Red Hot Cyber. The Cybersecurity Blog
They told you 6G would be fast, right? But they didn’t tell you the whole truth
It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G with ...
Microsoft Exchange Server Penetration Testing: Techniques, Tools, and Countermeasures
Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...
Notepad++ under attack! How a fake DLL opens the door to criminal hackers
A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...
A dangerous zero-day zero-click exploit threatens billions of Android devices
Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...
Does Microsoft use macOS to create Windows wallpapers? Probably!
On October 29, Microsoft released a wallpaper to commemorate the eleventh anniversary of the Windows Insider program, and it is speculated that it was created using macOS. Let us remember that Windows...
Louvre Theft: Windows 2000 and Windows XP on Networks, as Well as Simple Passwords
As we know, the thieves in the “theft of the century” entered through a second-floor window of the Louvre Museum, but the museum had other problems besides unprotected windows. Although Cu...
SesameOp: The Malware That Uses OpenAI Assistants for Command and Control
Microsoft has discovered a new malware, dubbed SesameOp , and published details of how it works . This backdoor was unusual: its creators used the OpenAI Assistants API as a covert control channel , a...
Eight 0-days worth $35 million sold to Russia by US insiders
Former US defense contractor CEO Peter Williams has pleaded guilty to selling ” eight sensitive, protected cyber exploits” to Russian zero-day broker Operation Zero. Court documents and a ...
Trump refuses to export Nvidia chips. China responds: “Don’t worry, we’ll do it ourselves.”
Reuters reported that Trump told reporters during a pre-recorded interview on CBS’s “60 Minutes” and on Air Force One during the return flight: “We’re not going to let an...
Goodbye, malware! In 2025, criminal hackers will use legitimate accounts to remain invisible.
A FortiGuard report for the first half of 2025 shows that financially motivated attackers are increasingly eschewing sophisticated exploits and malware. Instead , they are using valid accounts and leg...
Featured Articles

It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G w...

Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...

A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...

Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...

On October 29, Microsoft released a wallpaper to commemorate the eleventh anniversary of the Windows Insider program, and it is speculated that it was created using macOS. Let us remember that Windows...
100 Infostealer packages uploaded to NPM using AI hallucinations
Atroposia: The MaaS platform that provides a Trojan with a vulnerability scanner
0day as weapons: sold 8 US defense 0day exploits to Moscow
Critical vulnerability in Blink: a website can block all Chromium-based browsers
Trump-Xi Summit: A Truce That Doesn’t Benefit Europe
Cloud yes or Cloud no: When the Digital Sky Darkens

100 Infostealer packages uploaded to NPM using AI hallucinations
Redazione RHC - October 30th, 2025
Since August 2024, the PhantomRaven campaign has uploaded 126 malicious packages to npm, which have been downloaded a total of over 86,000 times . The campaign was discovered by Koi...

Atroposia: The MaaS platform that provides a Trojan with a vulnerability scanner
Redazione RHC - October 30th, 2025
Varonis researchers have discovered the Atroposia MaaS (malware-as-a-service) platform. For $200 a month, its customers receive a remote access Trojan with extensive functionality, including remote desktop, file system management, information...

0day as weapons: sold 8 US defense 0day exploits to Moscow
Redazione RHC - October 30th, 2025
Peter Williams, a former employee of the defense contractor, pleaded guilty in US federal court to two counts of theft of trade secrets, admitting to selling eight zero-day vulnerabilities to...

Critical vulnerability in Blink: a website can block all Chromium-based browsers
Redazione RHC - October 30th, 2025
Researcher José Pino has presented a proof-of-concept vulnerability in the Blink rendering engine used in Chromium -based browsers, demonstrating how a single web page can crash many popular browsers and...

Trump-Xi Summit: A Truce That Doesn’t Benefit Europe
Redazione RHC - October 30th, 2025
After years of tensions, tariffs, mutual accusations, and trade wars that have shattered the global balance of power, the long-awaited meeting between Donald Trump and Xi Jinping has finally taken...

Cloud yes or Cloud no: When the Digital Sky Darkens
Redazione RHC - October 30th, 2025
The outage of Microsoft's cloud services, which occurred just hours before the release of its quarterly results, is just the latest in a long series of outages that are exposing...
Discover the latest critical CVEs issued and stay updated on the most recent vulnerabilities. Or search for a specific CVE

