Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.

Articles By: Alessandro Mascellino

141 results
Fake RMM Vendor TrustConnect Caught Selling Signed Malware
News

Fake RMM Vendor TrustConnect Caught Selling Signed Malware

Proofpoint Links New “TrustConnect” Malware Platform to RedLine Ecosystem

Alessandro Mascellino by Alessandro Mascellino
Jun 8, 2026
Logitech Confirmed Data Theft After Oracle Zero-Day Exploit
News

Logitech Confirmed Data Theft After Oracle Zero-Day Exploit

A Logitech breach is linked to CL0P extortion group.

Alessandro Mascellino by Alessandro Mascellino
Jun 8, 2026
Fortinet Issues Urgent Warning Over Zero-Day Vulnerability Allowing Full Remote Access
News

Fortinet Issues Urgent Warning Over Zero-Day Vulnerability Allowing Full Remote Access

Attackers can execute code without credentials on unpatched FortiClient EMS servers, and CISA says federal agencies have three days to patch

Alessandro Mascellino by Alessandro Mascellino
Jun 8, 2026
Attackers Abused Microsoft Entra Invitations In New TOAD Phishing Scheme
News

Attackers Abused Microsoft Entra Invitations In New TOAD Phishing Scheme

A shift from traditional phishing to voice-oriented attacks is used in to target Microsoft users.

Alessandro Mascellino by Alessandro Mascellino
Jun 8, 2026
Researchers Expose ‘Silent Ransom’ Group Targeting Law Firms With Fake IT Support Calls
News

Researchers Expose ‘Silent Ransom’ Group Targeting Law Firms With Fake IT Support Calls

Resecurity says it is the first to map the rotating botnet that hides the extortion group's data-leak sites, and is calling on ISPs and DNS providers to help dismantle it.

Alessandro Mascellino by Alessandro Mascellino
Jun 8, 2026
Any Messaging App Can Deliver a Gemini Hijack, Researchers Find After Bypassing Google’s Fixes
News

Any Messaging App Can Deliver a Gemini Hijack, Researchers Find After Bypassing Google’s Fixes

SafeBreach researchers bypassed Google's latest Gemini defenses by splitting what a user hears from what the assistant's security check sees.

Alessandro Mascellino by Alessandro Mascellino
Jun 4, 2026
Trump’s AI Order Is a Signal for Defenders to Build Remediation Capacity
News

Trump’s AI Order Is a Signal for Defenders to Build Remediation Capacity

A new executive order lets the government assess frontier AI models' cyber capabilities, but fixing flaws fast enough remains defenders' real challenge.

Alessandro Mascellino by Alessandro Mascellino
Jun 4, 2026
VS Code Bug Lets Attackers Steal GitHub Tokens With A Single Click
News

VS Code Bug Lets Attackers Steal GitHub Tokens With A Single Click

The unpatched vulnerability in github.dev lets a single malicious link exfiltrate a GitHub OAuth token with full access to all of a victim's repositories, including private ones.

Alessandro Mascellino by Alessandro Mascellino
Jun 3, 2026
Callback Phishing Campaign Clears DKIM and DMARC by Routing Lures Through Airbnb’s Servers
News

Callback Phishing Campaign Clears DKIM and DMARC by Routing Lures Through Airbnb’s Servers

A targeted campaign hid callback phishing lures inside genuine Airbnb emails, defeating authentication checks with no link to click or file to open.

Alessandro Mascellino by Alessandro Mascellino
Jun 2, 2026
ChatGPT Can Be Tricked Into Delivering Phishing Links From Any Web Page
News

ChatGPT Can Be Tricked Into Delivering Phishing Links From Any Web Page

A small payload appended to a web page can plant phishing links, fake security alerts, and QR codes inside ChatGPT's response interface.

Alessandro Mascellino by Alessandro Mascellino
Jun 1, 2026
Six Windows Zero-Days Dropped Without Warning Show the Cracks in Coordinated Disclosure
News

Six Windows Zero-Days Dropped Without Warning Show the Cracks in Coordinated Disclosure

A single researcher published exploits for six Windows and Defender flaws outside the normal disclosure process, several still unpatched, in a pattern AI could soon make far more common.

