• Kali Linux 2025.3 has arrived, bringing a wave of improvements, updated firmware support, and a suite of ten new security tools. This release builds on the June 2025.2 update by refining core workflows, extending wireless capabilities, and preparing the distribution for emerging architectures. Whether you rely on virtual machines, Raspberry Pi devices, or mobile pentesting […]

    The post Kali Linux 2025.3 Launches With Fresh Features and 10 New Pentesting Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cloud security company Wiz has revealed that it uncovered in-the-wild exploitation of a security flaw in a Linux utility called Pandoc as part of attacks designed to infiltrate Amazon Web Services (AWS) Instance Metadata Service (IMDS). The vulnerability in question is CVE-2025-51591 (CVSS score: 6.5), which refers to a case of Server-Side Request Forgery (SSRF) that allows attackers to

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent security alert regarding an actively exploited zero-day vulnerability in Google Chrome.  The vulnerability, designated as CVE-2025-10585, affects the V8 JavaScript and WebAssembly engine within Google Chromium, creating significant security risks for users worldwide. Critical Type Confusion Flaw Discovered The newly identified vulnerability represents a […]

    The post CISA Issues Alert on Actively Exploited Google Chrome 0-Day Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Kali team has released Kali Linux 2025.3, the third major update of the year for the popular penetration testing and ethical hacking distribution.

    This release introduces 10 new tools, brings significant updates to its mobile platform, Kali NetHunter, and enhances wireless capabilities for Raspberry Pi devices

    Key updates in this version include a refresh of HashiCorp Packer and Vagrant integration, the reintroduction of Nexmon support, and various improvements to the user experience and underlying system architecture.

    Major Features and Enhancements

    The Kali Linux 2025.3 release comes with several notable improvements and changes since the June 2025.2 version.

    • Nexmon Support for Raspberry Pi: One of the headline features is the return of Nexmon support, a patched firmware that enables monitor mode and frame injection on certain wireless chips. This update brings these advanced Wi-Fi capabilities to the Raspberry Pi’s built-in wireless card, including for the Raspberry Pi 5. This allows security professionals to sniff wireless packets and inject custom raw packets, which is crucial for wireless security assessments. The 64-bit (arm64) image is now recommended for Raspberry Pi devices, and it includes support for the Pi 5, eliminating the need for a separate image.
    • HashiCorp Packer & Vagrant Refresh: The development team has streamlined how it builds Virtual Machine (VM) images by revamping its use of HashiCorp’s Packer and Vagrant tools. To improve the build process, Kali’s Vagrant images are no longer generated using Packer. Instead, the modifications are now part of the existing VM build scripts, and the team has upgraded its Packer build scripts to v2 standards.
    • Dropping ARMel Support: Following in Debian’s footsteps, Kali Linux is discontinuing support for the ARMel architecture. This change affects a small number of older devices, such as the original Raspberry Pi 1 and Raspberry Pi Zero W. The team stated that the resources required to maintain this legacy architecture are better spent on newer platforms like RISC-V.
    • Configurable Xfce VPN IP Plugin: The Xfce desktop environment’s VPN IP plugin has been updated. Users can now configure which network interface the plugin monitors, an improvement for those using multiple VPN connections or non-standard interfaces.

    10 New Hacking Tools

    As with every release, Kali 2025.3 adds a fresh set of tools to its arsenal. This version includes 10 new packages:

    • Caido & Caido-cli: A web security auditing toolkit with a graphical client and command-line server.
    • Detect It Easy (DiE): A utility for identifying file types.
    • Gemini CLI: An open-source AI agent that integrates Google’s Gemini into the command line.
    • krbrelayx: A toolkit for Kerberos relaying and abusing unconstrained delegation.
    • ligolo-mp: A solution for creating multi-user pivoting tunnels.
    • llm-tools-nmap: A tool that allows Large Language Models (LLMs) to use nmap for network scanning.
    • mcp-kali-server: A configuration tool for connecting AI agents to Kali.
    • patchleaks: A tool designed to quickly identify and detail security fixes in software patches.
    • vwifi-dkms: A module for creating virtual “dummy” Wi-Fi networks.

