Red Hot Cyber
Cybersecurity, Cybercrime News and Vulnerability Analysis
Fortinet 970x120px

Author: Manuel Roccon

Manuel Roccon

I began my career working in ICT research and implementation and application development. In order to add security aspects to these fields, a few years ago I added skills related to offensive security (OSCP), also dealing with security analysis and pentesting in many organizations.

Profilo LinkedIn
Areas of Expertise Ethical Hacking, Bug Hunting, Penetration Testing, Red Teaming, Security Research, Cybersecurity Communication

Current Positions

  • IT & Cyber Security Manager – WPR Srl: Manuel Roccon is the strategic lead for the entire IT infrastructure and corporate defense. He proactively oversees Red Teaming activities and extends his role to governance and compliance, conducting internal audits to ensure strict alignment with international frameworks such as NIS2 and IEC 62443. Simultaneously, he drives corporate innovation through continuous research and the implementation of hardware/software solutions for intrusion monitoring.
  • Technical Writer – Red Hot Cyber: Author of technical articles and analyses on vulnerabilities, cyberattacks, and security tools.
  • Instructor & Certified Trainer: Since 2023, trainer in Cyber Security and Ethical Hacking at IMI Academy and certified instructor for Cisco Networking Academy.

Core Competencies

  • Offensive Security & Red Teaming: Expert in vulnerability assessment and penetration testing, specialized in attack methodology analysis and threat simulation to strengthen systemic resilience.
  • ICT Infrastructure: Management of client/server systems, networking, VPS, and web services.
  • Compliance: Deep knowledge of NIS2, IEC 62443, and the AI Act, ensuring corporate processes align with the latest security standards.
  • Software Development: Strong experience in C#, PHP, and Python, focusing on custom monitoring tools and complex system integrations.
  • Attack Monitoring & Analysis: Configuration of control systems to detect threats and anomalous behavior.

Initiatives and Contributions

  • Public Speaking: Regular speaker at the Red Hot Cyber Conference (2023–2025) and the Digital Security Festival, with presentations focused on web vulnerabilities and OT security.
  • Research & Community Engagement: Active member of the Technical Committee of Club Bit and researcher for the Red Hot Cyber and HackerHood communities.
  • Technical Innovation: Creator of Ares Security Box, a proactive defense solution against lateral movement in networks, and Hyper-Monitor for remote monitoring of virtualized infrastructures.

Professional Vision

Manuel Roccon combines deep technical expertise in defensive and offensive security with a strong passion for training. He firmly believes in security awareness as a cornerstone of modern defense, actively promoting a culture of safe digital practices and preparing the next generation of IT professionals.

Web resources

Personal website
Numero di articoli trovati: 15

Supply Chain Attack: How Notepad++ Was Compromised via CVE-2025-15556

In cybersecurity, we often focus on finding complex bugs in source code, ignoring the fact that end-user trust is built on a much simpler foundation: a download link. The Notepad++...

Critical Vulnerability in Modular DS WordPress Plugin – Update Now

A high-severity security vulnerability has been identified in the WordPress plugin "Modular DS (Modular Connector)," and numerous security reports suggest that this vulnerability is being exploited in real-world attacks. The...

Browser-in-the-Browser Phishing Attack: How to Protect Yourself

This article analyzes a recent and sophisticated phishing campaign that uses the Browser-in-the-Browser (BitB) technique to steal credentials, particularly those from services like Microsoft 365. The BitB attack is notable...

MongoDB Vulnerability CVE-2025-14847: Critical Memory Disclosure Bug

As previously reported, a serious vulnerability has been discovered in MongoDB that allows a remote attacker, without authentication, to access uninitialized server memory. The vulnerability has been assigned the CVE-2025-14847...

CVE-2025-47761: FortiClient VPN Zero-Day Exploit Lets Privilege Escalation

The following analysis examines the attack vector for CVE-2025-47761 , a vulnerability found in the Fortips_74.sys kernel driver used by FortiClient VPN for Windows. The core of the vulnerability lies...

Multi-threaded Hacking: US Pioneers Automated Operations with AI Agents

In recent months, a new cyber operations infrastructure has been developing in the United States, in which automated agents are becoming not just a support tool, but a full-fledged participant...

Discovering Remote Code Execution (RCE). The most feared security bug!

Of all the vulnerabilities, the most feared by victims and the most sought after by attackers is remote code execution, or RCE. This vulnerability allows arbitrary commands to be executed...

Notepad++ under attack! How a fake DLL opens the door to criminal hackers

A new vulnerability affecting Notepad++ was released in September. The vulnerability has been identified as CVE-2025-56383, and details can be found on the NIST website. CVE-2025-56383 is a DLL hijacking...

Tasting the Exploit: HackerHood tests Microsoft WSUS CVE-2025-59287 Exploit

The cybersecurity landscape was recently rocked by the discovery of a critical Remote Code Execution (RCE) vulnerability in Microsoft’s Windows Server Update Services (WSUS) . Identified as CVE-2025-59287 and with...

Harvard University Hit by Hacking Campaign Using Oracle E-Business Suite

Harvard University has confirmed that it was hit by a recent campaign that exploited a vulnerability in Oracle's E-Business Suite (EBS). In a statement to Recorded Future News, the university...