Alessandro Mascellino by Alessandro Mascellino
May 28, 2026
AI Chatbots May Be Directing Users to Cryptojacking Download Sites
News

AI Chatbots May Be Directing Users to Cryptojacking Download Sites

The operation impersonates trusted PC utilities like CrystalDiskInfo and FurMark to find machines worth mining, and plants a ScreenConnect backdoor that could later enable ransomware

Alessandro Mascellino by Alessandro Mascellino
May 27, 2026
Google Exposes Phishing Campaigns That Bypass MFA and Hijack Digital Wallets
News

Google Exposes Phishing Campaigns That Bypass MFA and Hijack Digital Wallets

A maturing Chinese-language Phishing-as-a-Service ecosystem has moved past stealing logins, instead intercepting MFA codes in real time and loading victims' payment cards into attacker-controlled digital wallets.

Alessandro Mascellino by Alessandro Mascellino
May 27, 2026
Microsoft 365 MFA Bypassed by New Kali365 Phishing Kit, FBI Warns
News

Microsoft 365 MFA Bypassed by New Kali365 Phishing Kit, FBI Warns

The Phishing-as-a-Service platform steals Microsoft 365 OAuth tokens by routing victims through Microsoft's real login page and sidestepping MFA without ever capturing a password.

Alessandro Mascellino by Alessandro Mascellino
May 26, 2026
TrapDoor Crypto Stealer Targets AI Developers in Coordinated Campaign
News

TrapDoor Crypto Stealer Targets AI Developers in Coordinated Campaign

Socket researchers tracked more than 34 malicious packages across npm, PyPI, and Crates.io that poison AI coding assistants and harvest crypto wallets, SSH keys, and cloud credentials.

Alessandro Mascellino by Alessandro Mascellino
May 26, 2026
Supply Chain Breaches Surge 60% To Hit Half Of All Incidents
News

Supply Chain Breaches Surge 60% To Hit Half Of All Incidents

Verizon’s latest report finds third-party-involved breaches reached 48% of the total this year, after already doubling in the previous edition, with Salesloft Drift cited as a textbook case.

Alessandro Mascellino by Alessandro Mascellino
May 21, 2026
Microsoft’s New AI Bug Hunter Finds 16 Windows Vulnerabilities
News

Microsoft’s New AI Bug Hunter Finds 16 Windows Vulnerabilities

The system orchestrates over 100 AI agents and found 16 flaws in this week’s Patch Tuesday.

Alessandro Mascellino by Alessandro Mascellino
May 20, 2026
Anthropic’s Claude Helped Adversary Map OT Path During Mexican Water Utility Breach
News

Anthropic’s Claude Helped Adversary Map OT Path During Mexican Water Utility Breach

The AI identified a SCADA management interface and generated a targeted password spray to breach the IT-OT boundary, according to a new Dragos intelligence brief.

Alessandro Mascellino by Alessandro Mascellino
May 20, 2026
3,800 Internal GitHub Repos Stolen Via Poisoned VS Code Extension
News

3,800 Internal GitHub Repos Stolen Via Poisoned VS Code Extension

The breach came from a single GitHub employee installing a malicious VS Code extension, with TeamPCP claiming responsibility and offering the stolen source code for $50,000.

Alessandro Mascellino by Alessandro Mascellino
May 20, 2026
New macOS Stealer Impersonates Apple, Google & Microsoft In Single Attack Chain
News

New macOS Stealer Impersonates Apple, Google & Microsoft In Single Attack Chain

The new SHub Stealer variant disguises its delivery as an Apple security update, hosts payloads on a typo-squatted Microsoft domain, and persists from a fake Google Software Update directory.

Alessandro Mascellino by Alessandro Mascellino
May 20, 2026
Trusted IT Tools Were All Attackers Needed to Spend Four Months Inside a Network
News

Trusted IT Tools Were All Attackers Needed to Spend Four Months Inside a Network

Microsoft Incident Response found no exploits, no novel malware, and no firewall breaches — attackers moved freely using HPE Operations Agent and harvested credentials via malicious DLLs on domain controllers.

Alessandro Mascellino by Alessandro Mascellino
May 13, 2026
Google Disrupts First AI-Developed Zero-Day Exploit Campaign
News

Google Disrupts First AI-Developed Zero-Day Exploit Campaign

Google Threat Intelligence Group tracked cybercrime actors using AI assistance to discover and weaponize a 2FA bypass in an open-source admin tool.