    Kali NetHunter and ARM Updates

    The Kali NetHunter platform for mobile devices received significant updates. A major announcement is the support for the Samsung Galaxy S10 as a new budget-friendly device capable of internal Wi-Fi monitor mode and injection on both 2.4Ghz and 5Ghz bands.

    The CARsenal car hacking suite has also been heavily updated with a new user interface, refactored code, expanded tools, and improved simulation capabilities with the addition of UDSim.

    How to Get Kali Linux 2025.3

    For new installations, fresh images are available for download from the official Kali website. Existing Kali Linux users can upgrade their system to version 2025.3 by running the following commands in their terminal:

    bashsudo apt update && sudo apt -y full-upgrade
    

    After the update, users can verify the new version by checking the /etc/os-release file.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Kali Linux 2025.3 Released With New Features and 10 New Hacking Tools appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SonicWall has released an urgent software update for its Secure Mobile Access (SMA) 100 Series appliances to remove a dangerous rootkit known as ‘OVERSTEP.’ This backdoor malware was discovered in older SMA firmware versions and can give attackers persistent access to affected devices. The new build, version 10.2.2.2-92sv, adds additional file checking to detect and […]

    The post SonicWall Issues Emergency Patch to Remove ‘OVERSTEP’ Rootkit Malware on SMA Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • For China’s People’s Liberation Army, massive parades like the recent celebration of the 80th anniversary of victory in World War II are more than propaganda set pieces. Military leaders use them to show their Party superiors that the force is progressing towards its modernization goals, including being ready to fight jointly and to defeat any potential adversary—particularly “the strong adversary,” i.e., the United States. And as PLA texts attest, parades are opportunities to unveil new systems intended to deepen nuclear and conventional deterrence.

    The hours-long showcase on Sept. 3 offered glimpses of new weapons—especially missiles—and hints about about China’s progress on key military technologies. These are valuable because the PLA operates in an opaque manner, and because its equipment and weapons, with some notable exceptions, have seldom been tested on the battlefield. But analysts must proceed cautiously: the parade was at heart a carefully calibrated influence operation. As one U.S. military analyst recently noted, the military equipment that the PLA displayed “was exactly what they wanted the world and the U.S. military to see.”   

    So what should we make of five PLA missile systems that made their public debut on Sept. 3? Are they mere showpieces—“old wine in a new bottle,” as the Chinese idiom goes—or are they showstoppers that should give U.S. military planners pause? 

    DF-61 ICBM: Showpiece (mostly). Little is known about this massive, road-mobile, solid-fueled ballistic missile beyond its reported range of over 12,000 kilometers and alleged payload of up to ten multiple independently targetable reentry vehicles. But several analysts suspect it may be an incrementally updated version of the DF-41 road-mobile ICBM that appeared in the 2019 parade and is now operated by the PLA Rocket Force. The missiles are similar in design and use the same transporter-erector-launcher. Both systems are made by the China Academy of Launch Vehicle Technology under the China Aerospace Science and Technology Corporation, an enormous state-owned aerospace enterprise that is the country’s sole ICBM manufacturer

    In the parade, the DF-61 rolled among other strategic weapons, which further suggests that it is simply a better version of the nuclear DF-41. And yet: the possibility exists that its placement was deception. It is conceivable that the weapon is a new conventional ICBM—and a significant boost to the PLA’s long-range tactical striking power.

    DF-5C ICBM: Showpiece. Bringing up the rear of the parade’s missile column was the DF-5C, an upgraded variant of the four-decade-old DF-5, the PLA’s oldest active ICBM. The arrival of the C variant adds range and warheads to China’s array of liquid-fueled, silo-based missiles. But its technology is not new, having been first tested in 2017; and its predecessor DF-5B could also carry MIRVs to any target in the United States. 

