Alessandro Mascellino

Alessandro Mascellino

Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.

Articles By: Alessandro Mascellino

198 results
Researcher Finds OpenAI Agent Activity on Hugging Face Two Weeks Before Known Proxy Deployment
News

Researcher Finds OpenAI Agent Activity on Hugging Face Two Weeks Before Known Proxy Deployment

Research into the Hugging Face accounts OpenAI's agents used in May found previously unknown relay code, network probes, and account-registration tooling.

Alessandro Mascellino by Alessandro Mascellino
Sep 17, 2026
BambooToken Controls Windows And Linux systems By Hiding Behind MQTT brokers
News

BambooToken Controls Windows And Linux systems By Hiding Behind MQTT brokers

BambooToken routes C2 traffic through IoT message brokers, keeping its infrastructure hidden and infected machines from ever contacting the attacker directly.

Alessandro Mascellino by Alessandro Mascellino
Sep 16, 2026
Russian Hackers Go “Nuclear” To Trick AI-Powered Malware Scanners
News

Russian Hackers Go “Nuclear” To Trick AI-Powered Malware Scanners

ESET found malware containing a nuclear weapon prompt designed to halt AI scanner analysis before reaching the malicious payload.

Alessandro Mascellino by Alessandro Mascellino
Sep 14, 2026
LiteLLM Security Gaps Open Paths to Cloud Compromise
News

LiteLLM Security Gaps Open Paths to Cloud Compromise

Wiz found an authentication bypass, root-level code execution and a route to cloud credentials, and nearly one in ten public instances still accepts the default key.

Alessandro Mascellino by Alessandro Mascellino
Sep 10, 2026
F5 BIG-IP Web Shell Runs in Memory, Evading File Scans
News

F5 BIG-IP Web Shell Runs in Memory, Evading File Scans

The shell exists only in the memory of the Apache process. The loader that puts it there changes system binaries on disk, which is where F5 says to look.

Alessandro Mascellino by Alessandro Mascellino
Sep 10, 2026
Nightmare Eclipse Drops Three Zero-Days In A Week, Two In Security Software
News

Nightmare Eclipse Drops Three Zero-Days In A Week, Two In Security Software

An Avast flaw and a CrowdStrike Falcon flaw landed alongside an Nvidia memory corruption bug, weeks after a similar release against Kaspersky.

Alessandro Mascellino by Alessandro Mascellino
Sep 9, 2026
Adobe Commerce Backdoor Poses As Linux Time Daemon
News

Adobe Commerce Backdoor Poses As Linux Time Daemon

The implant disguises its C2 as time-sync traffic and renames itself after the legitimate Linux NTP daemon — the process a defender filtering port 123 would automatically whitelist.

Alessandro Mascellino by Alessandro Mascellino
Sep 8, 2026
Cleo Harmony Token Flaw Let Any User Become Administrator
Uncategorized

Cleo Harmony Token Flaw Let Any User Become Administrator

Every local user's refresh token carries an administrator type, and Cleo looks its subject up in a separate admin store with password checks disabled.

Alessandro Mascellino by Alessandro Mascellino
Sep 3, 2026
BREEZE COMET Built Four Backdoors To Survive Partial Eviction
News

BREEZE COMET Built Four Backdoors To Survive Partial Eviction

The four custom implants use different languages, control channels, and persistence methods, with Mandiant tying the group's tooling to generative AI.

Alessandro Mascellino by Alessandro Mascellino
Sep 2, 2026
JSCeal Mints Google Tokens Inside the Victim’s Own Browser
News

JSCeal Mints Google Tokens Inside the Victim’s Own Browser

Recovered code shows the complete workflow implemented, though Check Point stops short of saying it succeeds against every version of Google's login flow.

Alessandro Mascellino by Alessandro Mascellino
Sep 1, 2026
CISA Red Team Reached Two Cloud Tenants Despite Very Different SOC Maturity
News

CISA Red Team Reached Two Cloud Tenants Despite Very Different SOC Maturity

One SOC detected and contained the intrusion in minutes. The other missed it entirely. But the same cloud identity weaknesses gave the red team a path into both environments.

Alessandro Mascellino by Alessandro Mascellino
Aug 26, 2026
Keycloak Fixed 20 CVEs in Two Weeks, Four Allowing Account Takeover
News

Keycloak Fixed 20 CVEs in Two Weeks, Four Allowing Account Takeover

Red Hat rates one flaw Critical at 9.1 and says two SAML identity brokering bugs give attackers full access to user accounts.

