Vincenzo Ciancaglini
12 articles
-
Researchスターの数では守れない:MCPエコシステムにおいて人気は安全性の証にはならない
本リサーチでは、これまでの研究を踏まえ、公開されているMCPサーバで確認されたセキュリティ問題を、主要なディレクトリからクロールしたメタデータと突き合わせて分析しました。そのうえで、人気度・活動状況・審査の有無といった指標が、MCPサーバを採用する際のリスクを推し量る信頼できる尺度となり得るかを検証しました。
June 24th, 2026Vincenzo Ciancaglini, Marco Balduzzi, Alfredo Oliveira, David Fiser
Read article -
Blog拡散するAIと不可視のリスク:OpenClawが描き出すエージェント型アシスタントの現在
OpenClaw(別名:Clawdbot、Moltbot)は、エージェント型AIの新たな局面を象徴する存在です。高い自律性と強力な機能を備えながら、驚くほど簡単に使えてしまう。今回の調査では、OpenClawの能力が従来のツールと比べてどのように進化しているのかを確認しつつ、エージェント型AIという枠組みそのものに内在するセキュリティリスクを明らかにします。
February 6th, 2026 14 minSalvatore Gariuolo, Vincenzo Ciancaglini, Fernando Tucci
Read article -
ResearchThe Devil Reviews Xanthorox: A Criminal-Focused Analysis of the Latest Malicious LLM Offering
Xanthorox AI: flirty, menacing, and potentially devastating? We explored the inner workings of this LLM to unveil its devious capabilities for generating malicious code, obtaining private information, and roleplaying.
November 11th, 2025 15 minDavid Sancho, Vincenzo Ciancaglini, Salvatore Gariuolo
Read article -
ResearchThe Road to Agentic AI: Navigating Architecture, Threats, and Solutions
As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.
July 28th, 2025Fernando Tucci, Vincenzo Ciancaglini, Marco Balduzzi, Salvatore Gariuolo…
Read article -
ResearchDeepfake It ‘til You Make It: A Comprehensive View of the New AI Criminal Toolset
This report takes a comprehensive look at how deepfakes are used to support criminal business processes, what are the toolkits criminals are exploiting to power their deepfake creation, and what the deepfake underground looks like.
July 9th, 2025David Sancho, Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchThe Road to Agentic AI: Defining a New Paradigm for Technology and Cybersecurity
Our latest research provides a framework for understanding agentic AI systems, outlines their core characteristics, and examines the security implications surrounding their use.
June 17th, 2025Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchCES 2025: A Comprehensive Look at AI Digital Assistants and Their Security Risks
In this entry, we mapped the capabilities of various AI digital assistants that were showcased at CES 2025 based on an assessment matrix we developed to determine how this emerging technology holds up against potential security threats.
February 10th, 2025 12 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Rainer Vosseler
Read article -
ResearchAI Assistants in the Future: Security Concerns and Risk Management
The article explores the evolving landscape of AI digital assistants, highlighting their transformative potential, associated security risks, and the importance of robust design and collaboration to ensure a secure and user-centric future.
December 6th, 2024 15 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Robert McArdle…
Read article -
ResearchSurging Hype: An Update on the Rising Abuse of GenAI
The cybercriminal abuse of generative AI (GenAI) is developing at a blazing pace. After only a few weeks since we reported on Gen AI and how it is used for cybercrime, new key developments have emerged. Threat actors are proliferating their offerings on criminal large language models (LLMs) and deepfake technologies, ramping up the volume and extending their reach.
July 30th, 2024 9 minDavid Sancho, Vincenzo Ciancaglini
Read article -
ResearchBack to the Hype: An Update on How Cybercriminals Are Using GenAI
Generative AI continues to be misused and abused by malicious individuals. In this article, we dive into new criminal LLMs, criminal services with ChatGPT-like capabilities, and deepfakes being offered on criminal sites.
May 8th, 2024 12 minVincenzo Ciancaglini, David Sancho
Read article -
ResearchYour Stolen Data for Sale
In today’s rapidly evolving digital landscape, the risk of personal and professional data being stolen by nefarious actors looms larger than ever. This report lays bare the stark reality of this threat, with a specific focus on the unequal risks associated with data theft and its subsequent misuse.
November 13th, 2023 19 minDavid Sancho, Vincenzo Ciancaglini
Read article -
ResearchHype vs. Reality: AI in the Cybercriminal Underground
This report discusses the state of generative artificial intelligence (AI) in the cybercriminal underground: how cybercriminals are using ChatGPT, how they're adding ChatGPT features to their criminal products, and how they’re trying to remove censorship to ask ChatGPT anything.
August 15th, 2023 17 minDavid Sancho, Vincenzo Ciancaglini
Read article