu Refresh, BloodHound CE & CARsenal)](<https://devfeed.tech/articles/kali-linux-2025-2-release-kali-menu-refresh-bloodhound-ce-carsenal-47141.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2025-2-release/>)

Published: 2025-06-13T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [changelog](<https://devfeed.tech/topics/changelog.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [bloodhound](<https://devfeed.tech/tags/bloodhound.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [release](<https://devfeed.tech/tags/release.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Kali Linux 2025.2 introduces a redesigned Kali Menu organized around the MITRE ATT&CK framework, upgrades BloodHound Community Edition, adds smartwatch Wi-Fi injection support and the CARsenal car-hacking toolkit, and includes 13 new tools. The release also updates GNOME and KDE and automates menu management through a YAML-based system.

### Source excerpt

We're almost half way through 2025 already, and we've got a lot to share with you in this release, Kali 2025.2. The summary of the changelog since the 2025.1 release from March is: Desktop Updates - Kali-Menu refresh, GNOME 48 & KDE 6.3 updates BloodHound Community Edition - Major upgrade with full set of ingestors Kali NetHunter Smartwatch Wi-Fi Injection - TicWatch Pro 3 now able to de-authenticate and capture WPA2 handshakes Kali NetHunter CARsenal - Car hacking tool set! New Tools - 13 new shinny tools added (and various updates) Desktop Updates Kali Menu Refresh We've completely reworked the Kali Menu! It's now reorganized to follow the MITRE ATT&CK framework structure - which means that finding the right tool for your task should now be a lot more intuitive for red and blue teams alike. Previously the Kali menu structure followed what was in BackTrack... which followed WHAX before it. The previous structure was an in-house item, before MITRE was a thing. When our menu was first created, there wasn't as much design planning done, which we suffered for later. It meant that over time, scaling and adding new tools became difficult for us. The knock on effect was that this made it harder for you, the end-users, to discover new tools as similar tools with overlapping functions were in different places or missing entries. Yes, seasoned professionals may not use the menu to start up items, using shortcuts such as super key and typing the tool name , or via a terminal window. We see the menu as a way to discover tools. The final nail in the coffin in the setup was the fact that it was manually managed. Yes, all those entries were previously created by-hand (which also may explain a few things). As a result, we had stopped adding new tools to the menu... until now. Now, we have created a new system and automated many aspects, making it easier for us to manage, and easier for you to discover items. Win win. Over time, we hope to start to add this to kali.org/tools/. Currentl

## Kagi passes an independent security audit

DevFeed: [Kagi passes an independent security audit](<https://devfeed.tech/articles/kagi-passes-an-independent-security-audit-51251.md>)

Original publisher: [Read original article](<https://blog.kagi.com/security-audit>)

Published: 2022-08-29T12:00:22Z

Content type: article

Language: en

Sources: [Kagi Blog](<https://devfeed.tech/sources/kagi-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [stripe](<https://devfeed.tech/topics/stripe.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [audit](<https://devfeed.tech/tags/audit.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [independent](<https://devfeed.tech/tags/independent.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [stripe](<https://devfeed.tech/tags/stripe.md>), [transparency](<https://devfeed.tech/tags/transparency.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Kagi describes an independent security audit conducted by Illumant from May through August 2022. The company says it received the highest rating, "Highly Secure," with no findings of material significance, after reviewing and addressing issues identified in the initial report.

### Source excerpt

Update: We passed a security audit when we launched to establish our baseline security, which was very important for us. As any security researcher knows, these audits can be invalidated with the very next deployment to...