A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide.
The flaw, now tracked as CVE-2025-34299, affects multiple versions of the software and has been exploited in the wild.
Monsta FTP is a browser-based file transfer client that allows users to manage files on remote servers without dedicated FTP software.
With at least 5,000 instances exposed on the internet, the platform serves a diverse user base, including financial organizations and large enterprises.
The Vulnerability and Patch Available
The security flaw enables attackers to achieve pre-authenticated remote code execution on vulnerable Monsta FTP servers.
WatchTowr Labs researchers discovered that despite developers adding extensive input validation functions in recent updates, critical vulnerabilities remained unpatched across multiple versions.
The attack works through a simple three-step process: An attacker tricks Monsta FTP into connecting to a malicious SFTP server. Downloads a crafted payload file.
Writes that file to an arbitrary path on the target server. This grants complete control over the vulnerable system.
The construction industry has emerged as a primary target for sophisticated cyber adversaries in 2025, with threat actors including state-sponsored APT groups, ransomware operators, and organized cybercriminal networks actively targeting organizations across the building and construction sector. Nation-state actors from China, Russia, Iran, and North Korea are leveraging the industry’s rapid digital transformation and security […]
Intel is pursuing legal action against a former software engineer who the company claims downloaded thousands of confidential files shortly after being fired in July. The incident highlights growing concerns about data security during workforce reductions and employee departures. The Incident Jinfeng Luo, who worked as a software developer at Intel since 2014, lived in […]
A critical remote code execution vulnerability has been discovered in LangGraph’s checkpoint serialization library, affecting versions before 3.0. The flaw resides in the JsonPlusSerializer component, which is the default serialization protocol used for all checkpointing operations. This vulnerability (CVE-2025-64439) allows attackers to execute arbitrary Python code during the deserialization of malicious payloads. Attribute Details CVE […]
Elastic has released a security advisory addressing a significant vulnerability in Elastic Defend that could allow attackers to escalate their privileges on Windows systems. The vulnerability, tracked as CVE-2025-37735, stems from improper preservation of file permissions in the Defend service and poses a serious risk to organizations relying on this endpoint protection platform. Field Details […]
Three critical vulnerabilities in runc, the widely-used container runtime that powers Docker and Kubernetes, have been disclosed, allowing attackers to break out of container isolation and gain root access to host systems. The flaws, identified as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, were revealed by a SUSE researcher on November 5, 2025. CVE ID Affected Versions Fixed […]
In early November 2025, a massive data breach at Knownsec, a prominent Chinese cybersecurity firm with government ties, sent shockwaves through the international security community. The incident, reported on November 2, resulted in the theft of over 12,000 classified documents exposing sophisticated state-sponsored cyber weapons, internal hacking tools, and a comprehensive global target list spanning […]
Microsoft researchers have unveiled a sophisticated side-channel attack targeting remote language models that could allow adversaries to infer conversation topics from encrypted network traffic. Despite end-to-end encryption via Transport Layer Security (TLS), the attack exploits patterns in packet sizes and timing to classify the subject matter of user prompts sent to AI chatbots. The research […]
Security researchers have discovered an actively exploited remote code execution vulnerability in Monsta FTP, a web-based FTP client used by financial institutions, enterprises, and individual users worldwide. The flaw, now tracked as CVE-2025-34299, affects versions up to 2.11.2 and allows attackers to execute arbitrary code on vulnerable servers without authentication. CVE ID Vulnerability Type Affected […]
HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need for effective vulnerability assessments.
The platform supports multi-model AI, including OpenAI’s GPT-4 and local LLMs like Ollama, enabling pattern recognition, anomaly detection, and zero-day vulnerability discovery.
Developed by Yashab Alam, this cloud-native platform integrates advanced AI and machine learning to automate professional-grade penetration testing.
Its machine learning capabilities correlate threats, score risks using CVSS standards, and prioritize exploits, streamlining what was once a labor-intensive process.
Supports OpenAI GPT-4, local LLMs like Ollama, TensorFlow, and PyTorch for pattern recognition, anomaly detection, behavioral analysis, ML-powered vulnerability discovery, CVSS scoring, impact assessment, exploit prioritization, and AI-generated executive summaries with compliance mapping.
Enterprise Security & Compliance
Authentication, Authorization, Compliance, Audit Logging, Data Protection
Includes RBAC with LDAP/Active Directory integration, role-based permissions for Admin, Lead, Senior, Pentester, and Analyst roles, support for OWASP, NIST, ISO27001, SOC2, and PCI-DSS frameworks, comprehensive activity tracking, and AES-256-GCM encryption with JWT tokens and secure sessions.
Cloud-Native Architecture
Microservices, Service Discovery, Load Balancing, Multi-Cloud, High Availability
Utilizes Docker containers orchestrated by Kubernetes, Consul-based service registry, Nginx reverse proxy with auto-scaling, deployment support for AWS, Azure, and GCP, and features like circuit breakers, health checks, and failover for reliability.
Employs Celery for distributed tasks, Redis with memory caching and TTL management, PostgreSQL with connection pooling and replication, WebSocket for live dashboard updates, and adaptive worker pools to handle workload demands.
Offers exports in HTML, PDF, JSON, XML, and CSV formats; Prometheus + Grafana for monitoring; ELK stack (Elasticsearch + Kibana) for logs; AI-generated business impact assessments; and framework-specific compliance documentation.
At its core, HackGPT follows an enhanced six-phase penetration testing methodology. Phase one automates OSINT reconnaissance with tools like theHarvester and Shodan, aggregating data from multi-cloud environments such as AWS and Azure.
Scanning in phase two employs parallel processing with Nmap and Nuclei for service fingerprinting and vulnerability correlation.
Subsequent phases handle assessment, safe exploitation via Metasploit, reporting, and retesting, all with built-in compliance mapping to OWASP, NIST, and PCI-DSS frameworks.
Enterprise security features include RBAC with LDAP integration, AES-256 encryption, and audit logging to ensure robust data protection.
HackGPT’s microservices architecture, built on Docker and Kubernetes, supports high availability and multi-cloud deployments across AWS, Azure, and GCP.
Performance is optimized with Celery for task distribution, Redis caching, and PostgreSQL databases, allowing real-time dashboards via WebSockets and analytics through Prometheus and Grafana.
Deployment is straightforward: clone the GitHub repo, run the installer, and choose modes like standalone, API server, or full stack with docker-compose.
Interfaces range from CLI for interactive assessments to a web dashboard for monitoring and voice commands for quick operations.
For enterprises, HackGPT reduces manual effort, enhances accuracy in threat detection, and generates dynamic reports in HTML, PDF, or JSON formats. It integrates with SIEM systems and supports custom AI models, making it adaptable for advanced users.
Recent recognitions place it among the top AI cybersecurity tools of 2025, highlighting its role in proactive defense. HackGPT can be cloned from GitHub.
Looking ahead, the roadmap includes version 2.1 in Q3 2025 with threat hunting and SIEM integrations, progressing to fully autonomous assessments in version 3.0 by Q1 2026.