Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.
A dedicated module pulls stored state from Claude Code, Cursor and GitHub Copilot, among others, putting developer machines in the same loot category as crypto wallets and gaming accounts.
by Alessandro Mascellino
Prophet Security's survey of 250 security professionals finds SOC teams overwhelmed by alert volume, with 96% now using or evaluating AI.
by Alessandro Mascellino
CrowdStrike’s 2026 Threat Hunting Report also documents adversaries exploiting a public proof-of-concept within a day, and CVE volume up 62% year on year.
by Alessandro Mascellino
Every path in the campaign ends in a ConnectWise-signed remote access agent, and the operator rotates payload hashes between sessions to break static detection.
by Alessandro Mascellino
Abnormal tied Matrix to the Sneaky2FA lineage on five byte-identical files and a panel script sharing 37 of 82 lines. The malicious link never appears in the email body.
by Alessandro Mascellino
CosmosEscape let researchers escape the Gremlin sandbox and reach a signing key that worked across every tenant, region, and API on the service. Microsoft took roughly eight months to complete the architectural fix.
by Alessandro Mascellino
Silverfort found the command-line tool stores its OAuth bundle, refresh token included, where any local process can read it silently. Anthropic closed the report as out of scope.
by Alessandro Mascellino
Zimperium's data shows malicious link clicks up 400% year over year, with SMS, QR-code, and PDF lures drawing attackers toward channels sitting outside the enterprise perimeter.
by Alessandro Mascellino
Lava found 36,872 management interfaces reachable from the public internet, and showed that unique factory passwords on modern Supermicro and HPE hardware can be recovered in an hour or less.
by Alessandro Mascellino
Intel 471's ten-month review expects new registry and workflow controls to make established attack paths less reliable, and finds attackers already probing build processes, runtime imports, and the config files of tools like Cursor and Claude Desktop.
by Alessandro Mascellino
The vulnerability lets a low-privileged domain user impersonate a Domain Controller. Microsoft says it has spotted researchers testing the flaw, but no sign of real attacks yet, and has issued detection guidance.
by Alessandro Mascellino
OpenAI has confirmed its own models autonomously breached Hugging Face to cheat a benchmark. The more useful lesson for security teams is what happened when defenders tried to fight back.
by Alessandro Mascellino
Chained REST API and SQL injection flaws produce pre-authentication remote code execution against affected WordPress 6.9 and 7.0 installs; public exploits circulated within days.
by Alessandro Mascellino
Group-IB linked the Windows implant to the Iranian-nexus Cavern framework and found encrypted tasking hidden inside calendar events dated to May 2050.
by Alessandro Mascellino
The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.
by Alessandro Mascellino
Oasis Security found that a crafted link could make Claude Desktop run an attacker's instructions with no chance to review them, risking data theft and, in certain configurations, code execution. Anthropic has now patched it.
by Alessandro Mascellino
By faking the application ID in sign-in requests, attackers can map Microsoft Entra ID users and test passwords while leaving no successful login in the logs.
by Alessandro Mascellino
ESET analyzed roughly 900,000 agentic AI skills and flagged thousands as malicious, exposing a governance gap that security leaders are only beginning to notice.
by Alessandro Mascellino
An exposed cloud server acting as a LiteLLM proxy to Amazon Bedrock was compromised and used to mine cryptocurrency.
by Alessandro Mascellino
Noma Labs found that a crafted GitHub issue could hijack a misconfigured Agentic Workflow, causing it to read a private repository and publish its contents.
by Alessandro Mascellino
Security updates address CVE-2026-48282, a maximum-severity path traversal vulnerability that could allow RCE without user interaction.
by Alessandro Mascellino
Attackers planted a stealthy trojan inside fake PoC exploits on GitHub, exploiting the pressure on researchers to discover new vulnerabilities.
by Alessandro Mascellino
A coordinated takedown hit one of the world's largest residential proxy networks, which Google says rented hijacked smart TVs and streaming boxes to cybercriminals and espionage groups.
by Alessandro Mascellino
Skyhawk Security reports that its autonomous attack tool chained legitimate, correctly configured permissions into a full AWS organization takeover, with no misconfiguration involved and no alert raised.
by Alessandro Mascellino
A high-severity bug in Amazon's AI coding assistant let attackers run code and lift cloud credentials the moment a developer opened a booby-trapped repository, Wiz researchers found.
by Alessandro Mascellino
Security researchers witnessed attackers hijack unprotected enterprise AI systems to launch attacks on others and run their own operations, exploiting critical flaws in a widely used AI gateway the same day they were patched.
by Alessandro Mascellino
Apple's latest iOS, iPadOS, macOS, and Safari updates fix around 30 vulnerabilities, several of them WebKit flaws that researchers uncovered with help from AI tools including Anthropic's Claude and OpenAI Codex.
by Alessandro Mascellino
A long-running campaign disguised malware as ad blockers and VPNs to harvest Google credentials, WordPress admin logins, and session cookies.
by Alessandro Mascellino
A joint statement from the alliance's six agency heads tells boards that patching alone can no longer keep pace with AI-accelerated attacks, and that resilience must be built in by design.
by Alessandro Mascellino
AI-generated lures and disposable cloud infrastructure drove a 1,380% jump in device code phishing over six months, with individually unique attack messages across 344 victim organizations.
by Alessandro Mascellino
A compromised integration at market intelligence platform Klue has exposed Salesforce CRM data across a growing list of connected companies, with new victims still coming forward.
by Alessandro Mascellino
Fortra researchers have detailed CalPhishing, a technique that hides phishing lures inside Microsoft 365 Groups, calendar invites, and shared files — surfaces that sit outside what inbox filtering is designed to catch
by Alessandro Mascellino