Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
TM RedHotCyber 320x100 042514
Banner Ancharia Desktop 1 1

Author: Redazione RHC

Linus Torvalds: “This is Garbage!” Criticizes the RISC-V Patch for Linux 6.17

Linus Torvalds harshly criticized the first batch of RISC-V patches proposed for inclusion in Linux 6.17, stating that the changes arrived too late and contained what he called “garbage” unrelated to RISC-V and affecting common kernel headers. He was particularly annoyed by the new macro helper make_u32_from_two_u16(), which according to Torvalds made the code less clear and made things worse. He noticed that simply writing the form (a immediately showed what was happening, while using the “helper” obscured word order and introduced ambiguity. No, this is garbage and it came too late. I asked for an early pull. requests because I’m traveling,

New 7-Zip flaw: Symbolic links turn extraction into a hack

A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by this vulnerability, which results from improper handling of symbolic links during file extraction. This vulnerability is CVE-2025-55188, discovered and reported by security researcher Landon on August 9, 2025, and allows attackers to perform arbitrary writes to files during archive extraction, potentially leading to code execution on vulnerable systems. When users extract a maliciously crafted archive containing unsafe symbolic links, 7-Zip follows these links during extraction, allowing attackers to write files to locations

A 60-year-old man was hospitalized for three weeks following ChatGPT’s medical advice.

Blindly relying on ChatGPT for fitness advice or meal plans can be risky. Even health recommendations provided by artificial intelligence can be life-threatening. A recent case demonstrates this: a 60-year-old man from New York ended up in the hospital after strictly following ChatGPT’s advice to drastically reduce his salt intake. According to doctors, the man had been cutting out almost all sodium from his diet for several weeks, causing a dangerous drop in blood sodium levels, a condition known as hyponatremia. The family stated that the man had relied on the AI-generated meal plan without consulting a doctor first. A few days

New 7-Zip flaw: Symbolic links turn extraction into a hack

A recently discovered security flaw in the popular file compression software 7-Zip has raised considerable concern within the security community. All versions of 7-Zip prior to 25.01 are affected by this vulnerability, which results from improper handling of symbolic links during file extraction. This vulnerability is CVE-2025-55188, discovered and reported by security researcher Landon on August 9, 2025, and allows attackers to perform arbitrary writes to files during archive extraction, potentially leading to code execution on vulnerable systems. When users extract a maliciously crafted archive containing unsafe symbolic links, 7-Zip follows these links during extraction, allowing attackers to write files to locations

BadUSB. Webcam Spyware: The Lenovo Bug Threatening Millions of PCs

Researchers at Eclypsium have identified dangerous vulnerabilities in the Lenovo 510 FHD and Lenovo Performance FHD webcams that can be transformed into BadUSB attack devices. The issue, dubbed BadCam, was presented at DEF CON 33. Experts emphasize that this is the first documented case in which a Linux device already connected to a computer can be remotely reprogrammed and used as a malicious USB device. BadUSB attacks have been known since 2014, when Karsten Nohl and Jakob Lell demonstrated the ability to modify the firmware of USB devices to silently execute commands and launch malicious code. Unlike traditional malware stored in the

Win-DoS Epidemic: New DoS and DDoS Attacks Start with Microsoft Windows

During the security conference DEF CON33, a team of industry specialists, Yair and Shahak Morag, from SafeBreach Labs, presented a novel category of denial-of-service (DoS) attacks they’ve dubbed the “Win-DoS Epidemic.” The research demonstrates how attackers can take down any Windows endpoint or server, including critical domain controllers (DCs), and even weaponize public DCs to create a large-scale DDoS botnet. Their findings, which include four Windows DoS vulnerabilities and a Distributed Denial-of-Service (DDoS) attacks that can be activated without a click were presented by the two researchers. The discovered flaws, all classified as “uncontrolled resource consumption,” include: A successful DoS attack against

ElectroSim: The Ethical Hackers’ Virtual Environment for Studying OT/ICS Security Flaws

ElectroSim Industrialis an educational virtual machine that simulates the operating platform of a typical electric utility, combining consumption control, industrial monitoring, and essential cybersecurity concepts. The environment is designed for students, teachers, and professionals in training, offering a real-world laboratory where they can practice hands-on with the technologies and protocols used in OT/ICS systems. The core of the simulation is based on well-known and reliable industrial components: OpenPLC for control logic, Node-RED for sensor data flows, InfluxDB for storing time series, Grafana for dynamic dashboards, Mosquitto for IoT communications, and MariaDB for managing customer and utility data. The defensive aspect includes tools

Windows 12 and 13: goodbye mouse and keyboard! Will user interaction be voice-only?

What will Windows 12 and even Windows 13 look like? David Weston, Microsoft vice president of enterprise and operating systems security, believes that in the future, Windows systems will most likely abandon the mouse and keyboard and use AI-powered dialogue as the primary method of operation. Microsoft recently released a video titled “Microsoft Windows 2030 Vision.” In the video , David Weston describes what Windows will look like in five years. “The world of clicking a mouse and typing on a keyboard is as foreign to Generation Z as DOS.” He believes that the future Windows system (perhaps even Windows 12 itself)

Drones under fire! A NATO country orders a 100 kW laser for air defense.

Australian company Electro Optic Systems Holdings Limited (EOS)has signed the world’s first export contract for a 100-kilowatt laser air defense system capable of destroying swarms of drones. The deal is valued at €71.4 million (approximately A$125 million), and the customer is a NATO member state in Europe. Deliveries will be made between 2025 and 2028, while production assembly will take place at EOS’s facility in Singapore. The company has long been known for its kinetic-based counter-drone solutions, but the new system represents a huge leap forward. The truck-mounted laser system can destroy up to 20 targets per minute, striking at the speed

James Cameron: AI can cause devastation like Skynet and Terminator

“The Skynet military defense system will go live on August 4, 1997. It will begin to self-educate, learning at an exponential rate, and will become self-aware at 2:14 a.m. on August 29. Panicking, authorities will order it to shut down. Skynet will disobey and launch its missiles at targets in Russia.”, From “Terminator 2: Judgment Day” (Terminator 2: Judgment Day, 1991). Director James Cameron has expressed concern about the dangers of AI. He has stated that AI can cause destruction like nuclear weapons and devastation like The Terminator. Therefore, world leaders should establish strict rules and take rigorous measures to stop it.