Red Hot Cyber. The Cybersecurity Blog
29,000 Exchange servers at risk. The exploit for CVE-2025-53786 is under exploitation.
29,000 Exchange servers are vulnerable to CVE-2025-53786, which allows attackers to move within Microsoft cloud environments, potentially leading to complete domain compromise. CVE-2025-53786 allows a...
No Tariffs for 90 Days! China and the US Reach a Temporary Economic Agreement
The Government of the People’s Republic of China (“China”) and the Government of the United States of America (“USA”), according to a report by Beijing-based Xinhua ...
New 7-Zip flaw: Symbolic links turn extraction into a hack
A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by t...
James Cameron: AI can cause devastation like Skynet and Terminator
“The Skynet military defense system will go live on August 4, 1997. It will begin to self-educate, learning at an exponential rate, and will become self-aware at 2:14 a.m. on August 29. Panicki...
HTTP/1.1 Must Die! Critical vulnerabilities put millions of websites at risk.
A critical security flaw in HTTP/1.1 has been disclosed by security experts, highlighting a threat that has continued to impact web infrastructure for more than six years, potentially impacting millio...
A new Privilege Escalation (PE) technique allows UAC bypass on Windows
A recent discovery has uncovered a sophisticated technique that bypasses Windows User Account Control (UAC), allowing privilege escalation without user intervention through the use of the private font...
Discovering the Deep Web and Dark Web: The Ultimate Guide
There has been a lot of talk for some years now about the deep web and the dark web, and many have wondered: but what exactly does this mean? The dark web is often associated with shady and criminal a...
New Critical Vulnerability Discovered in Microsoft Exchange Server: CISA Warns
A critical security flaw has been discovered in hybrid deployments of Microsoft Exchange Server. This vulnerability (CWE-287) allows attackers with local administrative access to escalate their privil...
Critical Bugs on NVIDIA Triton Allow Attackers to Compromise and Steal AI Model
Critical vulnerabilities have been discovered in NVIDIA’s Triton Inference Server, threatening the security of AI infrastructure on Windows and Linux. The open-source solution is designed for l...
Malware disguises itself as an innocent photo on Dropbox. APT37’s steganographic strategy
Specialists at the Genians Security Center have discovered an improved version of the RoKRAT malware, associated with the North Korean APT37 group. The new version is distinguished by an unusual way o...
Featured Articles

29,000 Exchange servers are vulnerable to CVE-2025-53786, which allows attackers to move within Microsoft cloud environments, potentially leading to complete domain compromise. CVE-2025-53786 allows a...

The Government of the People’s Republic of China (“China”) and the Government of the United States of America (“USA”), according to a report by Beijing-based Xinhua ...

A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by t...

“The Skynet military defense system will go live on August 4, 1997. It will begin to self-educate, learning at an exponential rate, and will become self-aware at 2:14 a.m. on August 29. Panicki...

A critical security flaw in HTTP/1.1 has been disclosed by security experts, highlighting a threat that has continued to impact web infrastructure for more than six years, potentially impacting millio...

Heading for a bang for August! 36 RCEs for Microsoft Patch Tuesday August
August Patch Tuesday: Microsoft releases security updates that fix 107 vulnerabilities across its ecosystem products. The update includes fixes for 90 vulnerabilities, classified as follows: 13 are critical, 76 are important, one is moderate, and one is low. Notably, none

Critical RCE vulnerability in Microsoft Teams: Urgent update needed
As part of the August 2025 Patch Tuesday security updates, a critical Remote Code Execution (RCE) vulnerability in Microsoft’s Teams collaboration software has been patched. The critical flaw, tracked as CVE-2025-53783, could allow an unauthorized attacker to read, write, and

29,000 Exchange servers at risk. The exploit for CVE-2025-53786 is under exploitation.
29,000 Exchange servers are vulnerable to CVE-2025-53786, which allows attackers to move within Microsoft cloud environments, potentially leading to complete domain compromise. CVE-2025-53786 allows attackers who have already gained administrative access to on-premises Exchange servers to escalate privileges in an

Vulnerability in a car dealership’s online login system: Researcher finds security flaws
A vulnerability was discovered in the online dealership login system of one of the world’s largest automakers—all it took was a little digging into the page’s code. Security researcher Eaton Zwer of Harness reported that he managed to exploit the

Vulnerability in car dealership online login system: Researcher finds security flaws
A vulnerability has been discovered in the online login system for dealerships at one of the world’s largest car manufacturers: all it took was a little digging into the page’s code. Security researcher Eaton Zwer of Harness reported that he

As expected, the WinRAR bug has become a devastating weapon for cyber criminals
As expected, the infamous WinRAR bug is now being actively exploited by attackers on a large scale, given the software’s widespread use and popularity. ESET experts have reported that the recently patched WinRAR vulnerability (CVE-2025-8088) was used as a zero-day

Critical Vulnerability in Fortinet: Update FortiOS, FortiProxy, and FortiPAM Now
Redazione RHC - August 13th, 2025
Several Fortinet security products, including FortiOS, FortiProxy, and FortiPAM, are affected by a high-severity authentication evasion vulnerability. The flaw, tracked as CVE-2024-26009, has a CVSS score of 7.9 and allows...

Critical Update for Google Chrome: Patches for Various Vulnerabilities
Redazione RHC - August 13th, 2025
A critical security update has been released for Google Chrome, which addresses six security vulnerabilities that could be exploited to execute arbitrary code on affected systems. An emergency security update...

Heading for a bang for August! 36 RCEs for Microsoft Patch Tuesday August
Redazione RHC - August 13th, 2025
August Patch Tuesday: Microsoft releases security updates that fix 107 vulnerabilities across its ecosystem products. The update includes fixes for 90 vulnerabilities, classified as follows: 13 are critical, 76 are...

Critical RCE vulnerability in Microsoft Teams: Urgent update needed
Redazione RHC - August 13th, 2025
As part of the August 2025 Patch Tuesday security updates, a critical Remote Code Execution (RCE) vulnerability in Microsoft's Teams collaboration software has been patched. The critical flaw, tracked as...
Sign up for the newsletter