Red Hot Cyber. The Cybersecurity Blog
12.5 million HD movies per second! Amazon’s undersea cable will connect the US to Ireland.
In a few years, Ireland and the United States will be connected by an undersea communications cable designed to help Amazon improve its AWS services. Undersea cables are a vital part of the infrastruc...
They told you 6G would be fast, right? But they didn’t tell you the whole truth
It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G with ...
Microsoft Exchange Server Penetration Testing: Techniques, Tools, and Countermeasures
Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...
Notepad++ under attack! How a fake DLL opens the door to criminal hackers
A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...
A dangerous zero-day zero-click exploit threatens billions of Android devices
Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...
Does Microsoft use macOS to create Windows wallpapers? Probably!
On October 29, Microsoft released a wallpaper to commemorate the eleventh anniversary of the Windows Insider program, and it is speculated that it was created using macOS. Let us remember that Windows...
Louvre Theft: Windows 2000 and Windows XP on Networks, as Well as Simple Passwords
As we know, the thieves in the “theft of the century” entered through a second-floor window of the Louvre Museum, but the museum had other problems besides unprotected windows. Although Cu...
SesameOp: The Malware That Uses OpenAI Assistants for Command and Control
Microsoft has discovered a new malware, dubbed SesameOp , and published details of how it works . This backdoor was unusual: its creators used the OpenAI Assistants API as a covert control channel , a...
Eight 0-days worth $35 million sold to Russia by US insiders
Former US defense contractor CEO Peter Williams has pleaded guilty to selling ” eight sensitive, protected cyber exploits” to Russian zero-day broker Operation Zero. Court documents and a ...
Trump refuses to export Nvidia chips. China responds: “Don’t worry, we’ll do it ourselves.”
Reuters reported that Trump told reporters during a pre-recorded interview on CBS’s “60 Minutes” and on Air Force One during the return flight: “We’re not going to let an...
Featured Articles

In a few years, Ireland and the United States will be connected by an undersea communications cable designed to help Amazon improve its AWS services. Undersea cables are a vital part of the infrastruc...

It’s not “ just faster ”: 6G changes the very nature of the network! When we talk about 6G, we risk reducing everything to a speed upgrade, as if the network of the future were simply a 5G w...

Often, during penetration testing, we find ourselves with elevated access (Domain Admin) within an organization. Some companies stop there, thinking that obtaining Domain Admin is the ultimate goal. B...

A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijack...

Google has issued an urgent advisory regarding a critical vulnerability in Android that allows attackers to execute arbitrary code on the device without any user interaction. The Zero Click vulnerabil...
Taiwan launches international initiative for submarine cable safety
Port scanning in 2025: Nmap and AI — how to integrate them securely and operationally
The Louvre Theft: When Thieves Taught the World the Physical Pen Test
Starting November 12th, age verification for porn sites will be implemented in Italy. What’s changing?
AzureHound: The “Legitimate” Tool for Cloud Attacks
Red Hot Cyber launches free real-time CVE Enrichment service

Taiwan launches international initiative for submarine cable safety
Redazione RHC - November 1st, 2025
On October 28, 2025, during the Taiwan-EU Submarine Cable Safety Cooperation Forum held in Taipei, Taiwanese Foreign Minister Lin Chia-lung introduced the "International Initiative for Submarine Cable Risk Management" ,...

Port scanning in 2025: Nmap and AI — how to integrate them securely and operationally
Luca Stivali - November 1st, 2025
In 2025, port scanning remains a key activity for both Red Teams (reconnaissance, discovery, fingerprinting) and Blue Teams (monitoring and proactive defense). But the latest development is the arrival of...

The Louvre Theft: When Thieves Taught the World the Physical Pen Test
Luca Errico - November 1st, 2025
The event that shook the world on October 19, 2025, was not a natural disaster or a financial collapse, but the sensational theft of Napoleon's jewels from the Louvre Museum....

Starting November 12th, age verification for porn sites will be implemented in Italy. What’s changing?
Redazione RHC - October 31st, 2025
Starting Tuesday, November 12, 2025, new provisions from the Italian Communications Regulatory Authority (AGCOM) will come into force, requiring an age verification system for accessing pornographic websites. The measure, provided...

AzureHound: The “Legitimate” Tool for Cloud Attacks
Luca Galuppi - October 31st, 2025
AzureHound, part of the BloodHound suite, was born as an open-source tool to help security teams and red teams identify vulnerabilities and escalation paths in Microsoft Azure and Entra ID...

Red Hot Cyber launches free real-time CVE Enrichment service
Redazione RHC - October 31st, 2025
Timeliness is key in cybersecurity. Red Hot Cyber recently launched a completely free service that allows IT professionals, security analysts, and enthusiasts to monitor the most critical vulnerabilities published in...
Discover the latest critical CVEs issued and stay updated on the most recent vulnerabilities. Or search for a specific CVE

