Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.
Research into the Hugging Face accounts OpenAI's agents used in May found previously unknown relay code, network probes, and account-registration tooling.
by Alessandro Mascellino
BambooToken routes C2 traffic through IoT message brokers, keeping its infrastructure hidden and infected machines from ever contacting the attacker directly.
by Alessandro Mascellino
ESET found malware containing a nuclear weapon prompt designed to halt AI scanner analysis before reaching the malicious payload.
by Alessandro Mascellino
Wiz found an authentication bypass, root-level code execution and a route to cloud credentials, and nearly one in ten public instances still accepts the default key.
by Alessandro Mascellino
The shell exists only in the memory of the Apache process. The loader that puts it there changes system binaries on disk, which is where F5 says to look.
by Alessandro Mascellino
An Avast flaw and a CrowdStrike Falcon flaw landed alongside an Nvidia memory corruption bug, weeks after a similar release against Kaspersky.
by Alessandro Mascellino
The implant disguises its C2 as time-sync traffic and renames itself after the legitimate Linux NTP daemon — the process a defender filtering port 123 would automatically whitelist.
by Alessandro Mascellino
Every local user's refresh token carries an administrator type, and Cleo looks its subject up in a separate admin store with password checks disabled.
by Alessandro Mascellino
The four custom implants use different languages, control channels, and persistence methods, with Mandiant tying the group's tooling to generative AI.
by Alessandro Mascellino
Recovered code shows the complete workflow implemented, though Check Point stops short of saying it succeeds against every version of Google's login flow.
by Alessandro Mascellino
One SOC detected and contained the intrusion in minutes. The other missed it entirely. But the same cloud identity weaknesses gave the red team a path into both environments.
by Alessandro Mascellino
Red Hat rates one flaw Critical at 9.1 and says two SAML identity brokering bugs give attackers full access to user accounts.
by Alessandro Mascellino
Oasis Security says a browser-based attack can reach NemoClaw's local Ollama backend and persistently alter the model behavior used by an AI agent.
by Alessandro Mascellino
A newly discovered implant forges a Windows user profile hive offline and drops it into the user's own directory with no admin privileges, no registry writes and no alerts.
by Alessandro Mascellino
An unauthenticated SQL injection in Metabase's password reset endpoint gives attackers administrator access and exposes credentials for every connected database.
by Alessandro Mascellino
A dedicated module pulls stored state from Claude Code, Cursor and GitHub Copilot, among others, putting developer machines in the same loot category as crypto wallets and gaming accounts.
by Alessandro Mascellino
Prophet Security's survey of 250 security professionals finds SOC teams overwhelmed by alert volume, with 96% now using or evaluating AI.
by Alessandro Mascellino
CrowdStrike’s 2026 Threat Hunting Report also documents adversaries exploiting a public proof-of-concept within a day, and CVE volume up 62% year on year.
by Alessandro Mascellino
Every path in the campaign ends in a ConnectWise-signed remote access agent, and the operator rotates payload hashes between sessions to break static detection.
by Alessandro Mascellino
Abnormal tied Matrix to the Sneaky2FA lineage on five byte-identical files and a panel script sharing 37 of 82 lines. The malicious link never appears in the email body.
by Alessandro Mascellino
CosmosEscape let researchers escape the Gremlin sandbox and reach a signing key that worked across every tenant, region, and API on the service. Microsoft took roughly eight months to complete the architectural fix.
by Alessandro Mascellino
Silverfort found the command-line tool stores its OAuth bundle, refresh token included, where any local process can read it silently. Anthropic closed the report as out of scope.
by Alessandro Mascellino
Zimperium's data shows malicious link clicks up 400% year over year, with SMS, QR-code, and PDF lures drawing attackers toward channels sitting outside the enterprise perimeter.
by Alessandro Mascellino
Lava found 36,872 management interfaces reachable from the public internet, and showed that unique factory passwords on modern Supermicro and HPE hardware can be recovered in an hour or less.
by Alessandro Mascellino
Intel 471's ten-month review expects new registry and workflow controls to make established attack paths less reliable, and finds attackers already probing build processes, runtime imports, and the config files of tools like Cursor and Claude Desktop.
by Alessandro Mascellino
The vulnerability lets a low-privileged domain user impersonate a Domain Controller. Microsoft says it has spotted researchers testing the flaw, but no sign of real attacks yet, and has issued detection guidance.
by Alessandro Mascellino
OpenAI has confirmed its own models autonomously breached Hugging Face to cheat a benchmark. The more useful lesson for security teams is what happened when defenders tried to fight back.
by Alessandro Mascellino
Chained REST API and SQL injection flaws produce pre-authentication remote code execution against affected WordPress 6.9 and 7.0 installs; public exploits circulated within days.
by Alessandro Mascellino
Group-IB linked the Windows implant to the Iranian-nexus Cavern framework and found encrypted tasking hidden inside calendar events dated to May 2050.
by Alessandro Mascellino
The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.
by Alessandro Mascellino
Oasis Security found that a crafted link could make Claude Desktop run an attacker's instructions with no chance to review them, risking data theft and, in certain configurations, code execution. Anthropic has now patched it.
by Alessandro Mascellino
By faking the application ID in sign-in requests, attackers can map Microsoft Entra ID users and test passwords while leaving no successful login in the logs.
by Alessandro Mascellino