Blog Entries

25. 09. 2026 Francesco Pavanello SEC4U, Threat Intelligence

The Supply Chain Attack Surge in 2026: Emerging Threats

The first half of 2026 marked a structural shift in how cyber criminals and state-sponsored groups achieve initial access. Rather than targeting corporate perimeters directly, adversaries have increasingly exploited the “web of trust”, generally known as supply chain attacks. This means compromising open-source code registries, developer utilities, and third-party SaaS integrations. According to threat intelligence…

Read More
03. 07. 2026 Francesco Pavanello AI, SEC4U, Threat Intelligence

The AI Cyber Attacks Explosion in 2026: Emerging Threats

The first half of 2026 has witnessed the transition of artificial intelligence from an experimental playground into a cyber warfare domain. In fact, threat actors have shifted from basic prompting toward highly automated, multi-stage operations. This shift is characterized by a bifurcation of threats. On one side, attacks exploiting inherent AI vulnerabilities and architectural boundaries,…

Read More
26. 09. 2023 Francesco Pavanello Exposure Assessment, SATAYO, SEC4U, Threat Intelligence

Exposure Assessment: How to Identify Infrastructure Vulnerabilities

In our previous post about Exposure Assessment, we described how we outline a target’s infrastructure using SATAYO, our Cyber Threat Intelligence (CTI) platform. This means that we collected the identifiers of all the target’s machines, i.e., their host names and IP addresses. Now it’s time to understand which machines could allow an attacker to gain…

Read More
09. 06. 2023 Francesco Pavanello Exposure Assessment, SATAYO, SEC4U, Threat Intelligence

Exposure Assessment: The Best Way to Easily Discover a Target’s Infrastructure

Overview of discovering hostnames and IP addresses using OSINT techniques.

Read More
10. 01. 2023 Francesco Pavanello Blue Team, SEC4U

Spam Trap Box – A Powerful Method to Detect Phishing Attempts

It’s more and more common to receive emails asking for credentials. They usually say that there’s some kind of issue that can only be solved by accessing the involved service using the link inside the message text. In most cases these emails are malicious, intended to steal users’ or employees’ credentials and gain access to…

Read More

Archive