Alessandro Mascellino by Alessandro Mascellino
May 12, 2026
Identity Breaches Hit 71% of Organizations in Past Year
News

Identity Breaches Hit 71% of Organizations in Past Year

The survey of 5,000 IT and cybersecurity leaders across 17 countries pegs the mean cost to recover from a successful identity breach at USD 1.64 million, with weak non-human identity management cited in 41% of cases.

Alessandro Mascellino by Alessandro Mascellino
May 12, 2026
Fake OpenAI Privacy Filter Repository Racked Up 244,000 Downloads Before Hugging Face Takedown
News

Fake OpenAI Privacy Filter Repository Racked Up 244,000 Downloads Before Hugging Face Takedown

HiddenLayer researchers found the fake "Privacy Filter" repository briefly hit the trending charts before shipping a Rust-based infostealer through a six-stage attack chain.

Alessandro Mascellino by Alessandro Mascellino
May 11, 2026
Palo Alto Firewall Zero-Day Under Active Attack With No Fix Available Until May 13
News

Palo Alto Firewall Zero-Day Under Active Attack With No Fix Available Until May 13

The unauthenticated buffer overflow in the User-ID Authentication Portal carries a CVSS score of 9.3 and lets attackers run arbitrary code with root privileges on PA-Series and VM-Series firewalls.

Alessandro Mascellino by Alessandro Mascellino
May 6, 2026
Trellix Confirms Source Code Repository Breach
News

Trellix Confirms Source Code Repository Breach

The cybersecurity vendor, formed in 2022 from McAfee Enterprise and FireEye, is working with outside forensic experts and has notified law enforcement, but key details about the intrusion remain unclear.

Alessandro Mascellino by Alessandro Mascellino
May 5, 2026
Microsoft Flags Code-of-Conduct Phishing Campaign Targeting 35,000 Users Across 26 Countries
News

Microsoft Flags Code-of-Conduct Phishing Campaign Targeting 35,000 Users Across 26 Countries

The multi-stage operation used CAPTCHA-gated landing pages and adversary-in-the-middle infrastructure to grab sign-in tokens and bypass non-phishing-resistant MFA.

Alessandro Mascellino by Alessandro Mascellino
May 5, 2026
cPanel Flaw Goes From Disclosure to Mass Compromise in Hours as ‘.sorry’ Ransomware Spreads
News

cPanel Flaw Goes From Disclosure to Mass Compromise in Hours as ‘.sorry’ Ransomware Spreads

A newly disclosed cPanel and WHM authentication bypass is being exploited in multiple campaigns, including botnet deployment and suspected ransomware activity affecting exposed hosting infrastructure.

Alessandro Mascellino by Alessandro Mascellino
May 5, 2026
Patch Window Collapses As Attackers Exploit New Vulnerabilities In Under 48 Hours
News

Patch Window Collapses As Attackers Exploit New Vulnerabilities In Under 48 Hours

Automation, identity abuse, and patch latency are now main drivers of compromise, ahead of zero days, new research finds.

Alessandro Mascellino by Alessandro Mascellino
Apr 30, 2026
Microsoft Entra ID’s New AI Agent Roles Could Be Abused To Take Over Any Service Principal
News

Microsoft Entra ID’s New AI Agent Roles Could Be Abused To Take Over Any Service Principal

The Agent ID Administrator role, scoped to AI agent objects, could be abused to take ownership of arbitrary service principals across a tenant.

Alessandro Mascellino by Alessandro Mascellino
Apr 29, 2026
GitHub Exploit Exposed Millions Of Public And Private Repositories, Wiz Finds
News

GitHub Exploit Exposed Millions Of Public And Private Repositories, Wiz Finds

Wiz researchers used AI-augmented reverse engineering to surface an X-Stat header injection that let authenticated users compromise GitHub's backend.

Alessandro Mascellino by Alessandro Mascellino
Apr 29, 2026
AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants
News

AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants

Proofpoint’s annual survey of 1,453 security professionals shows that organizations hit by an AI incident saw threats appear across every collaboration channel, not just the inbox.

Alessandro Mascellino by Alessandro Mascellino
Apr 28, 2026