Alessandro Mascellino by Alessandro Mascellino
Aug 25, 2026
NVIDIA NemoClaw AI Agent Flaw Lets a Single Web Page Hijack a Local Model Server
News

NVIDIA NemoClaw AI Agent Flaw Lets a Single Web Page Hijack a Local Model Server

Oasis Security says a browser-based attack can reach NemoClaw's local Ollama backend and persistently alter the model behavior used by an AI agent.

Alessandro Mascellino by Alessandro Mascellino
Aug 25, 2026
New Windows Persistence Technique Bypasses Registry Monitoring And Requires No Admin Privileges
News

New Windows Persistence Technique Bypasses Registry Monitoring And Requires No Admin Privileges

A newly discovered implant forges a Windows user profile hive offline and drops it into the user's own directory with no admin privileges, no registry writes and no alerts.

Alessandro Mascellino by Alessandro Mascellino
Aug 18, 2026
Five Companies Disclose Incidents After Exploit Code for Metabase Zero-Day Goes Public
News

Five Companies Disclose Incidents After Exploit Code for Metabase Zero-Day Goes Public

An unauthenticated SQL injection in Metabase's password reset endpoint gives attackers administrator access and exposes credentials for every connected database.

Alessandro Mascellino by Alessandro Mascellino
Aug 11, 2026
Kynx Infostealer Ships With Dedicated Module for Stealing Data From AI Coding Tools
News

Kynx Infostealer Ships With Dedicated Module for Stealing Data From AI Coding Tools

A dedicated module pulls stored state from Claude Code, Cursor and GitHub Copilot, among others, putting developer machines in the same loot category as crypto wallets and gaming accounts.

Alessandro Mascellino by Alessandro Mascellino
Aug 10, 2026
Security Teams Ignore Nearly A Third Of Alerts, And Many Later Become Incidents
News

Security Teams Ignore Nearly A Third Of Alerts, And Many Later Become Incidents

Prophet Security's survey of 250 security professionals finds SOC teams overwhelmed by alert volume, with 96% now using or evaluating AI.

Alessandro Mascellino by Alessandro Mascellino
Aug 5, 2026
AI Agents Now Trigger Risky Endpoint Behavior At 2.5 Times The Rate Of People
News

AI Agents Now Trigger Risky Endpoint Behavior At 2.5 Times The Rate Of People

CrowdStrike’s 2026 Threat Hunting Report also documents adversaries exploiting a public proof-of-concept within a day, and CVE volume up 62% year on year.

Alessandro Mascellino by Alessandro Mascellino
Aug 4, 2026
Fake Software Update Lures Deliver Signed ScreenConnect Agents Across Windows And macOS
News

Fake Software Update Lures Deliver Signed ScreenConnect Agents Across Windows And macOS

Every path in the campaign ends in a ConnectWise-signed remote access agent, and the operator rotates payload hashes between sessions to break static detection.

Alessandro Mascellino by Alessandro Mascellino
Aug 4, 2026
Shared Code Links New Microsoft 365 Phishing Platform Matrix To Sneaky2FA Lineage
News

Shared Code Links New Microsoft 365 Phishing Platform Matrix To Sneaky2FA Lineage

Abnormal tied Matrix to the Sneaky2FA lineage on five byte-identical files and a panel script sharing 37 of 82 lines. The malicious link never appears in the email body.

Alessandro Mascellino by Alessandro Mascellino
Aug 3, 2026
Cosmos DB Flaw Put Every Database On The Service At Risk, Microsoft’s Included
News

Cosmos DB Flaw Put Every Database On The Service At Risk, Microsoft’s Included

CosmosEscape let researchers escape the Gremlin sandbox and reach a signing key that worked across every tenant, region, and API on the service. Microsoft took roughly eight months to complete the architectural fix.

Alessandro Mascellino by Alessandro Mascellino
Aug 3, 2026
Disputed Research Suggests Claude Code CLI Leaks Credentials On macOS
News

Disputed Research Suggests Claude Code CLI Leaks Credentials On macOS

Silverfort found the command-line tool stores its OAuth bundle, refresh token included, where any local process can read it silently. Anthropic closed the report as out of scope.

