Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.
Group-IB linked the Windows implant to the Iranian-nexus Cavern framework and found encrypted tasking hidden inside calendar events dated to May 2050.
by Alessandro Mascellino
The Windows User Profile Service local privilege escalation flaw works on systems running the July 2026 updates, but the researcher scaled the exploit back to slow immediate weaponization.
by Alessandro Mascellino
Oasis Security found that a crafted link could make Claude Desktop run an attacker's instructions with no chance to review them, risking data theft and, in certain configurations, code execution. Anthropic has now patched it.
by Alessandro Mascellino
By faking the application ID in sign-in requests, attackers can map Microsoft Entra ID users and test passwords while leaving no successful login in the logs.
by Alessandro Mascellino
ESET analyzed roughly 900,000 agentic AI skills and flagged thousands as malicious, exposing a governance gap that security leaders are only beginning to notice.
by Alessandro Mascellino
An exposed cloud server acting as a LiteLLM proxy to Amazon Bedrock was compromised and used to mine cryptocurrency.
by Alessandro Mascellino
Noma Labs found that a crafted GitHub issue could hijack a misconfigured Agentic Workflow, causing it to read a private repository and publish its contents.
by Alessandro Mascellino
Security updates address CVE-2026-48282, a maximum-severity path traversal vulnerability that could allow RCE without user interaction.
by Alessandro Mascellino
Attackers planted a stealthy trojan inside fake PoC exploits on GitHub, exploiting the pressure on researchers to discover new vulnerabilities.
by Alessandro Mascellino
A coordinated takedown hit one of the world's largest residential proxy networks, which Google says rented hijacked smart TVs and streaming boxes to cybercriminals and espionage groups.
by Alessandro Mascellino
Skyhawk Security reports that its autonomous attack tool chained legitimate, correctly configured permissions into a full AWS organization takeover, with no misconfiguration involved and no alert raised.
by Alessandro Mascellino
A high-severity bug in Amazon's AI coding assistant let attackers run code and lift cloud credentials the moment a developer opened a booby-trapped repository, Wiz researchers found.
by Alessandro Mascellino
Security researchers witnessed attackers hijack unprotected enterprise AI systems to launch attacks on others and run their own operations, exploiting critical flaws in a widely used AI gateway the same day they were patched.
by Alessandro Mascellino
Apple's latest iOS, iPadOS, macOS, and Safari updates fix around 30 vulnerabilities, several of them WebKit flaws that researchers uncovered with help from AI tools including Anthropic's Claude and OpenAI Codex.
by Alessandro Mascellino
A long-running campaign disguised malware as ad blockers and VPNs to harvest Google credentials, WordPress admin logins, and session cookies.
by Alessandro Mascellino
A joint statement from the alliance's six agency heads tells boards that patching alone can no longer keep pace with AI-accelerated attacks, and that resilience must be built in by design.
by Alessandro Mascellino
AI-generated lures and disposable cloud infrastructure drove a 1,380% jump in device code phishing over six months, with individually unique attack messages across 344 victim organizations.
by Alessandro Mascellino
A compromised integration at market intelligence platform Klue has exposed Salesforce CRM data across a growing list of connected companies, with new victims still coming forward.
by Alessandro Mascellino
Fortra researchers have detailed CalPhishing, a technique that hides phishing lures inside Microsoft 365 Groups, calendar invites, and shared files — surfaces that sit outside what inbox filtering is designed to catch
by Alessandro Mascellino
A sprawling dataset of working Fortinet logins reveals an uncomfortable truth: many of the exposed passwords were long and complex yet useless, because they had been stolen rather than guessed.
by Alessandro Mascellino
A now-patched weakness in Google's Vertex AI SDK for Python let an attacker poison a victim's AI model and run code in their cloud, with no access to the target's project.
by Alessandro Mascellino
Cisco has patched a medium-severity file-write bug in Catalyst SD-WAN Manager that is under active exploitation, with no workaround available and a federal patching deadline now set.
by Alessandro Mascellino
Researchers chained an AI prompt-injection bug with two classic web flaws to turn Copilot Enterprise Search into a silent data-theft tool, before Microsoft fixed it.
by Alessandro Mascellino
Mandiant says the extortion group weaponized a critical flaw in Oracle's enterprise software for weeks before a patch existed, with higher education bearing the brunt.
by Alessandro Mascellino
A joint legal and law-enforcement action has dismantled "Outsider Enterprise," a subscription smishing operation that Google and the FBI say relied on AI-based tools to defraud victims at industrial scale.
by Alessandro Mascellino
Check Point is urging customers to patch a critical authentication bypass in its VPN products after finding it exploited in the wild, with one case tied to a Qilin ransomware affiliate.
by Alessandro Mascellino
The lure is AI hype, but the substance is evasion: fake CAPTCHAs that defeat malware sandboxes, laundered redirect chains, and search results poisoned to surface fake tool downloads.
by Alessandro Mascellino
Claude Fable 5 has shipped to everyone, but with safeguards that route risky cyber and biology queries to a weaker model.
by Alessandro Mascellino
A self-spreading credential stealer reached 73 Microsoft repositories, including Azure projects, before GitHub disabled them. The malware is built to fire when developers open infected code in AI coding tools.
by Alessandro Mascellino
Proofpoint Links New “TrustConnect” Malware Platform to RedLine Ecosystem
by Alessandro Mascellino
A Logitech breach is linked to CL0P extortion group.
by Alessandro Mascellino
Attackers can execute code without credentials on unpatched FortiClient EMS servers, and CISA says federal agencies have three days to patch
by Alessandro Mascellino