Red Hot Cyber

Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search

Kali Linux 2025.3 is out! A new release with improvements and new tools.

Redazione RHC : 24 September 2025 21:14

Kali Linux developers have released a new release, 2025.3 , which expands the distribution’s functionality and adds ten new penetration testing tools.

The update improves deployment processes in virtual environments, restores wireless driver support for Raspberry Pi, reworks several plugins, and drops support for the legacy ARMel architecture.

Developers have completely redesigned the virtual image creation process, updating integration with HashiCorp Packer and Vagrant . Scripts now use the version 2 standard, ensuring consistent template generation. Preconfiguration files for automated installations have been standardized, and Vagrant scripts can now apply additional settings immediately upon launch, eliminating the need for routine steps during lab deployment.

A major addition was the return of Nexmon for Broadcom and Cypress , including the Raspberry Pi 5. The patch enables monitoring mode and packet injection on devices where this functionality is not available in the standard drivers. At the same time, support for the ARMel architecture has been dropped, due to Debian’s decision to end maintenance after the release of “trixie” . The team is dedicating these resources to preparing for future RISC-V support.

Xfce users now have a redesigned IP VPN panel that allows them to select the interface to monitor and quickly copy the address of the specific connection they need.

Ten new tools have been added to the repository. These include the Caido graphical and console interfaces for web security auditing, the Detect It Easy utility for file type recognition, the Gemini CLI with AI agent integration directly into the terminal, and krbrelayx for Kerberos attacks.

Also added are ligolo-mp for traffic proxying, llm-tools-nmap for network scanning using language models, patchleaks for patch analysis, and vwifi-dkms for creating mock Wi-Fi networks.

The mobile version of Kali NetHunter has received major updates. Support for available devices now includes internal monitoring with frame injection in the 2.4 and 5 GHz bands. The port to the Samsung Galaxy S10 produced Broadcom-compatible firmware, a specialized kernel, and a stable ARM64 version of the hijacker utility.

  • Caido – The client side of caido (the graphical/desktop aka the main interface) – a web security auditing toolkit
  • Caido-cli – The server section of caido – a web security auditing toolkit
  • Detect It Easy (DiE) – File type identification
  • Gemini CLI – An open-source AI agent that brings the power of Gemini directly into your terminal
  • krbrelayx – Kerberos relaying and unconstrained delegation abuse toolkit
  • ligolo-mp – Multiplayer pivoting solution
  • llm-tools-nmap – Enables LLMs to perform network discovery and security scanning tasks using the nmap
  • mcp-kali-server – MCP configuration to connect AI agent to Kali
  • patchleaks – Spots the security fix and provides detailed description so you can validate – or weaponize – it fast
  • vwifi-dkms – Setup “dummy” Wi-Fi networks, establishing connections, and disconnecting from them

The CARsenal car module has been updated with a package and new features have been added, the activation of which requires re-running the installation script.

Thus, Kali Linux 2025.3 combines a redesigned virtualization infrastructure, updated wireless card drivers, and a number of new utilities, making the distribution even more convenient and relevant for security testing specialists.

Redazione
The editorial team of Red Hot Cyber consists of a group of individuals and anonymous sources who actively collaborate to provide early information and news on cybersecurity and computing in general.

Lista degli articoli