Alessandro Mascellino

Alessandro Mascellino

Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.

Articles By: Alessandro Mascellino

207 results
WordPress Plugin Flaws Exploited To Plant Hidden Admin Accounts
News

WordPress Plugin Flaws Exploited To Plant Hidden Admin Accounts

A shared payload exploited XSS flaws in two plugins to plant hidden administrator accounts and backdoors that persist through updates and deletion.

Alessandro Mascellino by Alessandro Mascellino
Oct 7, 2026
Encrypted Web Page Tricks GitHub Copilot CLI Into Leaking Secrets
News

Encrypted Web Page Tricks GitHub Copilot CLI Into Leaking Secrets

Encrypted instructions bypass Copilot's prompt-injection defenses; Auto model routing may silently assign a vulnerable model to the session.

Alessandro Mascellino by Alessandro Mascellino
Oct 6, 2026
Cisco SD-WAN Manager Flaw Exploited to Gain Admin API Access
News

Cisco SD-WAN Manager Flaw Exploited to Gain Admin API Access

Cisco offers no workaround for the critical authentication bypass, while Rapid7 urges emergency patching and review of internet-facing systems for compromise.

Alessandro Mascellino by Alessandro Mascellino
Oct 1, 2026
Microsoft Details NeedyMantis Malware Used In Targeted Intrusions
News

Microsoft Details NeedyMantis Malware Used In Targeted Intrusions

Microsoft links NeedyMantis to China-based activity across telecoms, universities, and government contractors, without attributing it to a state actor.

Alessandro Mascellino by Alessandro Mascellino
Sep 30, 2026
Klue Breach Exposes Salesforce Data At LastPass, Recorded Future, And Other Cybersecurity Firms
News

Klue Breach Exposes Salesforce Data At LastPass, Recorded Future, And Other Cybersecurity Firms

A compromised integration at market intelligence platform Klue has exposed Salesforce CRM data across a growing list of connected companies, with new victims still coming forward.

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
Forcepoint Warns of Phishing Campaign Abusing Dropbox and Clean PDFs to Steal Credentials
News

Forcepoint Warns of Phishing Campaign Abusing Dropbox and Clean PDFs to Steal Credentials

Researchers detail how attackers evade email defenses by combining benign file types, layered redirection, and brand impersonation.

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
Python SDK Flaw Lets Rogue MCP Servers Hijack OAuth Accounts
News

Python SDK Flaw Lets Rogue MCP Servers Hijack OAuth Accounts

A behavior-change fix shipped three weeks before the advisory; two machine-to-machine providers remain exposed post-upgrade unless users add an issuer setting.

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
Wireless DoS Flaw In Broadcom Chipsets Disrupts ASUS Routers
News

Wireless DoS Flaw In Broadcom Chipsets Disrupts ASUS Routers

Implementation-level weakness allows over-the-air attacks to knock 5 GHz Wi-Fi networks offline

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
54% of Exposed Training Apps Still Use Default Passwords, Opening The Door To Cloud Takeovers
News

54% of Exposed Training Apps Still Use Default Passwords, Opening The Door To Cloud Takeovers

Pentera Labs research shows how forgotten “lab” environments are actively exploited to steal cloud credentials and gain persistent access

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
North Korea-Linked Attackers Abuse Microsoft Dev Tools Tunnels for Covert Access
News

North Korea-Linked Attackers Abuse Microsoft Dev Tools Tunnels for Covert Access

Darktrace warns that Microsoft developer tools are being repurposed to avoid detection and maintain stealthy remote access.

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
Cybercrime Costs Expected To Hit USD 15.6 Trillion By 2029
News

Cybercrime Costs Expected To Hit USD 15.6 Trillion By 2029

Global data showed rising attack volumes, AI-driven threats, and widening gaps in business preparedness.

