REMnux v8 was released as a major rebuild of the malware-analysis Linux distribution, moving its base to Ubuntu 24.04 ahead of Ubuntu 20.04 end-of-life and introducing a new Cast-based installer that supports fresh installs, upgrades, and installing REMnux tooling onto an existing Ubuntu system. A headline addition is the REMnux MCP server, which implements the Model Context Protocol (MCP) to connect AI agents to REMnux’s 200+ preconfigured malware-analysis tools with embedded practitioner guidance on which utilities to use for different artifact types.
Separately, PentestAgent was published as an open-source AI agent framework for penetration testing, featuring a terminal UI with assisted, autonomous, and multi-agent “crew” modes, plus prebuilt attack playbooks and HexStrike integration. It is designed to drive black-box assessment workflows (reconnaissance, scanning, exploitation) using LLMs via LiteLLM and a RAG-backed knowledge system, with session artifacts and findings persisted (e.g., loot/notes.json) to inform subsequent agent actions; the project emphasizes authorized-use constraints.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
REMnux released version 8 of its Linux malware analysis distribution, rebuilding the platform on Ubuntu 24.04 as Ubuntu 20.04 approaches end-of-life. The update added a Cast-based installer, a new MCP server for connecting AI agents to more than 200 analysis tools, refreshed utilities, and new tooling such as YARA-X.
A developer and researcher using the alias Masic (GH05TCREW) released PentestAgent, an open-source AI agent framework for authorized penetration testing, on GitHub. The project includes prebuilt attack playbooks, HexStrike integration, and support for LLM-assisted black-box assessments.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.