Red Hot Cyber. The Cybersecurity Blog
The Robot Girlfriend is coming! The new frontier of Chinese-made technology.
While the rise of robots in China, the world’s largest market and producer of robots, is attracting the attention of the global information technology (IT) industry, the emergence of a “...
29,000 Exchange servers at risk. The exploit for CVE-2025-53786 is under exploitation.
29,000 Exchange servers are vulnerable to CVE-2025-53786, which allows attackers to move within Microsoft cloud environments, potentially leading to complete domain compromise. CVE-2025-53786 allows a...
No Tariffs for 90 Days! China and the US Reach a Temporary Economic Agreement
The Government of the People’s Republic of China (“China”) and the Government of the United States of America (“USA”), according to a report by Beijing-based Xinhua ...
New 7-Zip flaw: Symbolic links turn extraction into a hack
A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by t...
James Cameron: AI can cause devastation like Skynet and Terminator
“The Skynet military defense system will go live on August 4, 1997. It will begin to self-educate, learning at an exponential rate, and will become self-aware at 2:14 a.m. on August 29. Panicki...
HTTP/1.1 Must Die! Critical vulnerabilities put millions of websites at risk.
A critical security flaw in HTTP/1.1 has been disclosed by security experts, highlighting a threat that has continued to impact web infrastructure for more than six years, potentially impacting millio...
A new Privilege Escalation (PE) technique allows UAC bypass on Windows
A recent discovery has uncovered a sophisticated technique that bypasses Windows User Account Control (UAC), allowing privilege escalation without user intervention through the use of the private font...
Discovering the Deep Web and Dark Web: The Ultimate Guide
There has been a lot of talk for some years now about the deep web and the dark web, and many have wondered: but what exactly does this mean? The dark web is often associated with shady and criminal a...
New Critical Vulnerability Discovered in Microsoft Exchange Server: CISA Warns
A critical security flaw has been discovered in hybrid deployments of Microsoft Exchange Server. This vulnerability (CWE-287) allows attackers with local administrative access to escalate their privil...
Critical Bugs on NVIDIA Triton Allow Attackers to Compromise and Steal AI Model
Critical vulnerabilities have been discovered in NVIDIA’s Triton Inference Server, threatening the security of AI infrastructure on Windows and Linux. The open-source solution is designed for l...
Featured Articles

While the rise of robots in China, the world’s largest market and producer of robots, is attracting the attention of the global information technology (IT) industry, the emergence of a “...

29,000 Exchange servers are vulnerable to CVE-2025-53786, which allows attackers to move within Microsoft cloud environments, potentially leading to complete domain compromise. CVE-2025-53786 allows a...

The Government of the People’s Republic of China (“China”) and the Government of the United States of America (“USA”), according to a report by Beijing-based Xinhua ...

A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by t...

“The Skynet military defense system will go live on August 4, 1997. It will begin to self-educate, learning at an exponential rate, and will become self-aware at 2:14 a.m. on August 29. Panicki...

FIDO Downgrade Attacks, a New Authentication Threat
Proofpoint researchers have identified a sophisticated downgrade attack that could bypass FIDO-based authentication, exposing targets to adversary-in-the-middle (AiTM) threats.These are some of the key findings the researchers found: Despite the lack of observed use by threat actors, Proofpoint considers FIDO

Mozilla Fixes Dangerous RCE Bug in Firefox 142
Mozilla has fixed several high-severity security bugs with the release of Firefox 142, preventing attackers from remotely executing code of their choosing on affected systems. The security advisory, published on August 19, 2025, reveals nine distinct vulnerabilities ranging from sandbox

Spyware under fire! Apple releases a critical patch for a 0day used on iOS and iPadOS
Apple has released an urgent security patch for iOS and iPadOS to address a critical zero-day vulnerability. This vulnerability, identified as CVE-2025-43300, has been confirmed to be actively exploited in highly targeted attacks. The urgent patches, released as iOS 18.6.2

LastPass, 1Password, and Keeper under fire! Widespread zero-day bugs detected, putting millions of users at risk.
A cybersecurity expert has identified zero-day vulnerabilities affecting eleven popular password managers, potentially putting tens of millions of users at risk of credential theft with a single malicious click. An innovative attack strategy, known as “DOM-based Extension Clickjacking,” marks a

Zero-Day RCE Exploit for Windows Selling for $125,000: How to Protect Yourself
Browsing the dark web can reveal disturbing and alarming ads for those involved in cybersecurity. Recently, we noticed a post offering a zero-day exploit, an extremely dangerous type of tool, for sale. The ad, from a user with the handle

Nike Under Fire! IT Infrastructure Access for Sale from an Initial Access Broker
An Initial Access Broker is selling access to Nike USA servers on a popular underground forum. A recent post on a dark web forum has raised new concerns about the security of large international companies. An Initial Access Broker (IAB),

FIDO Downgrade Attacks, a New Authentication Threat
Redazione RHC - August 21st, 2025
Proofpoint researchers have identified a sophisticated downgrade attack that could bypass FIDO-based authentication, exposing targets to adversary-in-the-middle (AiTM) threats.These are some of the key findings the researchers found: Using a...

Mozilla Fixes Dangerous RCE Bug in Firefox 142
Redazione RHC - August 21st, 2025
Mozilla has fixed several high-severity security bugs with the release of Firefox 142, preventing attackers from remotely executing code of their choosing on affected systems. The security advisory, published on...

Spyware under fire! Apple releases a critical patch for a 0day used on iOS and iPadOS
Redazione RHC - August 21st, 2025
Apple has released an urgent security patch for iOS and iPadOS to address a critical zero-day vulnerability. This vulnerability, identified as CVE-2025-43300, has been confirmed to be actively exploited in...

LastPass, 1Password, and Keeper under fire! Widespread zero-day bugs detected, putting millions of users at risk.
Redazione RHC - August 21st, 2025
A cybersecurity expert has identified zero-day vulnerabilities affecting eleven popular password managers, potentially putting tens of millions of users at risk of credential theft with a single malicious click. An...
Sign up for the newsletter