Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Fortinet 320x100px
970x120

Author: Redazione RHC

OpenAI Puts Parents in Control: Parental Controls Arrive on ChatGPT

At a time when controversy over the impact of artificial intelligence on youth mental health is growing, the introduction of parental controls for ChatGPT has been announced as a measure by OpenAI. In a blog post published Tuesday, the California-based AI company said it launched these features in response to families’ need to support “the establishment of healthy guidelines that fit a teenager’s unique developmental stage.” With these changes, parents will be able to link their ChatGPT accounts to their children’s, disable certain features, including memory and chat history, and control how the chatbot responds to queries through “appropriate model behavior rules.”

Lovable, the Swedish AI unicorn that’s revolutionizing programming

This year’s TechBBQ conference was packed to capacity at Copenhagen’s Bella Center when Anton Osika, co-founder of the AI-powered programming app Lovable, took the stage. The fundamental concept of Lovable is extremely simple: it’s about enabling anyone, especially those with no programming knowledge, to develop apps and websites. This is made possible by introducing the concept of “vibe coding,” or intuition-based programming, which uses trial and error aided by artificial intelligence. Solutions like Cursor, Gemini, Claude, and of course Lovable are paving the way for this new approach. At the end of June, Lovable released an agent to help users read files,

Trend Micro: Beware of the “Task Scam,” the scam targeting online job seekers.

The latest research from the security leader reveals the fraudulent mechanisms behind fake job opportunities offered by digital platforms The number of victims of the “Task scam” is increasing worldwide, a rapidly growing scam that Trend Micro, a global cybersecurity leader, analyzes in its latest research, “Unmasking Task Scams to Prevent Financial Fallout From Fraud.” The “Task scam” is a sophisticated scam that targets users looking for work online. This type of fraud, after an initial seemingly serious job offer, lures the victim into repetitive digital activities that deprive them of large sums of money. “Task scams are one of the most

The Battle Between OnlyFans and Google: Piracy, AI, and the Chaos of Automated Copyright

The massive clash between adult content creators and pirates, now transferred to automated copyright protection systems, is beginning to radically change the face of the Internet. Every day, it becomes increasingly difficult to navigate online, and the reason is not only censorship, but also the imprecise functioning of algorithms. This phenomenon is particularly evident on platforms like OnlyFans, where independent creators are trying en masse to protect their material from leaks and unauthorized distribution. Pornography piracy has been present on the web since its inception, but with the explosion of subscription revenue, more and more creators have begun to rely on specialized

Nearly a third of web traffic is generated by bots! The era of invasive AI is now

Yesterday, the Red Hot Cyber website was inaccessible for about an hour. But what’s going on, we wondered? After a series of analyses, here’s the result: the internet is changing rapidly under the pressure of artificial intelligence. If previously, websites suffered from classic search robots, today a growing share of traffic is generated by new, aggressive scanners that operate in the interest of large language models. According to Cloudflare, nearly a third of all global web traffic comes from bots, with AI crawlers being the fastest-growing. Fastly’s analysis specifies that 80% of this traffic is generated by programs designed to mass-collect data

Lazarus APT: 3 Advanced RATs for Cryptocurrency Financial Organizations

Recently, an advanced subgroup linked to the notorious threat actor Lazarus was detected distributing three different remote access Trojans (RATs) within compromised financial and cryptocurrency organizations. Initial access was achieved primarily through social engineering campaigns conducted on Telegram, where attackers pretended to be legitimate employees of major commercial companies. Fake dating websites, including fake portals like Calendly and Picktime, lure victims, who are reached via a Chrome zero-day exploit that allows silent code execution on their computers. Once inside the network, attackers deploy PondRAT as a first step, then use the more difficult-to-detect ThemeForestRAT, which runs only in memory. The use of

Zscaler Suffers Data Breach: Supply Chain Attack Via Salesloft Drift

A large-scale cyberattack has targeted security firm Zscaler, which has officially confirmed it was the victim of a supply chain breach. This attack exposed customer contact data due to compromised Salesforce credentials linked to the Salesloft Drift marketing platform. The incident, made public on August 31, 2025, was the result of a larger campaign targeting Salesloft Drift OAuth tokens, involving over 700 organizations globally. The breach is due to a broader supply chain attack on Salesloft Drift, in which threat actors stole OAuth and refresh tokens. These tokens granted unauthorized access to Salesforce customer instances, allowing the exfiltration of sensitive information. In

From AI chatbots to global data theft: The Drift flaw rocks Google Workspace.

Last week, it emerged that criminal hackers had compromised the sales automation platform Salesloft and stolen OAuth and update tokens from customers in its AI agent Drift, designed to integrate with Salesforce. As Google has now warned, the attack was widespread and affected Google Workspace data. SalesDrift is a third-party platform for integrating the Drift AI chatbot with a Salesforce instance, allowing organizations to sync conversations, leads, and support tickets with their CRM. Drift can also integrate with a variety of services to streamline the process, including Salesforce (unrelated to Salesloft) and other platforms (Slack, Google Workspace, and others). According to Salesloft,

QNAP releases security patches for critical vulnerabilities in VioStor NVR systems.

QNAP Systems has released security updates to address several vulnerabilities in the QVR firmware of its VioStor Network Video Recorder (NVR) systems. On August 29, 2025, two serious security vulnerabilities were disclosed, prompting the company to promptly update their systems to prevent potential security breaches. QNAP responded quickly to these security reports by releasing updated firmware that addresses both vulnerabilities. Legacy VioStor NVR systems running QVR 5.1.x are affected, but users can now update to QVR 5.1.6 build 20250621 or later to eliminate these security risks. The security advisory discloses two separate vulnerabilities that could compromise the integrity of legacy VioStor NVR

Computer engineer found dead on Microsoft campus in Mountain View

An Indian-born software engineer employed by Microsoft Corp. has been found dead on the company’s campus in Mountain View, California. The 35-year-old, identified as Pratik Pandey and originally from Indore, India, entered the office on the evening of August 19 and was found dead in the early hours of August 20, police confirmed. Officers responded to the scene around 2 a.m. and reported they found no signs of suspicious activity or behavior. Authorities have clarified that the case is not being treated as a criminal investigation, according to a Bloomberg report. Relatives urged tech companies to take stronger measures to protect employees