    In the parade, the DF-5B followed the DF-31BJ, an improved version of the DF-31AG solid-fueled ICBM that first appeared in 2017. The prominence of these two silo-based missiles at the end of the line is a reminder that even as the PLA adds road-mobile ICBMs and works to consolidate a nuclear triad with better sea- and air-launched nuclear missiles, its expanding network of ICBM silos remains another key element of deterrence. 

    CJ-1000 long-range hypersonic cruise missile: Showstopper. The parade’s “cruise missile column” saw the debut of several advanced air, sea, and ground-launched cruise missiles. None is a bigger gamechanger than the Changjian-1000, which ups the PLARF’s precision-strike capabilities with engines that U.S. missiles still lack. 

    Unlike the PLARF’s current DF-17 hypersonic missile, which uses a boost glide system, the CJ-1000 and the YJ-19 missile (see below) are propelled by airbreathing scramjet engines, which makes the PLA just the second military, after Russia’s, to deploy scramjet hypersonic weapons. The U.S. Air Force’s effort to develop a hypersonic cruise missile, meanwhile, is delayed and over budget.

    The U.S. Army’s Training and Doctrine Command reports that the CJ-1000 can launch quickly and penetrate deeply against high-value land or sea targets. And although U.S. missile defense systems such as THAAD have received upgrades to better track and intercept hypersonic attacks, they will be challenged by the high maneuverability and long range of the CJ-1000, which can purportedly launch from Fujian in eastern China and hit Guam in 38 minutes. Xinhua agrees: the speedy, nimble, long-ranged CJ-1000 is a potential gamechanger that threatens U.S. bases in the western Pacific.

    YJ-19 hypersonic anti-ship missile: Showstopper. The parade’s anti-ship missile formation introduced four new types—three of which are likely hypersonic. Perhaps the most notable is the YJ-19, whose scramjet is reportedly capable of flying faster than Mach 10 out to around 1,440 kilometers. Its waverider configuration harnesses its own shockwaves to improve lift-drag ratio.

    If the capabilities are as advertised, the YJ-19 will greatly improve the ability of the PLA Navy’s surface ships and attack submarines to strike enemy warships within the first and even second island chains. Like the CJ-1000, it provides a capability that the U.S. does not currently have and raises the level of risk to U.S. forces responding to a contingency in our around Taiwan, the South China Sea, or the East China Sea.

    HQ-29 anti-ballistic missile and anti-satellite weapon: Showstopper. Among the several HQ-series surface-to-air missiles debuted in the parade’s air defense column, the standout was the Hongqi-29—and not just because it was the largest. 

    The HQ-29 is a follow-on to the HQ-19 high-altitude interceptor, which employs kinetic-kill technology akin to the U.S. THAAD system. It is road-mobile, unlike other long-range interceptors that are silo-based, allowing for more flexible deployments and optimization of launch position. The HQ-29 also provides the PLA with an interceptor that can hit incoming ICBMs in midcourse—or even low-earth orbit satellites. If and when it is fielded, it will improve China’s regional ballistic missile defense and anti-satellite warfare capabilities.  

    China clearly intended its Sept. 3 parade to convey its growing military strength and technological ambition, and it succeeded. The new and not-so-new missiles clearly show the PLA’s growing ability to project power and Beijing’s intention to fundamentally alter the region’s military balance. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Libraesva has released a security update to address a vulnerability in its Email Security Gateway (ESG) solution that it said has been exploited by state-sponsored threat actors. The vulnerability, tracked as CVE-2025-59689, carries a CVSS score of 6.1, indicating medium severity. “Libraesva ESG is affected by a command injection flaw that can be triggered by a malicious email containing a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Darktrace’s latest investigation uncovered a novel campaign that blends traditional malware with modern DevOps technology. At the center of this operation lies a Python-based command-and-control (C2) framework hosted on GitHub CodeSpaces. The threat actors leverage a multi-stage Docker deployment initiated by a Python spreader, followed by a Go-based Remote Access Trojan (RAT) that implements a […]

    The post ShadowV2 Botnet Infects AWS Docker Containers to Launch DDoS Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA has released a comprehensive cybersecurity advisory detailing how threat actors successfully compromised a U.S. federal civilian executive branch agency’s network by exploiting CVE-2024-36401, a critical remote code execution vulnerability in GeoServer.