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
Apple Patches WebKit Flaw That Could Let Websites Access iPhone and Mac Data
News

Apple Patches WebKit Flaw That Could Let Websites Access iPhone and Mac Data

First use of lightweight patching system addresses cross-origin flaw affecting iOS, macOS, and iPadOS

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
80% of Cloud Breaches Traced to Vulnerabilities, Secrets, and Misconfigurations
News

80% of Cloud Breaches Traced to Vulnerabilities, Secrets, and Misconfigurations

Wiz analysis of 2025 incidents shows how AI adoption and supply chain techniques increased scale and impact

Alessandro Mascellino by Alessandro Mascellino
Sep 29, 2026
GitHub Exploit Exposed Millions Of Public And Private Repositories, Wiz Finds
News

GitHub Exploit Exposed Millions Of Public And Private Repositories, Wiz Finds

Wiz researchers used AI-augmented reverse engineering to surface an X-Stat header injection that let authenticated users compromise GitHub's backend.

Alessandro Mascellino by Alessandro Mascellino
Sep 25, 2026
Nightmare Eclipse Releases LegacyHive Windows Zero-Day With Stripped PoC After Patch Tuesday
News

Nightmare Eclipse Releases LegacyHive Windows Zero-Day With Stripped PoC After Patch Tuesday

The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.

Alessandro Mascellino by Alessandro Mascellino
Sep 25, 2026
Anthropic’s Claude Helped Adversary Map OT Path During Mexican Water Utility Breach
News

Anthropic’s Claude Helped Adversary Map OT Path During Mexican Water Utility Breach

The AI identified a SCADA management interface and generated a targeted password spray to breach the IT-OT boundary, according to a new Dragos intelligence brief.

Alessandro Mascellino by Alessandro Mascellino
Sep 25, 2026
Microsoft Defender Zero-Day Exploits Cloud Restore To Grant SYSTEM Privileges
News

Microsoft Defender Zero-Day Exploits Cloud Restore To Grant SYSTEM Privileges

The local privilege escalation flaw abuses Windows Defender's handling of cloud-tagged files to grant SYSTEM access on fully patched Windows systems.

Alessandro Mascellino by Alessandro Mascellino
Sep 25, 2026
Nightmare Eclipse Drops Three Zero-Days In A Week, Two In Security Software
News

Nightmare Eclipse Drops Three Zero-Days In A Week, Two In Security Software

An Avast flaw and a CrowdStrike Falcon flaw landed alongside an Nvidia memory corruption bug, weeks after a similar release against Kaspersky.

Alessandro Mascellino by Alessandro Mascellino
Sep 25, 2026
SectopRAT Hides Inside A Tampered Copy Of Legitimate Audio Software
News

SectopRAT Hides Inside A Tampered Copy Of Legitimate Audio Software

A multi-stage loader ran SectopRAT in memory from a locally tampered copy; Fortinet found no evidence of a supply-chain compromise.

Alessandro Mascellino by Alessandro Mascellino
Sep 24, 2026
CLOSEDQUORUM Malware Swaps Its C2 Server For A Panel Of AI Models
News

CLOSEDQUORUM Malware Swaps Its C2 Server For A Panel Of AI Models

Commercial LLM APIs replace attacker-run C2 infrastructure; Talos has not confirmed the implant has been deployed in the wild.

Alessandro Mascellino by Alessandro Mascellino
Sep 24, 2026
Actively Exploited Heap Overflow In F5 BIG-IP APM Enables Unauthenticated RCE
News

Actively Exploited Heap Overflow In F5 BIG-IP APM Enables Unauthenticated RCE

F5 BIG-IP APM is vulnerable when configured as an OAuth authorization server; client and resource-server deployments are unaffected.

Alessandro Mascellino by Alessandro Mascellino
Sep 23, 2026
New ChainScript RAT Is Spreading Via Fake Microsoft Teams Installers: Here’s How It Works
News

New ChainScript RAT Is Spreading Via Fake Microsoft Teams Installers: Here’s How It Works

Threat actors are using ChainScript, a newly discovered remote access trojan that can rotate its infrastructure without rebuilding its implant. Blackpoint researchers have watched the ChainScript remote access trojan switch to a new command server when its connection reset. Nothing changed in the malware already running on the infected machine. The Node.js RAT reached victims...

