CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Metasploit Framework 6.5 Released

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3580

As cited

Copy frozen at (site build).

vulnerabilities

Metasploit Framework 6.5 Released

Metasploit Framework version 6.5 was released, adding 422 new modules and introducing support for Malleable C2 profiles across all current Meterpreter payloads to customize HTTP(S) traffic behavior. The release also includes the Metasploit MCP Server (msfmcpd), a middleware layer that exposes 16 standardized tools to integrate Metasploit capabilities with AI applications like Claude and Cursor.

Why it matters: Penetration testers and red teamers can now better evade network detection by camouflaging malicious traffic to mimic legitimate browsing patterns, and security teams should prepare for AI-integrated Metasploit workflows that could accelerate exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Metasploit Framework 6.5 Released

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Metasploit Framework 6.5 Released

Metasploit Framework 6.5 has been released with 422 new modules and two major features: Malleable Command and Control (C2) profiles that allow users to shape HTTP traffic across all Meterpreter payloads to evade detection, and the Metasploit MCP Server (msfmcpd), a middleware layer that integrates Metasploit with artificial intelligence (AI) applications via the Model Context Protocol with 16 standardized tools for reconnaissance and session management.

Why it matters: Penetration testers and red team operators can now use traffic obfuscation and AI-driven automation to improve attack simulation fidelity and efficiency; defenders must account for Malleable C2 evasion in network detection rules and monitor for AI-assisted exploitation frameworks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Metasploit Framework 6.5 Released

Metasploit Framework 6.5 has been released with 422 new modules and two major features: Malleable Command and Control (C2) profiles that allow users to shape HTTP traffic across all Meterpreter payloads to evade detection, and the Metasploit MCP Server (msfmcpd), a middleware layer that integrates Metasploit with artificial intelligence (AI) applications via the Model Context Protocol with 16 standardized tools for reconnaissance and session management.

Why it matters: Penetration testers and red team operators can now use traffic obfuscation and AI-driven automation to improve attack simulation fidelity and efficiency; defenders must account for Malleable C2 evasion in network detection rules and monitor for AI-assisted exploitation frameworks.

VendorsMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary