Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Banner Ancharia Mobile 1
Fortinet 970x120px

Author: Redazione RHC

Will you soon be fired? AI surpasses humans in the Coding Olympics.

Google DeepMind and OpenAI’s artificial intelligence have achieved gold-level results in a competition dubbed the “Programming Olympics.” The companies’ models demonstrated a level of proficiency comparable to top competitors in the finals of the International Collegiate Programming Contest (ICPC), held in early September. According to OpenAI, its latest model, GPT-5, solved all 12 problems, 11 of them on the first try. The company claims this result would have secured the system first place. DeepMind, meanwhile, reported that its reasoning model Gemini 2.5 Deep Think achieved the second-best result, solving a task that no human could have solved. AI Victory at the ICPC

Two Scattered Spider activists found guilty of TfL cyber attack

Two young men involved in the Scattered Spider group have been charged as part of the National Crime Agency investigation into a cyber attack on Transport for London (TfL). On August 31, 2024, TfL was the subject of a network intrusion that investigators believe was carried out by members of the criminal collective. Thalha Jubair, 19, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were arrested on Tuesday (September 16) at their home addresses by the NCA and City of London Police. Both appeared today (September 18) at Westminster Magistrates Court, after the Crown Prosecution Service authorised their charges

NVIDIA’s demise in China! Tech companies ordered to stop purchasing GPUs.

Chinese authorities have ordered the country’s largest tech companies, including Libaba, ByteDance, and Tencent, to stop purchasing Nvidia GPUs. The order, issued by the state cybersecurity regulator and the Cyberspace Administration of China, also applies to the RTX Pro 6000D models, designed specifically for the Chinese market. Companies were ordered not only to suspend testing of new solutions but also to cancel existing orders. Recall that in 2024, Nvidia generated approximately $17.1 billion in revenue from China, equivalent to 13% of the company’s total revenue, which amounted to approximately $130 billion. This move is part of Beijing’s broader policy aimed at reducing

Frontier supercomputer surpasses Fugaku to become world’s fastest

The supercomputer “Fugaku,” developed by Fujitsu in collaboration with the RIKEN Institute of Physical and Chemical Research, dominated the rankings of the world’s fastest machines for years thanks to its ARM architecture. Its supremacy, however, was broken by a new player: “Frontier.” “Frontier” has claimed the title of fastest supercomputer, returning the x86 architecture to the top after Fugaku’s long dominance. This achievement represents a significant shift in the landscape of high-performance computing systems. The machine uses AMD’s third-generation EPYC server processors, codenamed “Milan, coupled with the Instinct MI250X accelerated graphics card, designed with an OCP accelerator module. The combination of these

Ready for AI-powered Notepad? Coming soon to Windows 11 with PC Copilot+!

Windows 11 users with PC Copilot+ will be able to take advantage of advanced artificial intelligence features, now an integral part of the Notepad application, thanks to an update that includes powerful tools for creating and editing text. New features include “Summarize,” “Write,” and “Rewrite,” which can be used directly on the device without a subscription. Innovative AI-powered tools built into Notepad enable users to efficiently create, optimize, and summarize text. Running directly on the Neural Processing Unit (NPU) of Copilot+ PCs, these tools run locally, allowing offline use without a Microsoft 365 subscription or Microsoft account access. A key element of

ShadowLeak Arrives: A 0-Click Bug in ChatGPT Leads to Sensitive Data Exfiltration

A new threat is beginning to emerge in the IT world: the world of artificial intelligence agents. ShadowLeak is a recently discovered clickless indirect prompt injection (IPI) vulnerability that occurs when OpenAI’s ChatGPT is connected to corporate Gmail and allowed to browse the web. How ShadowLeak Works The attack, discovered by Radware, exploits the vulnerability by sending a legitimate-looking email that silently embeds malicious instructions in invisible or non-obvious HTML code. When an employee asks the assistant to “recap today’s emails” or “search my inbox for a topic,” the agent captures the booby-trapped message and, without further user interaction, exfiltrates sensitive data

Generative Artificial Intelligence: Explosive Growth and Security Challenges

By Umberto Pirovano, Senior Manager Technical Solutions at Palo Alto Networks Generative Artificial Intelligence (GenAI) is redefining the technology and business landscape at an astonishing rate. According to Palo Alto Networks’ report “The State of Generative AI in 2025,” GenAI traffic is expected to surge more than 890% in 2024. This explosive growth is attributable to the maturation of AI models, increasing business automation, and increased deployment, driven by increasingly evident productivity returns. The increase in adoption and use marks a definitive shift: GenAI is no longer a novelty, but an essential utility. According to Research by the Artificial Intelligence Observatory of

GitLab fixes critical vulnerability CVE-2025-6454

The collaborative development platform GitLab has announced the fix for a critical vulnerability, identified as CVE-2025-6454. The issue affected server installations of the Community and Enterprise editions and allowed requests to be made to internal resources via specially crafted webhook headers. The attack required an account with minimum developer privileges and no intervention from other users was necessary. The bug received a high CVSS score of 8.5 out of 10. It affected versions 16.11 through 18.1.6, 18.2 through 18.2.6, and 18.3 through 18.3.2. The fixes were included in version 18.3.2, released on September 10. GitLab emphasized that the issue was discovered through

Supply Chain Wormable? NPM Packages with Self-Propagating Malware Arrive

Security researchers have discovered the compromise of over 180 npm packages, infected with a self-propagating malware designed to infect other packages. The campaign, dubbed Shai-Hulud, likely began with the hack of the @ctrl/tinycolor package, which is downloaded over 2 million times a week. The name Shai-Hulud comes from the shai-hulud.yaml files used by the malware. It is a reference to the giant sandworms from Frank Herbert’s Dune. The issue was first brought to the attention of developer Daniel Pereira developer Daniel Pereira, who alerted the community to a large-scale supply chain attack. “Right now, as you read this, malware is being distributed

The KING of RaidForums remains in limbo. The battle between the US and Portugal over his extradition continues.

The High Court in London has overturned the decision to extradite Portuguese citizen Diogo Santos Coelho to the United States. The young man, known by the pseudonym Omnipotent, was the administrator of one of the largest hacker forums, RaidForums. The story begins in January 2022, when Coelho travels to the United Kingdom to visit his mother. There, he is arrested. Since then, he has been in limbo for more than three years: two countries are fighting over his extradition. The United States is seeking Coelho’s extradition for crimes related to his management of RaidForums. Portugal has sent its own order, citing the