Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.
A shared payload exploited XSS flaws in two plugins to plant hidden administrator accounts and backdoors that persist through updates and deletion.
by Alessandro Mascellino
Encrypted instructions bypass Copilot's prompt-injection defenses; Auto model routing may silently assign a vulnerable model to the session.
by Alessandro Mascellino
Cisco offers no workaround for the critical authentication bypass, while Rapid7 urges emergency patching and review of internet-facing systems for compromise.
by Alessandro Mascellino
Microsoft links NeedyMantis to China-based activity across telecoms, universities, and government contractors, without attributing it to a state actor.
by Alessandro Mascellino
A compromised integration at market intelligence platform Klue has exposed Salesforce CRM data across a growing list of connected companies, with new victims still coming forward.
by Alessandro Mascellino
Researchers detail how attackers evade email defenses by combining benign file types, layered redirection, and brand impersonation.
by Alessandro Mascellino
A behavior-change fix shipped three weeks before the advisory; two machine-to-machine providers remain exposed post-upgrade unless users add an issuer setting.
by Alessandro Mascellino
Implementation-level weakness allows over-the-air attacks to knock 5 GHz Wi-Fi networks offline
by Alessandro Mascellino
Pentera Labs research shows how forgotten “lab” environments are actively exploited to steal cloud credentials and gain persistent access
by Alessandro Mascellino
Darktrace warns that Microsoft developer tools are being repurposed to avoid detection and maintain stealthy remote access.
by Alessandro Mascellino
Global data showed rising attack volumes, AI-driven threats, and widening gaps in business preparedness.
by Alessandro Mascellino
First use of lightweight patching system addresses cross-origin flaw affecting iOS, macOS, and iPadOS
by Alessandro Mascellino
Wiz analysis of 2025 incidents shows how AI adoption and supply chain techniques increased scale and impact
by Alessandro Mascellino
Wiz researchers used AI-augmented reverse engineering to surface an X-Stat header injection that let authenticated users compromise GitHub's backend.
by Alessandro Mascellino
The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.
by Alessandro Mascellino
The AI identified a SCADA management interface and generated a targeted password spray to breach the IT-OT boundary, according to a new Dragos intelligence brief.
by Alessandro Mascellino
The local privilege escalation flaw abuses Windows Defender's handling of cloud-tagged files to grant SYSTEM access on fully patched Windows systems.
by Alessandro Mascellino
An Avast flaw and a CrowdStrike Falcon flaw landed alongside an Nvidia memory corruption bug, weeks after a similar release against Kaspersky.
by Alessandro Mascellino
A multi-stage loader ran SectopRAT in memory from a locally tampered copy; Fortinet found no evidence of a supply-chain compromise.
by Alessandro Mascellino
Commercial LLM APIs replace attacker-run C2 infrastructure; Talos has not confirmed the implant has been deployed in the wild.
by Alessandro Mascellino
F5 BIG-IP APM is vulnerable when configured as an OAuth authorization server; client and resource-server deployments are unaffected.
by Alessandro Mascellino
Threat actors are using ChainScript, a newly discovered remote access trojan that can rotate its infrastructure without rebuilding its implant. Blackpoint researchers have watched the ChainScript remote access trojan switch to a new command server when its connection reset. Nothing changed in the malware already running on the infected machine. The Node.js RAT reached victims...
by Alessandro Mascellino
Research into the Hugging Face accounts OpenAI's agents used in May found previously unknown relay code, network probes, and account-registration tooling.
by Alessandro Mascellino
BambooToken routes C2 traffic through IoT message brokers, keeping its infrastructure hidden and infected machines from ever contacting the attacker directly.
by Alessandro Mascellino
ESET found malware containing a nuclear weapon prompt designed to halt AI scanner analysis before reaching the malicious payload.
by Alessandro Mascellino
Wiz found an authentication bypass, root-level code execution and a route to cloud credentials, and nearly one in ten public instances still accepts the default key.
by Alessandro Mascellino
The shell exists only in the memory of the Apache process. The loader that puts it there changes system binaries on disk, which is where F5 says to look.
by Alessandro Mascellino
The implant disguises its C2 as time-sync traffic and renames itself after the legitimate Linux NTP daemon — the process a defender filtering port 123 would automatically whitelist.
by Alessandro Mascellino
Every local user's refresh token carries an administrator type, and Cleo looks its subject up in a separate admin store with password checks disabled.
by Alessandro Mascellino
The four custom implants use different languages, control channels, and persistence methods, with Mandiant tying the group's tooling to generative AI.
by Alessandro Mascellino
Recovered code shows the complete workflow implemented, though Check Point stops short of saying it succeeds against every version of Google's login flow.
by Alessandro Mascellino
One SOC detected and contained the intrusion in minutes. The other missed it entirely. But the same cloud identity weaknesses gave the red team a path into both environments.
by Alessandro Mascellino