Vincenzo Ciancaglini
10 articles
-
ResearchStars Don’t Save You: Popularity Is Not Security in the MCP Ecosystem
Building on our previous research, we correlated the security issues identified in public MCP servers with metadata crawled from popular directories. We then analyzed whether indicators such as popularity, activity, and vetting serve as reliable metrics to infer the risk of adopting an MCP server.
June 24th, 2026Vincenzo Ciancaglini, Marco Balduzzi, Alfredo Oliveira, David Fiser
Read article -
ResearchViral AI, Invisible Risks: What OpenClaw Reveals About Agentic Assistants
OpenClaw (aka Clawdbot or Moltbot) represents a new frontier in agentic AI: powerful, highly autonomous, and surprisingly easy to use. In this research, we examine how its capabilities compare to its predecessors’ and highlight the security risks inherent to the agentic AI paradigm.
February 6th, 2026 14 minSalvatore Gariuolo, Vincenzo Ciancaglini, Fernando Tucci
Read article -
ResearchThe Devil Reviews Xanthorox: A Criminal-Focused Analysis of the Latest Malicious LLM Offering
Xanthorox AI: flirty, menacing, and potentially devastating? We explored the inner workings of this LLM to unveil its devious capabilities for generating malicious code, obtaining private information, and roleplaying.
November 11th, 2025 15 minDavid Sancho, Vincenzo Ciancaglini, Salvatore Gariuolo
Read article -
ResearchThe Road to Agentic AI: Navigating Architecture, Threats, and Solutions
As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.
July 28th, 2025Fernando Tucci, Vincenzo Ciancaglini, Marco Balduzzi, Salvatore Gariuolo…
Read article -
ResearchDeepfake It ‘til You Make It: A Comprehensive View of the New AI Criminal Toolset
This report takes a comprehensive look at how deepfakes are used to support criminal business processes, what are the toolkits criminals are exploiting to power their deepfake creation, and what the deepfake underground looks like.
July 9th, 2025David Sancho, Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchThe Road to Agentic AI: Defining a New Paradigm for Technology and Cybersecurity
Our latest research provides a framework for understanding agentic AI systems, outlines their core characteristics, and examines the security implications surrounding their use.
June 17th, 2025Salvatore Gariuolo, Vincenzo Ciancaglini
Read article -
ResearchAI Assistants in the Future: Security Concerns and Risk Management
The article explores the evolving landscape of AI digital assistants, highlighting their transformative potential, associated security risks, and the importance of robust design and collaboration to ensure a secure and user-centric future.
December 6th, 2024 15 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Robert McArdle…
Read article -
ResearchSurging Hype: An Update on the Rising Abuse of GenAI
The cybercriminal abuse of generative AI (GenAI) is developing at a blazing pace. After only a few weeks since we reported on Gen AI and how it is used for cybercrime, new key developments have emerged. Threat actors are proliferating their offerings on criminal large language models (LLMs) and deepfake technologies, ramping up the volume and extending their reach.
July 30th, 2024 9 minDavid Sancho, Vincenzo Ciancaglini
Read article -
ResearchBack to the Hype: An Update on How Cybercriminals Are Using GenAI
Generative AI continues to be misused and abused by malicious individuals. In this article, we dive into new criminal LLMs, criminal services with ChatGPT-like capabilities, and deepfakes being offered on criminal sites.
May 8th, 2024 12 minVincenzo Ciancaglini, David Sancho
Read article -
ResearchHype vs. Reality: AI in the Cybercriminal Underground
This report discusses the state of generative artificial intelligence (AI) in the cybercriminal underground: how cybercriminals are using ChatGPT, how they're adding ChatGPT features to their criminal products, and how they’re trying to remove censorship to ask ChatGPT anything.
August 15th, 2023 17 minDavid Sancho, Vincenzo Ciancaglini
Read article