#PacketHunters
SSO & threat models, not just a cloud passing by.
It's a risk dev and CISO must comply with: proper config, proper access.

My #PacketHunters of the week - Bruce approved 😎
#PacketHunters - SSO: when one login becomes too many trust assumptions - Baited
SSO misconfigurations can turn a single compromised identity into full organizational access. This analysis explains how SSO amplifies trust errors, enables lateral movement, and becomes a critical id...
blog.baited.io
December 15, 2025 at 11:58 AM
My weekly #tech writeup on #phishing and #MiTM for #Baited; something we (old schoolz crakerz intended) buried long ago and now.. Ay Carramba!

#Cybersecurity @ransomnews.online
🎣 #PacketHunters - MITM is dead! Long live MITM! Now it wears a phishing kit 💥 - Baited
MITM didn't die in 2018. It moved from the LAN to the identity layer and became the AiTM phishing kit. Technical breakdown and three detections inside.
blog.baited.io
June 22, 2026 at 1:10 PM
#Pretexting is a thing, and #WindTre (too bad) knows it now.

The worst part? Yet to come.
My #PacketHunters for Baited.io, quite technical and worthy - not for #piangina.

#phishing #cybersecurity @garantepiracy.it (thanks for the WoW)
How did attackers steal 365k Wind Tre customer records using social engineering?
The Wind Tre social engineering breach cost €1.7M. Two fake support techs, two stores, 365K records. Technical breakdown and detection code inside.
blog.baited.io
July 21, 2026 at 9:57 AM
Le riunioni, le call, le call, le riunioni e decine di "ti mando un calendar".

Clicchi e #ciaone: il malware viene deployato, il CISO piange, l'impiegato viene fustigato in sala mensa.

Due parole sul fenomeno #calsmuggling e le red flag da cercare. Ho scritto un post tecnico, vi avverto.
#PacketHunters - HTML smuggling in Calendar invites (aka the .ics you didn’t inspect) - Baited
What looks like a harmless calendar invite can be a hidden delivery system. Attackers are now embedding base64-encoded HTML payloads inside .ics files — turning “urgent meeting” requests into stealth ...
blog.baited.io
October 6, 2025 at 3:21 PM
Da ascoltare la musica e pagare un concerto ce ne passa.. soprattutto se si tratta dei tuoi soldi! (..vedi che poi il Signor Baci ha ragione a voler disdire?)

Fake #Spotify payment, ne parlo sul mio #PacketHunters per Baited:
Fake Spotify payment emails are stealing Credit Cards now
A fake Spotify 'payment failed' email is draining bank accounts within hours. Full breakdown of the attack chain, the tells, and the defenses that work.
blog.baited.io
August 3, 2026 at 4:31 PM
It's #RecoveryMonth at Baited and my very first #PacketHunter of the year is about identity exfiltration via browser extensions.

It happens, it will happen more and more if security is not taken into fucking serious consideration.

#cybersecurity
#PacketHunters: your recovery plan doesn’t include the browser, that’s why it will fail! - Baited
Malicious browser extensions silently exfiltrate identity data, sessions, and chats while bypassing traditional security controls. This technical deep dive shows how they work and why recovery plans i...
blog.baited.io
January 6, 2026 at 3:50 PM
Culatello, San Daniele, salame o #Emma-5?

La fiducia negli LLM dopo la figuraccia di un prodotto non sufficientemente addestrato e la spocchia di chi "è colpa degli utenti gné gné gné".

Ne parlo nel mio #PacktHunters per #Baited: blog.baited.io/2026/emma-5-...
🎣 #PacketHunters - 60k chats, 24 hours, DPO disabled: Emma-5 and the death of AI model trust 💥 - Baited
Emma-5 died in 24 hours: 60,000 chats, DPO disabled, no guardrails. The memes are funny. The real lesson about AI model trust is not.
blog.baited.io
June 29, 2026 at 1:10 PM
ShinyHunters made a phone call.
Then another to the vendor next door, eight months later.

Cost of the exploit kit: zero.
Not the sexiest, not the one that gets a DEFCON talk, just the cheapest one.

