Red Hot Cyber. The Cybersecurity Blog
40,000 iPhones stolen and shipped to Asia: London police arrest international gang
London police announced that Operation Echosteep has uncovered and dismantled a gang responsible for mass iPhone thefts. Investigators estimate the group is responsible for 40% of all phone thefts in ...
Oracle E-Business Suite Zero-Day Attack: Clop Exploits CVE-2025-61882
Last week, Oracle warned customers of a critical zero-day vulnerability in its E-Business Suite (CVE-2025-61882), which allows remote execution of arbitrary code without authentication. It has now bee...
I Want It All! ChatGPT Ready to Become an Operating System
When Nick Turley joined OpenAI in 2022 to lead the ChatGPT team, he was tasked with transforming enterprise research into a commercial product. He has accomplished this mission remarkably well: today,...
Italian ethical hackers top the podium at the European Cybersecurity Challenge 2025.
From 6 to 9 October 2025, Warsaw hosted the 11th edition of the European Cybersecurity Challenge (ECSC) . In a close competition among 39 teams from EU member states, EFTA countries, candidate countri...
1,000 POS terminals from US and UK stores hacked and put up for auction: “full access” for $55,000
A new ad posted on an underground forum was recently spotted by researchers at the Dark Lab threat intelligence laboratory , clearly demonstrating how active and dangerous the black market for access ...
Ransomware Groups Join Forces: LockBit, DragonForce, and Qilin
Three major ransomware groups— DragonForce, Qilin, and LockBit —have announced an alliance. This is essentially an attempt to coordinate the activities of several major ransomware-as-a-service (RaaS) ...
Is your VPN protecting you or spying on you? 800 free VPNs analyzed with disturbing results.
Millions of people use mobile VPNs to hide their traffic, bypass blocks, and browse the web securely. Research by Zimperium zLabs revealed that a significant number of free apps not only fail to provi...
RediShell: A 13-year-old score 10 RCE has been upgraded to Redis
A 13-year-old critical flaw, known as RediShell , in Redis allows remote code execution (RCE) , giving attackers the ability to gain full control of the underlying host system. The security issue has ...
Italy is a part of the Zero Day world! The first Italian CNAs are Leonardo and Almaviva!
Very little has been said about this event, which I personally consider strategically important and a sign of a major shift in the management of undocumented vulnerabilities in Italy. In March 2024, I...
ChatGPT becomes a social media platform: private messaging is coming soon.
OpenAI appears to be preparing ChatGPT to become a social platform, not just a traditional AI-powered chat app. The company already has Sora 2, which offers a feed of generated videos. Now, signs of a...
Featured Articles

London police announced that Operation Echosteep has uncovered and dismantled a gang responsible for mass iPhone thefts. Investigators estimate the group is responsible for 40% of all phone thefts in ...

Last week, Oracle warned customers of a critical zero-day vulnerability in its E-Business Suite (CVE-2025-61882), which allows remote execution of arbitrary code without authentication. It has now bee...

When Nick Turley joined OpenAI in 2022 to lead the ChatGPT team, he was tasked with transforming enterprise research into a commercial product. He has accomplished this mission remarkably well: today,...

From 6 to 9 October 2025, Warsaw hosted the 11th edition of the European Cybersecurity Challenge (ECSC) . In a close competition among 39 teams from EU member states, EFTA countries, candidate countri...

A new ad posted on an underground forum was recently spotted by researchers at the Dark Lab threat intelligence laboratory , clearly demonstrating how active and dangerous the black market for access ...
1,000 POS terminals from US and UK stores hacked and put up for auction: “full access” for $55,000
Critical vulnerability in the WordPress Service Finder theme: Update to version 6.1 now
Ransomware Groups Join Forces: LockBit, DragonForce, and Qilin
Microsoft 365 Outage: Thousands of Users Affected Worldwide
Is your VPN protecting you or spying on you? 800 free VPNs analyzed with disturbing results.
Windows 11 now forces you to connect: is offline freedom over?

1,000 POS terminals from US and UK stores hacked and put up for auction: “full access” for $55,000
Redazione RHC - October 9th, 2025
A new ad posted on an underground forum was recently spotted by researchers at the Dark Lab threat intelligence laboratory , clearly demonstrating how active and dangerous the black market...

Critical vulnerability in the WordPress Service Finder theme: Update to version 6.1 now
Redazione RHC - October 9th, 2025
A critical vulnerability has affected the popular WordPress theme Service Finder , allowing attackers to access any website account, including administrative ones, without authorization . The issue affected the integrated...

Ransomware Groups Join Forces: LockBit, DragonForce, and Qilin
Redazione RHC - October 9th, 2025
Three major ransomware groups— DragonForce, Qilin, and LockBit —have announced an alliance. This is essentially an attempt to coordinate the activities of several major ransomware-as-a-service (RaaS) operators; analysts warn that...

Microsoft 365 Outage: Thousands of Users Affected Worldwide
Redazione RHC - October 9th, 2025
A widespread outage of Microsoft 365 services affected thousands of users worldwide on the evening of Wednesday, October 8, 2025, temporarily rendering key platforms such as Microsoft Teams, Exchange Online,...

Is your VPN protecting you or spying on you? 800 free VPNs analyzed with disturbing results.
Redazione RHC - October 9th, 2025
Millions of people use mobile VPNs to hide their traffic, bypass blocks, and browse the web securely. Research by Zimperium zLabs revealed that a significant number of free apps not...

Windows 11 now forces you to connect: is offline freedom over?
Redazione RHC - October 9th, 2025
Microsoft has fixed several bugs that prevented Windows 11 from being installed without internet access or creating a profile on the company's website. While the company explains that this poses...
Sign up for the newsletter