ISGroup history

From the underground to certified security

About Us / History
Cybersecurity since 2005

Before protecting companies, we found vulnerabilities in software used by millions of people. Vendors fixed them one by one. Today, the same methodology guides the Penetration Tests we perform for companies, banks and public administrations.

ISGroup SRL is an Italian Offensive Security company based in Verona, specialized in Penetration Testing, Vulnerability Assessment, Code Review and Red Team activities. The ISGroup brand was born in 2005 from the experience of USH.it, an independent security research group founded in 2000, and the company is certified ISO/IEC 27001 and ISO 9001. The team has published more than 30 security advisories with CVEs assigned on software from international vendors such as PHP, Mozilla Firefox, Nginx, Jetty, Zabbix, Veeam, QNAP and Fortinet, and has worked for organizations such as Nestlé, Coop Italia, UBI Banca, Mediaset and the Italian Public Administration.

The method has a name: responsible disclosure. Each flaw is reported to the vendor before publication. The same ethics guide our Ethical Hacking and vulnerability research activities today. This page proves it, date by date.

ISGroup in numbers

Security is not declared. It is proven.

Independent research since 2000, brand since 2005: public advisories, assigned CVEs and vulnerabilities fixed by vendors. Fully verifiable.

2000
Independent research
Active since 2000 with the USH.it project.
2005
Company
ISGroup since 2005, SRL since 2013.
30+
Security advisories
Public, on Bugtraq, Full Disclosure and Packetstorm.
20+
Assigned CVEs
Vulnerabilities fixed by vendors, not just reported.
9M+
Affected systems
Vulnerabilities in PHP, Mozilla, Veeam, QNAP and Fortinet.
15+
Certifications
ISO 27001, ISO 9001 and professional certifications.
8+
Disclosure channels
Bugtraq, Full Disclosure and international conferences.
98+
International mentions
DEF CON 31, NVD, Exploit-DB, Red Hat and white papers.

We've worked with

Nestle UBI Banca Libero Mediaset Repubblica Italiana Subito
  • 1994

    Roots in the underground

    With the arrival of dial-up connections, the future founders of ISGroup spent their nights in Italian hacker communities learning how systems really worked. The rule was clear: find flaws with original techniques, never exploit them, and understand them deeply enough to make systems safer.

  • 2000

    USH.it is born

    Francesco "ascii" Ongaro founded USH.it with other researchers: an independent hacking and security research group. USH.it is still active today as ISGroup’s non-commercial laboratory, and every advisory published there is freely available.

  • 2005

    ISGroup is born

    The ISGroup brand was born in 2005. That same year saw the first public security advisories on Bugtraq and Full Disclosure and the first CVEs, starting with CVE-2005-3366. Since then, every discovered flaw has been reported to the vendor first and disclosed in a coordinated way. The research has never stopped.

  • 2008

    On the Chaos Communication Congress stage

    The team brought its research to 25C3 in Berlin, Europe’s most important hacker conference, and taught penetration testing and web application security at the University of Pisa. Being selected for the Chaos Communication Congress means passing an international selection and standing alongside some of the continent’s best researchers. That research on PHP and web security is still cited today: in international whitepapers, by Red Hat and, in 2023, at DEF CON 31.

  • 2010

    Cyber Threat Intelligence and Early Warning

    The offering expanded to Cyber Threat Intelligence and Early Warning services thanks to a direct connection with the underground research community. The consulting work served leading global security vendors.

  • 2013

    ISGroup SRL, and research reaches the Swiss press

    ISGroup SRL was incorporated in Verona; its first financial year closed with EBT equal to 65% of revenues. In the same year, the investigation into SCADA industrial systems exposed on the Internet, conducted with journalists from SonntagsZeitung and Le Matin, demonstrated the real-world risks affecting critical infrastructure. From independent laboratory to partner for companies and institutions.

  • 2014

    From service to product

    To increase the efficiency of verification activities, ISGroup began developing proprietary software to support security testing. The EasyAudit spin-off brought penetration testing within reach of SMEs, while the topic of digital surveillance reached prime time on Italia Uno with Ongaro’s appearance on "Mistero" (Mediaset).

  • 2015

    CVE-2015-5742 and the International Journalism Festival

    The team discovered a critical privilege escalation in Veeam Backup & Replication (CVE-2015-5742), software present in most VMware and Hyper-V environments at the time. The vendor fixed the flaw. This is what matters to a customer: finding vulnerabilities before someone exploits them. During the same period, ISGroup presented the hacking landscape at the International Journalism Festival in Perugia, where it returned in 2016.

    See how we work during a Penetration Test

  • 2020

    ISO/IEC 27001 certification

    ISGroup obtained ISO/IEC 27001 certification for information security management: the same standards we verify for customers are applied to and audited on our own processes. For those who choose us, this means a supplier that can be qualified in regulated supply chains.

  • 2021

    ISO 9001 certification

    Quality joined security: ISO 9001 certification formalized control over methodologies, delivery times and project management. Both certifications are issued by IMQ with IQNET recognition and renewed at every audit cycle.

  • 2025

    A national RCE and international press

    ISGroup research identified critical vulnerabilities in GoSign Desktop, a digital signature software widely used in Italy, allowing remote code execution (CVE-2025-34324, CVE-2025-34327). In the same year, expansion toward English-speaking markets was covered by outlets such as The Globe and Mail and Digital Journal.

  • 2026

    In January 2026, the team published a new advisory on Ninja Forms, a WordPress plugin with hundreds of thousands of installations. Vulnerability research continues to feed our services: every technique discovered in our labs becomes one more control in the Penetration Tests we deliver. It has been this way since 1994, and it is why national and international companies choose us as a partner.

Many companies work in Cybersecurity. Few have contributed to public security research for 20 years.
We discover vulnerabilities in software used by millions of people.
Research-born methodologies become concrete controls on our customers’ systems.
Official recognition for security and quality

Our Certifications

IQNET CertificationIMQ ISO/IEC 27001:2022ISO/IEC 9001:2015 Certification

For more than twenty years, our work has been verifiable: vulnerabilities fixed by vendors, talks at international conferences, certifications and field results all tell the same story. It is the method we bring to every offensive security engagement.

If you want to understand how it can apply to your company, let’s talk.

Brochure

The experience with ISGroup has made us grow as an organization, increasing awareness of cyber risks and skills to manage secure IT systems. We appreciated competence, autonomy, quality of reports and a truly customer-oriented approach.

Giampietro Calabrese
Giampietro Calabrese

Add Value S.r.l.

Thanks to ISGroup SRL support we have consolidated an Integrated Management System compliant with international standards. Technical skills and targeted training have improved development processes, product security and audit management.

Stefano Luzi Crivellini
Stefano Luzi Crivellini

Creactives S.p.A.

The collaboration with ISGroup SRL was highly constructive and allowed us to strengthen internal procedures. We have significantly improved the security of our software solutions and the ability to prevent major threats.

Giovanni Cardarelli
Giovanni Cardarelli

ISWEB S.p.A.


🎉 We want to talk to you! Book an appointment!