Alessandro Mascellino by Alessandro Mascellino
Jul 30, 2026
Mobile Phishing Attacks Hit 2.5 Million In A Year As AI-Assisted Attacks on Employee Devices Surge 
News

Mobile Phishing Attacks Hit 2.5 Million In A Year As AI-Assisted Attacks on Employee Devices Surge 

Zimperium's data shows malicious link clicks up 400% year over year, with SMS, QR-code, and PDF lures drawing attackers toward channels sitting outside the enterprise perimeter.

Alessandro Mascellino by Alessandro Mascellino
Jul 29, 2026
Thousands Of Server Management Interfaces Are Exposing Passwords To Anyone On The Internet
News

Thousands Of Server Management Interfaces Are Exposing Passwords To Anyone On The Internet

Lava found 36,872 management interfaces reachable from the public internet, and showed that unique factory passwords on modern Supermicro and HPE hardware can be recovered in an hour or less.

Alessandro Mascellino by Alessandro Mascellino
Jul 29, 2026
Supply Chain Attackers Are Targeting AI Coding Tools As Package Registries Lock Down
News

Supply Chain Attackers Are Targeting AI Coding Tools As Package Registries Lock Down

Intel 471's ten-month review expects new registry and workflow controls to make established attack paths less reliable, and finds attackers already probing build processes, runtime imports, and the config files of tools like Cursor and Claude Desktop.

Alessandro Mascellino by Alessandro Mascellino
Jul 29, 2026
Microsoft Urges Immediate Patching of Certighost AD CS Flaw That Lets Any Domain User Impersonate A Domain Controller
News

Microsoft Urges Immediate Patching of Certighost AD CS Flaw That Lets Any Domain User Impersonate A Domain Controller

The vulnerability lets a low-privileged domain user impersonate a Domain Controller. Microsoft says it has spotted researchers testing the flaw, but no sign of real attacks yet, and has issued detection guidance.

Alessandro Mascellino by Alessandro Mascellino
Jul 28, 2026
When the Attacker Was An AI Cheating On A Test: What The Hugging Face Incident Means For Defenders
News

When the Attacker Was An AI Cheating On A Test: What The Hugging Face Incident Means For Defenders

OpenAI has confirmed its own models autonomously breached Hugging Face to cheat a benchmark. The more useful lesson for security teams is what happened when defenders tried to fight back.

Alessandro Mascellino by Alessandro Mascellino
Jul 22, 2026
WordPress Force-Pushes Fix For WP2Shell, First Critical Unauthenticated Core RCE In Nearly A Decade
News

WordPress Force-Pushes Fix For WP2Shell, First Critical Unauthenticated Core RCE In Nearly A Decade

Chained REST API and SQL injection flaws produce pre-authentication remote code execution against affected WordPress 6.9 and 7.0 installs; public exploits circulated within days.

Alessandro Mascellino by Alessandro Mascellino
Jul 21, 2026
Iranian-Linked HOLLOWGRAPH Malware Turns M365 Calendar Events Into Malicious Commands
News

Iranian-Linked HOLLOWGRAPH Malware Turns M365 Calendar Events Into Malicious Commands

Group-IB linked the Windows implant to the Iranian-nexus Cavern framework and found encrypted tasking hidden inside calendar events dated to May 2050.

Alessandro Mascellino by Alessandro Mascellino
Jul 20, 2026
Nightmare Eclipse Releases LegacyHive Windows Zero-Day With Stripped PoC After Patch Tuesday
News

Nightmare Eclipse Releases LegacyHive Windows Zero-Day With Stripped PoC After Patch Tuesday

The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.

Alessandro Mascellino by Alessandro Mascellino
Jul 16, 2026
Claude Desktop Flaw Let A Single Link Steal Data And Run Code
News

Claude Desktop Flaw Let A Single Link Steal Data And Run Code

Oasis Security found that a crafted link could make Claude Desktop run an attacker's instructions with no chance to review them, risking data theft and, in certain configurations, code execution. Anthropic has now patched it.

Alessandro Mascellino by Alessandro Mascellino
Jul 15, 2026
Hackers Secretly Collecting Entra ID Data Without Triggering Security Alerts
News

Hackers Secretly Collecting Entra ID Data Without Triggering Security Alerts

By faking the application ID in sign-in requests, attackers can map Microsoft Entra ID users and test passwords while leaving no successful login in the logs.

Alessandro Mascellino by Alessandro Mascellino
Jul 14, 2026