ISGroup history
From the underground to certified security
From the underground to certified security
Before protecting companies, we found vulnerabilities in software used by millions of people. Vendors fixed them one by one. Today, the same methodology guides the Penetration Tests we perform for companies, banks and public administrations.
ISGroup SRL is an Italian Offensive Security company based in Verona, specialized in Penetration Testing, Vulnerability Assessment, Code Review and Red Team activities. The ISGroup brand was born in 2005 from the experience of USH.it, an independent security research group founded in 2000, and the company is certified ISO/IEC 27001 and ISO 9001. The team has published more than 30 security advisories with CVEs assigned on software from international vendors such as PHP, Mozilla Firefox, Nginx, Jetty, Zabbix, Veeam, QNAP and Fortinet, and has worked for organizations such as Nestlé, Coop Italia, UBI Banca, Mediaset and the Italian Public Administration.
The method has a name: responsible disclosure. Each flaw is reported to the vendor before publication. The same ethics guide our Ethical Hacking and vulnerability research activities today. This page proves it, date by date.
Security is not declared. It is proven.
Independent research since 2000, brand since 2005: public advisories, assigned CVEs and vulnerabilities fixed by vendors. Fully verifiable.
With the arrival of dial-up connections, the future founders of ISGroup spent their nights in Italian hacker communities learning how systems really worked. The rule was clear: find flaws with original techniques, never exploit them, and understand them deeply enough to make systems safer.
Francesco "ascii" Ongaro founded USH.it with other researchers: an independent hacking and security research group. USH.it is still active today as ISGroup’s non-commercial laboratory, and every advisory published there is freely available.
The ISGroup brand was born in 2005. That same year saw the first public security advisories on Bugtraq and Full Disclosure and the first CVEs, starting with CVE-2005-3366. Since then, every discovered flaw has been reported to the vendor first and disclosed in a coordinated way. The research has never stopped.
The team brought its research to 25C3 in Berlin, Europe’s most important hacker conference, and taught penetration testing and web application security at the University of Pisa. Being selected for the Chaos Communication Congress means passing an international selection and standing alongside some of the continent’s best researchers. That research on PHP and web security is still cited today: in international whitepapers, by Red Hat and, in 2023, at DEF CON 31.
The offering expanded to Cyber Threat Intelligence and Early Warning services thanks to a direct connection with the underground research community. The consulting work served leading global security vendors.
ISGroup SRL was incorporated in Verona; its first financial year closed with EBT equal to 65% of revenues. In the same year, the investigation into SCADA industrial systems exposed on the Internet, conducted with journalists from SonntagsZeitung and Le Matin, demonstrated the real-world risks affecting critical infrastructure. From independent laboratory to partner for companies and institutions.
To increase the efficiency of verification activities, ISGroup began developing proprietary software to support security testing. The EasyAudit spin-off brought penetration testing within reach of SMEs, while the topic of digital surveillance reached prime time on Italia Uno with Ongaro’s appearance on "Mistero" (Mediaset).
The team discovered a critical privilege escalation in Veeam Backup & Replication (CVE-2015-5742), software present in most VMware and Hyper-V environments at the time. The vendor fixed the flaw. This is what matters to a customer: finding vulnerabilities before someone exploits them. During the same period, ISGroup presented the hacking landscape at the International Journalism Festival in Perugia, where it returned in 2016.
ISGroup obtained ISO/IEC 27001 certification for information security management: the same standards we verify for customers are applied to and audited on our own processes. For those who choose us, this means a supplier that can be qualified in regulated supply chains.
Quality joined security: ISO 9001 certification formalized control over methodologies, delivery times and project management. Both certifications are issued by IMQ with IQNET recognition and renewed at every audit cycle.
ISGroup research identified critical vulnerabilities in GoSign Desktop, a digital signature software widely used in Italy, allowing remote code execution (CVE-2025-34324, CVE-2025-34327). In the same year, expansion toward English-speaking markets was covered by outlets such as The Globe and Mail and Digital Journal.
In January 2026, the team published a new advisory on Ninja Forms, a WordPress plugin with hundreds of thousands of installations. Vulnerability research continues to feed our services: every technique discovered in our labs becomes one more control in the Penetration Tests we deliver. It has been this way since 1994, and it is why national and international companies choose us as a partner.
For more than twenty years, our work has been verifiable: vulnerabilities fixed by vendors, talks at international conferences, certifications and field results all tell the same story. It is the method we bring to every offensive security engagement.
If you want to understand how it can apply to your company, let’s talk.
The experience with ISGroup has made us grow as an organization, increasing awareness of cyber risks and skills to manage secure IT systems. We appreciated competence, autonomy, quality of reports and a truly customer-oriented approach.
Thanks to ISGroup SRL support we have consolidated an Integrated Management System compliant with international standards. Technical skills and targeted training have improved development processes, product security and audit management.
The collaboration with ISGroup SRL was highly constructive and allowed us to strengthen internal procedures. We have significantly improved the security of our software solutions and the ability to prevent major threats.