Why spend three weeks looking for a way in when a phone call gets you a session token in 12 minutes?
🎣 #PacketHunters - How did ShinyHunters breach Canvas and Instructure twice in eight months? - Baited
ShinyHunters breached Canvas. The vector class? Vishing into OAuth Device Code Flow. Passkeys don't save you. 275M users learned the hard way.
blog.baited.io
May 11, 2026 at 4:08 PM
So, my #PacketHunters about patterns - reused patterns - in phishing campaigns by threat actors.

Templates, templates, templates.
Must move away from standard education when talking about #cybersecurity!
June 25, 2026 at 9:45 AM
My #PacketHunters series lives on blog.baited.io - my playground!

Am a bit rude, I know but.. hey, who said unicorns have always to be cute? =)
Baited
Blog
blog.baited.io
June 22, 2026 at 5:29 PM
Very tech #PacketHunters today.
On AI agents, dumb humans and general #security strategies to secure things.

Governance is not a word, systems are exploitable and #Moltys 🦞 are playing under the glass dome.
Until... when?

blog.baited.io/2026/ai-agen...
AI Agents behave like users? We still need to secure them like scripts! - Baited
AI agents behave like users but are governed with static credentials and fragmented visibility. A technical analysis of identity drift, phishing risk, and why current IAM models are inadequate.
blog.baited.io
February 9, 2026 at 6:05 PM
📰 Italian university phish reused one visible template

A Palermo-focused #OSINT trail showed Italian universities hit by lookalike phishing pages built from the same operational template.

🔗 read more: blog.baited.io/2026/italian...

#ransomNews #cybersecurity
🎣 #PacketHunters - 138 campaigns in one week, and one of them cloned a university with a kit it already used on other atenei - Baited
CERT-AGID flagged a Weebly page cloning the University of Palermo login portal, the same kit it already used on other atenei. Inside the Italian universities phishing campaign.
blog.baited.io
June 25, 2026 at 8:37 AM
⚠️ The click isn’t “Join meeting”, it’s Join compromise

That “urgent meeting” in your inbox?
Might be carrying a #payload.

Attackers are now hiding base64 HTML code inside .ics files, using client quirks to slip past filters.

#CyberSecurity #Phishing #Infosec #RedTeam #BlueTeam
#PacketHunters - HTML smuggling in Calendar invites (aka the .ics you didn’t inspect) - Baited
What looks like a harmless calendar invite can be a hidden delivery system. Attackers are now embedding base64-encoded HTML payloads inside .ics files — turning “urgent meeting” requests into stealth…
blog.baited.io
October 6, 2025 at 4:37 PM
📰 TOAD invoices shipped before attacker QA finished

The campaign exposed six .xyz domains, two callback numbers and unfinished #TFN# placeholders, with no links or attachments to scan.

🔗 read more: blog.baited.io/2026/toad-in...

#ransomNews #cybersecurity
🎣 #PacketHunters – Caught mid-build: a TOAD invoice scam where #TFN# wasn't even filled in yet 💥 - Baited
Malwarebytes caught a TOAD invoice campaign mid-build — templates still showing #TFN# placeholders. Why callback phishing breaks your filters and your training.
blog.baited.io
June 26, 2026 at 7:37 AM
Haha, fair point! The best security pros usually have a bit of an edge. I’ll definitely check out the #PacketHunters series—looking forward to seeing what you’ve got brewing in your playground!
June 22, 2026 at 6:21 PM
📰 Mobile phishing beats email by forty percent

Verizon DBIR 2026 logged 22,000 confirmed breaches, with 62% involving humans and mobile phishing 40% more successful than email.

🔗 read more: blog.baited.io/2026/verizon...

#ransomNews #cybersecurity
🎣 #PacketHunters - Verizon DBIR 2026: 22.000 breaches, 40% more mobile phishing, and the one number nobody quoted - Baited
Verizon DBIR 2026 buried the scariest number on page 2: mobile social engineering success up 40%. Here is what defenders missed — and what Verizon's own breach record proves.
blog.baited.io
June 27, 2026 at 7:37 AM