Red Hot Cyber. The Cybersecurity Blog
RHC interviews ShinyHunters: “Systems can be repaired, but people remain vulnerable!”
ShinyHunters is a group of threat actors that gained notoriety after the massive data breach against Salesforce, an incident that led Google to closely monitor them and assign them the code name UNC62...
The Great Firewall in the Spotlight: The Leak Revealing the Industrialization of Chinese Censorship
Edited by Luca Stivali and Olivia Terragni. On September 11, 2025, what can be defined as the largest leak ever suffered by the Great Firewall of China (GFW) exploded in the media, massively and massi...
OpenAI and Microsoft reach agreement to transform into a public utility company.
OpenAI has entered into a memorandum of understanding with Microsoft to review its partnership, which could lead to the company’s transformation into a Public Benefit Corporation (PBC). If the transfo...
Goodbye PowerShell 2.0 and WMIC! The great Windows 11 cleanup has begun.
Windows 11 users who have installed the September 2025 Update might think that practically nothing changes. At first glance, KB5065426 looks like a normal small patch that Microsoft distributes to eve...
Looking for Volodymyr Tymoshchuk! 11 million dollars for the Nefilim hacker
The U.S. Department of Justice has indicted Ukrainian Volodymyr Tymoshchuk on seven counts of computer hacking and extortion. He is considered one of the most dangerous hackers of recent years. The in...
In Nepal, people are dying for social media! 19 people lost their lives trying to get Facebook back
In a dramatic reversal, Nepal has lifted the nationwide social media blackout imposed last week after it sparked massive youth protests and caused at least 19 deaths, according to local media. The dec...
Xi Jinping and the Chinese APT’s Ambition
The post-COVID macro political movements, including ongoing conflicts, have prompted a majority of states to shift their medium- to long-term political objectives. Clearly, a paradigm shift has been v...
Salesloft Cyber Attack: Chatbot Drift Temporarily Disabled
Salesloft announced that it would temporarily deactivate its AI-powered chatbot Drift on September 5, after several companies were hit by a massive supply chain attack. The incident resulted in the ma...
Discover the Dark Web: Access, Secrets, and Helpful Links to the Onion Network
The Dark Web is a part of the internet that cannot be reached with standard browsers (Chrome, Firefox, Edge). To access it, you need to use specific tools like the Tor Browser, which guarantees anonym...
AI A2 detected 102 0-day bugs and created exploits in Android apps for $1.77
Artificial intelligence systems have been criticized for creating confusing vulnerability reports and inundating open-source developers with irrelevant complaints. But researchers at Nanjing Universit...
Featured Articles

ShinyHunters is a group of threat actors that gained notoriety after the massive data breach against Salesforce, an incident that led Google to closely monitor them and assign them the code name UNC62...

Edited by Luca Stivali and Olivia Terragni. On September 11, 2025, what can be defined as the largest leak ever suffered by the Great Firewall of China (GFW) exploded in the media, massively and massi...

OpenAI has entered into a memorandum of understanding with Microsoft to review its partnership, which could lead to the company’s transformation into a Public Benefit Corporation (PBC). If the trans...

Windows 11 users who have installed the September 2025 Update might think that practically nothing changes. At first glance, KB5065426 looks like a normal small patch that Microsoft distributes to eve...

The U.S. Department of Justice has indicted Ukrainian Volodymyr Tymoshchuk on seven counts of computer hacking and extortion. He is considered one of the most dangerous hackers of recent years. The in...
Submarine cables are vulnerable! New strategies are needed.
Popular password managers, including LastPass, 1Password, and Bitwarden, are vulnerable to clickjacking.
Vibe Coding: Revolution or Security Risk?
Critical vulnerabilities in NetScaler ADC and Gateway. Update now! Attacks are ongoing!
The Democratization of Cybercrime Has Arrived! “I Can’t Code, But I Write Ransomware”
FreePBX under attack: Zero-day exploit already in use, emergency patch released

Submarine cables are vulnerable! New strategies are needed.
Redazione RHC - August 28th, 2025
Researchers from Reichman University (Israel) have detailed in an article in the journal Nature Electronics the growing risks and threats posed by natural and man-made factors to undersea communications cables,...

Popular password managers, including LastPass, 1Password, and Bitwarden, are vulnerable to clickjacking.
Redazione RHC - August 28th, 2025
A security expert has discovered that six of the most popular password managers, used by tens of millions of people, are vulnerable to clickjacking, a phenomenon that allows attackers to...

Vibe Coding: Revolution or Security Risk?
Redazione RHC - August 28th, 2025
Martyn Ditchburn, CTO in residence Zscaler Artificial intelligence, like any technology, is not inherently good or bad: it all depends on who uses it and for what purpose. What is...

Critical vulnerabilities in NetScaler ADC and Gateway. Update now! Attacks are ongoing!
Redazione RHC - August 28th, 2025
NetScaler has alerted administrators of three new vulnerabilities in NetScaler ADC and NetScaler Gateway, one of which is already being used in active attacks. Updates are available and the vendor...

The Democratization of Cybercrime Has Arrived! “I Can’t Code, But I Write Ransomware”
Redazione RHC - August 28th, 2025
Cybercriminals are rapidly mastering generative AI, and we're no longer talking about "scary" ransom notes, but about full-fledged malware development. The Anthropic research team reported that attackers are increasingly relying...

FreePBX under attack: Zero-day exploit already in use, emergency patch released
Luca Galuppi - August 28th, 2025
The world of VoIP telephony has once again ended up in the crosshairs of cybercriminals. This time it's FreePBX, the open-source platform built on Asterisk and widely used by companies,...
Sign up for the newsletter