Two new AI-assisted offensive security efforts were highlighted: BlacksmithAI, an open-source penetration testing framework, and a Kali Linux workflow that enables natural-language control of common pentesting tools via Anthropic’s Claude. BlacksmithAI is described as a hierarchical, multi-agent system where an orchestrator decomposes assessment goals and delegates work to specialized agents aligned to typical pentest phases (recon, scanning/enumeration, vulnerability analysis, exploitation, and post-exploitation), then compiles results into reporting.
Separately, Kali Linux was reported to support a native AI-assisted workflow by integrating Claude through the open-source Model Context Protocol (MCP), using an mcp-kali-server package to translate plain-English prompts into tool execution (e.g., Nmap/Gobuster/Metasploit), parse outputs, and return structured findings and prioritized reporting. Both items reflect a broader shift toward agentic and conversational interfaces for offensive tooling, reducing reliance on manual CLI syntax while automating planning, execution, and summarization of assessment steps.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
BlacksmithAI was presented as an open-source AI-powered penetration testing framework using a hierarchical multi-agent architecture for reconnaissance, scanning, vulnerability analysis, exploitation, post-exploitation, and reporting. Its author said the design mirrors real pentesting teams, with agents operating in a shared pre-configured container and supporting multiple LLM backends and interfaces.
A newly announced workflow integrated Anthropic's Claude AI with Kali Linux through the open-source Model Context Protocol and the mcp-kali-server package. The setup lets Claude Desktop translate plain-English prompts into execution of tools such as Nmap, Gobuster, and Metasploit, then summarize findings into a prioritized report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceosintteam.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.