Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
LECS 320x100 1
Enterprise BusinessLog 970x120 1

Author: Redazione RHC

QNAP fixes 7 critical NAS bugs discovered at Pwn2Own Ireland 2025

QNAP has fixed seven critical zero-day vulnerabilities in its Network Attached Storage (NAS) operating systems after a group of researchers successfully exploited them at Pwn2Own Ireland 2025 , held in Cork from October 20 to 22. In a controlled environment, the demonstrated exploits expose kernel-level vulnerabilities and web interface flaws that could allow unauthenticated attackers to compromise the device and exfiltrate data stored there. To find the flaws, Summoning Team, DEVCORE, Team DDOS, and a CyCraft intern chained these zero-days together to bypass authentication and gain complete system control over QNAP NAS devices. These flaws, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849, allow remote

Artificial intelligence surpasses humans, but not in every field. Is AGI near or far away?

According to experts, humanity has entered a new stage in the development of artificial intelligence: an era in which systems no longer simply assist humans , but are able to autonomously perform complex tasks that previously required human intervention. Speakers at a recent meeting on the topic included some of the industry’s most respected names: Nvidia CEO Jensen Huang , Meta AI chief Yann LeCun , and Turing and Nobel laureates Yoshua Bengio , Geoffrey Hinton , Fei-Fei Li , and Bill Dalley . The 2025 Queen Elizabeth Prize for Engineering is awarded to seven engineers who have made fundamental contributions to

Google Gemini 3.0: New features and updates for the year’s most anticipated AI assistant

Over the past week, Google announced that the Gemini Assistant can now natively integrate YouTube and Google Maps services without the need to use specific commands like “@YouTube” or “@Google Maps.” This change marks a step toward a more seamless and ” natural ” interaction with AI within the Google ecosystem , reducing friction between users and different services. For the average user, this means they can ask “play a video about…” or “take me to…” without having to worry about the correct prefix. At the same time, new rumors are emerging regarding the next evolution of the Gemini model, labeled as

WhatsApp used to spread LANDFALL, the new spyware for Android Samsung

Researchers at Palo Alto Networks Unit 42 have discovered a new, previously unknown family of Android spyware called LANDFALL . To spread it, malicious actors exploited a zero-day vulnerability (CVE-2025-21042) in the Android image processing library built into Samsung devices. This flaw is not an isolated case, but rather part of a recurring pattern of similar vulnerabilities found in various mobile platforms. CVE-2025-21042 was actively exploited in real-world (in-the-wild) attacks before its fix, released by Samsung in April 2025 , following initial reports of compromise. However, neither the exploit nor the associated commercial spyware had previously been analyzed or publicly documented .

Trump and Kim Jong Un summit? There seems to be a high probability of a meeting.

South Korean intelligence agencies , including the National Intelligence Service, reportedly believe there is a high probability that US President Donald Trump will hold a summit with North Korean Workers’ Party General Secretary Kim Jong Un. On November 4, South Korea’s National Intelligence Service briefed members of the National Assembly on the situation in North Korea and other matters. According to members of Congress, the National Intelligence Service said there was a “high probability” of a summit between Trump and Kim Jong Un , explaining that “Kim Jong Un is willing to engage with the United States. If conditions are favorable, he

New York sues Facebook, Instagram, TikTok, and YouTube over youth mental health crises

The City of New York filed a lawsuit on Wednesday against a group of prominent social media platforms, including TikTok, YouTube, Instagram, and Facebook, accusing them of contributing to a mental health crisis among young people. “Young people are now addicted en masse to the defendants’ platforms, significantly interfering with the operations of school districts and placing a heavy burden on cities, school districts, and public hospital systems that provide mental health services to young people ,” the 327-page lawsuit states. The health care and hospital systems, public schools, and the city itself claim that, in an effort to maximize youth participation,

Sam Altman: “I hope that bad things don’t happen because of technology.”

The latest statements by Sam Altman, CEO of OpenAI, regarding the progress of artificial intelligence (AI) are not very encouraging, as he recently stated that he is concerned about “the impact of AI on jobs” and also made it clear that we will not be safe even in a bunker “if AI gets out of control” . But that’s not all, because in a recent interview, OpenAI’s CEO bluntly stated that we should be concerned about the future that artificial intelligence will bring: “I think something bad will happen with artificial intelligence.” As reported by an Investopedia article, a month ago Sam

Microsoft’s new goal for artificial intelligence? Medicine!

The tech giant has announced the creation of a new development team for a “superhuman” artificial intelligence that will outperform human experts in medical diagnoses. The team will be led by Mustafa Suleiman , the company’s head of artificial intelligence. Microsoft has announced the creation of a new team called the MAI Superintelligence Team , which aims to develop “superhuman” artificial intelligence specialized in medical diagnostics, Reuters reports. The project is led by Mustafa Suleiman, former co-founder of DeepMind and Inflection AI. According to Suleiman, the new team doesn’t aim to develop general intelligence (AGI) capable of performing any human task, but

Artificial intelligence and security? What a tragedy!

A simple idea to simplify home network management and improve security unexpectedly turned into a series of near-catastrophic errors, all due to the advice of popular artificial intelligence assistants. Instead of saving time and reducing risks, a Cybernews journalist, relying on chatbots, stumbled upon tips that could expose his local services to the entire Internet. The attempt to centralize access to the control panel and other home infrastructure services stemmed from a perfectly reasonable desire: to replace IP addresses with user-friendly domain names and unsecured HTTP connections with secure TLS. The architecture itself was typical: pfSense as a firewall, TrueNAS storage, and

Rust 1.91: Full Windows support on ARM is here!

Rust has received a major update : version 1.91 officially brings Windows support on 64-bit ARM systems to the same level as Linux and macOS. Builds for the aarch64-pc-windows-msvc architecture are now in the highest compatibility class, ensuring all tests pass and binaries are available. For users of ARM computers running Windows, this makes Rust a complete industrial development tool, without the need for manual compilation. Additionally, the aarch64-pc-windows-gnullvm and x86_64-pc-windows-gnullvm builds have achieved Tier 2 status, bringing them closer to full support. The team plans to add missing components, including installation packages and LLVM tools, in the future. In addition to