paolocostanzo.com LinkedIn β†’
Cloud & AI Security Research

Paolo
Costanzo
Research

Independent Security Researcher Β· Co-Founder @ CoDe RTD Β· Professor of Cybersecurity & AWS @ ITS ICT Piemonte
Research reports, reproducible labs and technical field notes on cloud security, agentic AI/MCP, APIs and authorized offensive validation.

Research profile β†’ ResearchGate
Cloud SecurityAWS Β· IAM Β· Identity
Agentic AILLM Β· MCP Β· Tool Auth
Offensive ValidationScope Β· Evidence Β· Report
// Latest posts:
CTF Β· Walkthrough Β· TryHackMe Aug 2026
CTF Writeups β€” Hacker Holidays 2026

Step-by-step solutions to the Byte Lotus Hotel event rooms: OSINT, web, cloud, forensics, boot2root. Each writeup with reproducible methodology, defensive notes and redacted flags β€” the point is how you get there, not the value.

12 rooms Methodology OSINT Β· Web Β· Cloud Β· Forensics
Agentic AI Β· MCP Β· Tool Authorization Β· Cloud 29 Jul 2026
MCP 2026-07-28: stateless does not mean state-free

The revision removes protocol sessions and, in the same document, forbids treating possession of a state handle as authentication. An executable conformance test for that MUST NOT: three key strategies compared, 13/13 tests, in-process lab. The composite key the spec recommends can be bypassed when the principal id contains the delimiter.

Reproducible lab 13/13 tests
Privacy Β· Wearable Β· OSINT 24 May 2026
Wearable biometric telemetry: technical tear-down and data supply chain

Tear-down of a sensor ring (infrared PPG sampled at 250 Hz, skin temperature at 0.1Β°C), analysis of the v2 API and sync endpoints, documentary reconstruction of the corporate and investment chain, review of the available clinical literature (73% specificity, underestimated REM stage) and of the US class actions. With a self-critique section and explicit limitations.

Original research Methodology Cited sources v2
Threat Intelligence Β· OSINT Β· On-chain 07 Apr 2026
Anatomy of a TRON wallet drainer-as-a-service

Analysis of an affiliate-model drainer infrastructure: from the initial phishing message to the TRC-20 approval chain, mapping of collection wallets and command infrastructure, $13,960 in transfers traced on-chain. Public sources, open channels and blockchain data.

Original research On-chain data Preprint on ResearchGate
Cloud Β· AWS Β· SSRF Β· IAM 31 Mar 2026
SSRF β†’ IMDSv1: exfiltrating IAM credentials from an EC2 instance

Reproducible lab on an owned environment: from an application-level SSRF against 169.254.169.254 to the instance role's temporary credentials. Documented context (Capital One, 106 million records, $80M fine) and verifiable mitigations: HttpTokens=required, hop limit, least-privilege role policies.

Reproducible lab Mitigations
[ CLASSIFIED ] ???
β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

// ACCESS DENIED
// Clearance level: INSUFFICIENT
// Next post loading...
// ETA: soon™

guest@nonΓ¨:~/ctf β€” bash 🏴 0/5
// CTF CHALLENGE β€” find 5 flags Type help to begin.
guest@nonè:~$
Threat Intelligence Β· OSINT Β· Content Moderation 21 Apr 2026
Coordinated abuse network on Telegram: content moderation, payment rails and regulatory response

Starting from a published CNN investigation, a threat intelligence analysis of how an abuse-material distribution network stayed operational across content moderation, crypto payment rails and regulatory oversight. Based on public journalistic and documentary sources. Sensitive content.

Methodology Public sources Sensitive content
Wi-Fi Β· Hardware Β· Lab 21 Mar 2026
Evil portal, beacon spam and deauth: a €40 hardware Wi-Fi lab

Classroom lab on an isolated lab network: Cardputer-Adv with Bruce firmware, evil portal, beacon spam and 802.11 deauthentication. Hardware setup, commands, observed results and client- and infrastructure-side countermeasures (802.11w/PMF, captive portal verification, DNS and certificates).

Reproducible lab Countermeasures
Threat Intelligence Β· OSINT Β· Payload Analysis 17 Mar 2026
Operation Epic Fury: independent OSINT analysis of a dual-platform campaign

OSINT investigation into an Android + Windows campaign attributed to an Iranian actor. A Windows payload not documented in public reporting, a secondary C2 at 0/94 VirusTotal detections at time of analysis, infrastructure registered roughly 8 months before the operation. Point-by-point comparison with the Unit 42 and CloudSEK reports, full indicators of compromise and detection rules published alongside the report.

Original research Methodology IoC Detection rules Preprint on ResearchGate
Network Β· ISP Β· Diagnostics 10 Mar 2026
TIM, GeForce Now and the ICMP black hole

Diagnosing an ICMP black hole on an access network that broke Path MTU Discovery, causing packet loss on GeForce Now and capping throughput at 26 Mbps on a 1 Gbps line. Measurement method, isolation of the offending hop and MTU/MSS-side workaround.

Cloud Β· AWS Β· IAM Mar 2026
AWS IAM: five recurring misconfigurations and how to fix them

Wildcards in policies, root user without MFA, exposed static access keys, over-permissive roles and disabled logging. For each: how to detect it, why it matters and the applicable fix, mapped to Well-Architected Framework controls.

AI Security Β· LLM Β· AppSec Mar 2026
Prompt injection on enterprise LLMs: attack surface and mitigations

An LLM wired into internal data and application tooling introduces an attack surface traditional threat models do not cover. Walk-through of the input β†’ context β†’ tool call chain, and applicable mitigations: privilege separation, tool-level authorization, output validation and invocation logging.

Cloud Security Identity & Access (IAM) Agentic AI / MCP Security Threat Modeling Application & API Security Threat Intelligence OSINT Network Security Offensive Validation Security Reporting
// Certifications & badges Verify on Credly β†’
AWS Academy Educator Β· AWS Training & Certification Β· 2026 Claude Partner Badge β€” Claude Code Β· Anthropic Β· 2026 Secure AI/ML-Driven Software Development Β· The Linux Foundation Β· 2026 EU Cyber Resilience Act (CRA) Β· The Linux Foundation Β· 2026 AWS Academy Graduate β€” Cloud Architecting Β· AWS Academy AWS Academy Graduate β€” Cloud Security Foundations Β· AWS Academy Fortinet Certified Associate β€” Cybersecurity Β· Fortinet Model Context Protocol: Advanced Topics Β· Anthropic Operationalizing MITRE ATT&CK v13 Β· AttackIQ Ethical Hacker Β· Cisco Networking Academy
ATT&CK Security Stack Mappings: AWS Β· AttackIQ Strategic Cybersecurity Management Β· AttackIQ API Penetration Testing Β· APIsec University CyberOps Associate Β· Cisco Networking Academy Network Security Β· Cisco Networking Academy Cisco Certified Instructor Β· Networking Academy FortiGate 7.6 Operator Β· Fortinet Cyber Security Certificate Β· TryHackMe Building with the Claude API Β· Anthropic Claude Code in Action Β· Anthropic Claude in Amazon Bedrock Β· Anthropic Red Hat AI Foundations β€” Executive Β· Red Hat