Vincenzo Ciancaglini
12 articles
-
ResearchStars Don’t Save You: Popularity Is Not Security in the MCP Ecosystem
Building on our previous research, we correlated the security issues identified in public MCP servers with metadata crawled from popular directories. We then analyzed whether indicators such as popularity, activity, and vetting serve as reliable metrics to infer the risk of adopting an MCP server.
June 24th, 2026Vincenzo Ciancaglini, Marco Balduzzi, Alfredo Oliveira, David Fiser
Read article -
BlogViral AI, Invisible Risks: What OpenClaw Reveals About Agentic Assistants
OpenClaw (aka Clawdbot or Moltbot) represents a new frontier in agentic AI: powerful, highly autonomous, and surprisingly easy to use. In this research, we examine how its capabilities compare to its predecessors’ and highlight the security risks inherent to the agentic AI paradigm.
February 6th, 2026 14 minSalvatore Gariuolo, Vincenzo Ciancaglini, Fernando Tucci
Read article -
ResearchThe Devil Reviews Xanthorox: A Criminal-Focused Analysis of the Latest Malicious LLM Offering
Xanthorox AI: flirty, menacing, and potentially devastating? We explored the inner workings of this LLM to unveil its devious capabilities for generating malicious code, obtaining private information, and roleplaying.
November 11th, 2025 15 minDavid Sancho, Vincenzo Ciancaglini, Salvatore Gariuolo
Read article -
ResearchThe Road to Agentic AI: Navigating Architecture, Threats, and Solutions
As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.
July 28th, 2025Fernando Tucci, Vincenzo Ciancaglini, Marco Balduzzi, Salvatore Gariuolo…
Read article -
ResearchDeepfake It ‘til You Make It: A Comprehensive View of the New AI Criminal Toolset
This report takes a comprehensive look at how deepfakes are used to support criminal business processes, what are the toolkits criminals are exploiting to power their deepfake creation, and what the deepfake underground looks like.
July 9th, 2025David Sancho, Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchThe Road to Agentic AI: Defining a New Paradigm for Technology and Cybersecurity
Our latest research provides a framework for understanding agentic AI systems, outlines their core characteristics, and examines the security implications surrounding their use.
June 17th, 2025Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchCES 2025: A Comprehensive Look at AI Digital Assistants and Their Security Risks
In this entry, we mapped the capabilities of various AI digital assistants that were showcased at CES 2025 based on an assessment matrix we developed to determine how this emerging technology holds up against potential security threats.
February 10th, 2025 12 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Rainer Vosseler
Read article -
ResearchAI Assistants in the Future: Security Concerns and Risk Management
The article explores the evolving landscape of AI digital assistants, highlighting their transformative potential, associated security risks, and the importance of robust design and collaboration to ensure a secure and user-centric future.
December 6th, 2024 15 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Robert McArdle…
Read article -
ResearchSurging Hype: An Update on the Rising Abuse of GenAI
The cybercriminal abuse of generative AI (GenAI) is developing at a blazing pace. After only a few weeks since we reported on Gen AI and how it is used for cybercrime, new key developments have emerged. Threat actors are proliferating their offerings on criminal large language models (LLMs) and deepfake technologies, ramping up the volume and extending their reach.
July 30th, 2024 9 minDavid Sancho, Vincenzo Ciancaglini
Read article -
ResearchBack to the Hype: An Update on How Cybercriminals Are Using GenAI
Generative AI continues to be misused and abused by malicious individuals. In this article, we dive into new criminal LLMs, criminal services with ChatGPT-like capabilities, and deepfakes being offered on criminal sites.
May 8th, 2024 12 minVincenzo Ciancaglini, David Sancho
Read article -
ResearchYour Stolen Data for Sale
In today’s rapidly evolving digital landscape, the risk of personal and professional data being stolen by nefarious actors looms larger than ever. This report lays bare the stark reality of this threat, with a specific focus on the unequal risks associated with data theft and its subsequent misuse.
November 13th, 2023 19 minDavid Sancho, Vincenzo Ciancaglini
Read article -
ResearchHype vs. Reality: AI in the Cybercriminal Underground
This report discusses the state of generative artificial intelligence (AI) in the cybercriminal underground: how cybercriminals are using ChatGPT, how they're adding ChatGPT features to their criminal products, and how they’re trying to remove censorship to ask ChatGPT anything.
August 15th, 2023 17 minDavid Sancho, Vincenzo Ciancaglini
Read article