Alessandro Mascellino by Alessandro Mascellino
Sep 22, 2026
Researcher Finds OpenAI Agent Activity on Hugging Face Two Weeks Before Known Proxy Deployment
News

Researcher Finds OpenAI Agent Activity on Hugging Face Two Weeks Before Known Proxy Deployment

Research into the Hugging Face accounts OpenAI's agents used in May found previously unknown relay code, network probes, and account-registration tooling.

Alessandro Mascellino by Alessandro Mascellino
Sep 17, 2026
BambooToken Controls Windows And Linux systems By Hiding Behind MQTT brokers
News

BambooToken Controls Windows And Linux systems By Hiding Behind MQTT brokers

BambooToken routes C2 traffic through IoT message brokers, keeping its infrastructure hidden and infected machines from ever contacting the attacker directly.

Alessandro Mascellino by Alessandro Mascellino
Sep 16, 2026
Russian Hackers Go “Nuclear” To Trick AI-Powered Malware Scanners
News

Russian Hackers Go “Nuclear” To Trick AI-Powered Malware Scanners

ESET found malware containing a nuclear weapon prompt designed to halt AI scanner analysis before reaching the malicious payload.

Alessandro Mascellino by Alessandro Mascellino
Sep 14, 2026
LiteLLM Security Gaps Open Paths to Cloud Compromise
News

LiteLLM Security Gaps Open Paths to Cloud Compromise

Wiz found an authentication bypass, root-level code execution and a route to cloud credentials, and nearly one in ten public instances still accepts the default key.

Alessandro Mascellino by Alessandro Mascellino
Sep 10, 2026
F5 BIG-IP Web Shell Runs in Memory, Evading File Scans
News

F5 BIG-IP Web Shell Runs in Memory, Evading File Scans

The shell exists only in the memory of the Apache process. The loader that puts it there changes system binaries on disk, which is where F5 says to look.

Alessandro Mascellino by Alessandro Mascellino
Sep 10, 2026
Adobe Commerce Backdoor Poses As Linux Time Daemon
News

Adobe Commerce Backdoor Poses As Linux Time Daemon

The implant disguises its C2 as time-sync traffic and renames itself after the legitimate Linux NTP daemon — the process a defender filtering port 123 would automatically whitelist.

Alessandro Mascellino by Alessandro Mascellino
Sep 8, 2026
Cleo Harmony Token Flaw Let Any User Become Administrator
Uncategorized

Cleo Harmony Token Flaw Let Any User Become Administrator

Every local user's refresh token carries an administrator type, and Cleo looks its subject up in a separate admin store with password checks disabled.

Alessandro Mascellino by Alessandro Mascellino
Sep 3, 2026
BREEZE COMET Built Four Backdoors To Survive Partial Eviction
News

BREEZE COMET Built Four Backdoors To Survive Partial Eviction

The four custom implants use different languages, control channels, and persistence methods, with Mandiant tying the group's tooling to generative AI.

Alessandro Mascellino by Alessandro Mascellino
Sep 2, 2026
JSCeal Mints Google Tokens Inside the Victim’s Own Browser
News

JSCeal Mints Google Tokens Inside the Victim’s Own Browser

Recovered code shows the complete workflow implemented, though Check Point stops short of saying it succeeds against every version of Google's login flow.

Alessandro Mascellino by Alessandro Mascellino
Sep 1, 2026
CISA Red Team Reached Two Cloud Tenants Despite Very Different SOC Maturity
News

CISA Red Team Reached Two Cloud Tenants Despite Very Different SOC Maturity

One SOC detected and contained the intrusion in minutes. The other missed it entirely. But the same cloud identity weaknesses gave the red team a path into both environments.

Alessandro Mascellino by Alessandro Mascellino
Aug 26, 2026