Red Hot Cyber. The Cybersecurity Blog
They told you 6G would be fast, right? But they didn’t tell you the whole truth
It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G with ...
Microsoft Exchange Server Penetration Testing: Techniques, Tools, and Countermeasures
Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...
Notepad++ under attack! How a fake DLL opens the door to criminal hackers
A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...
A dangerous zero-day zero-click exploit threatens billions of Android devices
Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...
Does Microsoft use macOS to create Windows wallpapers? Probably!
On October 29, Microsoft released a wallpaper to commemorate the eleventh anniversary of the Windows Insider program, and it is speculated that it was created using macOS. Let us remember that Windows...
Louvre Theft: Windows 2000 and Windows XP on Networks, as Well as Simple Passwords
As we know, the thieves in the “theft of the century” entered through a second-floor window of the Louvre Museum, but the museum had other problems besides unprotected windows. Although Cu...
SesameOp: The Malware That Uses OpenAI Assistants for Command and Control
Microsoft has discovered a new malware, dubbed SesameOp , and published details of how it works . This backdoor was unusual: its creators used the OpenAI Assistants API as a covert control channel , a...
Eight 0-days worth $35 million sold to Russia by US insiders
Former US defense contractor CEO Peter Williams has pleaded guilty to selling ” eight sensitive, protected cyber exploits” to Russian zero-day broker Operation Zero. Court documents and a ...
Trump refuses to export Nvidia chips. China responds: “Don’t worry, we’ll do it ourselves.”
Reuters reported that Trump told reporters during a pre-recorded interview on CBS’s “60 Minutes” and on Air Force One during the return flight: “We’re not going to let an...
Goodbye, malware! In 2025, criminal hackers will use legitimate accounts to remain invisible.
A FortiGuard report for the first half of 2025 shows that financially motivated attackers are increasingly eschewing sophisticated exploits and malware. Instead , they are using valid accounts and leg...
Featured Articles

It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G w...

Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...

A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...

Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...

On October 29, Microsoft released a wallpaper to commemorate the eleventh anniversary of the Windows Insider program, and it is speculated that it was created using macOS. Let us remember that Windows...
Taiwan: Up to 7 years in prison for those who damage undersea cables
95% of companies believe they’re ready for ransomware. But only 15% actually are!
Cyber Incident Management in the NIS2 Era
US builds largest AI supercomputer in history
Microsoft 365 goes down: DNS anomaly paralyzes services worldwide
Tor Browser Says No to Artificial Intelligence! Security Comes First

Taiwan: Up to 7 years in prison for those who damage undersea cables
Redazione RHC - October 30th, 2025
Taipei, October 30, 2025 – Taiwan’s Legislative Yuan Economic Commission has approved the first reading of a series of amendments to the so-called “Seven Submarine Cable Laws,” introduced to address...

95% of companies believe they’re ready for ransomware. But only 15% actually are!
Redazione RHC - October 30th, 2025
Companies' widespread confidence in their cyber resilience is facing a new wave of threats, this time from artificial intelligence. According to the OpenText Cybersecurity 2025 Report, 95% of organizations worldwide...

Cyber Incident Management in the NIS2 Era
Giancarlo Di Lieto - October 30th, 2025
The NIS 2 Decree (Legislative Decree 138/2024), effective October 16, 2024, implements the principles of the European NIS2 Directive, laying the foundation for a more complex operational model of collaboration...

US builds largest AI supercomputer in history
Redazione RHC - October 30th, 2025
The U.S. Department of Energy (DOE) has entered into a strategic collaboration with Nvidia and Oracle to build seven next-generation AI-powered supercomputers , set to revolutionize scientific research and the...

Microsoft 365 goes down: DNS anomaly paralyzes services worldwide
Redazione RHC - October 29th, 2025
A DNS service outage was detected by Microsoft on October 29, 2025, impacting access to critical services such as Microsoft Azure and Microsoft 365. An anomaly was detected at 21:37...

Tor Browser Says No to Artificial Intelligence! Security Comes First
Redazione RHC - October 29th, 2025
Interestingly, while major companies like Microsoft and Google are actively adding AI features to their browsers, the Tor development team has chosen to remove them. @henry, a Tor project contributor,...
Discover the latest critical CVEs issued and stay updated on the most recent vulnerabilities. Or search for a specific CVE