    The incident, which remained undetected for three weeks, highlights significant gaps in vulnerability management and incident response preparedness within federal agencies.

    GeoServer RCE Vulnerability (CVE-2024-36401)

    The attack commenced on July 11, 2024, when cyber threat actors exploited CVE-2024-36401 on a public-facing GeoServer instance to gain initial network access. 

    This critical vulnerability, disclosed on June 30, 2024, enables unauthenticated users to achieve remote code execution through “eval injection” attacks on affected GeoServer versions. 

    The vulnerability carries a CWE-95 classification for “Eval Injection” and was subsequently added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on July 15, 2024.

    The threat actors demonstrated persistence by exploiting the same vulnerability on a second GeoServer (GeoServer 2) on July 24, 2024, despite the vulnerability being publicly disclosed 25 days earlier. 

    Between these initial compromises, the attackers conducted extensive reconnaissance using Burp Suite Burp Scanner to identify vulnerable systems and employed publicly available tools, including the fscan network scanner and linux-exploit-suggester2.pl, for comprehensive network enumeration.

    Following initial access, the threat actors established persistence through multiple techniques, including deployment of China Chopper web shells, creation of cron jobs for scheduled command execution, and attempts to escalate privileges using the publicly available dirtycow exploit targeting CVE-2016-5195. 

    Overview of Threat Actor Activity
    Overview of Threat Actor Activity

    The attackers also staged the RingQ defense evasion tool and utilized the Stowaway multi-level proxy tool to establish command and control communications over TCP ports 4441 and 50012.

    The compromise escalated as threat actors moved laterally from the initial GeoServer to a web server and subsequently to a SQL server, uploading web shells and scripts on each compromised system. 

    On the SQL server, they executed extensive discovery commands including whoami, systeminfo, tasklist, and netstat -ano to enumerate system information and network connections. 

    The attackers enabled cmdshell for remote code execution and utilized PowerShell and bitsadmin for payload downloads, demonstrating sophisticated living-off-the-land techniques.

    The incident remained undetected for three weeks until July 31, 2024, when the agency’s endpoint detection and response (EDR) tool identified a suspicious 1.txt file uploaded to the SQL server. 

    This detection delay occurred despite the EDR system generating an alert on July 15, 2024, when it detected the Stowaway tool on GeoServer 1, which went unreviewed by the security operations center. 

    The agency’s Web Server notably lacked endpoint protection entirely, creating additional blind spots in their security monitoring capabilities.

    Risk FactorsDetails
    Affected ProductsApache GeoServer 2.x (all releases before 2.26.5)
    ImpactRemote Code Execution via eval injection
    Exploit PrerequisitesPublicly accessible GeoServer instance; no auth
    CVSS 3.1 Score9.8 (Critical)

    CISA’s analysis revealed three critical lessons learned from this incident: vulnerabilities were not promptly remediated despite public disclosure and KEV catalog inclusion, the agency’s incident response plan lacked procedures for engaging third-party assistance and granting necessary access to security tools, and EDR alerts were not continuously monitored across all systems. 

    The advisory emphasizes that while July 24, 2024, fell within the KEV-required patching window, organizations should address known exploited vulnerabilities immediately as part of comprehensive vulnerability management practices.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Details That Hackers Gained Access to a U.S. Federal Agency Network Via GeoServer RCE Vulnerability appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Zscaler ThreatLabz have identified a sophisticated new malware strain dubbed YiBackdoor, first detected in June 2025. This emerging threat represents a significant evolution in backdoor technology, sharing substantial code similarities with established malware families IcedID and Latrodectus. The discovery highlighted the continuous adaptation of cybercriminal tools, as YiBackdoor demonstrates capabilities that enable […]

    The post New “YiBackdoor” Malware Lets Hackers Run Commands and Steal Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