Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Mar 9, 2023

    CERT, CSIRT or SOC?

    CERT and CSIRT are often used synonymously describing incident response teams, while SOC has a broader cyber security scope.… read more »
  • Mar 9, 2023

    Bitwarden vulnerability allows attackers to steal passwords using iframes

    The popular open-source password management service, Bitwarden, offers an auto-fill feature that can automatically fill in users' saved credentials when they visit a website. However, this feature has a potentially dangerous behavior that could allow malicious iframes embedded in trusted… read more »
  • Mar 8, 2023

    Sharp Panda is starting to use a new version of the Soul framework

    Chinese threat actor Sharp Panda has targeted high-profile government agencies in Southeast Asia with a cyber espionage campaign using a new version of the Soul modular framework. … read more »
  • Mar 6, 2023

    MITIGA expose Google Cloud Platform's lack of forensic storage visibility

    A new report from cybersecurity firm MITIGA has revealed that malicious actors can exploit a lack of forensic visibility in Google Cloud Platform to exfiltrate sensitive data.… read more »
  • Mar 5, 2023

    CrowdStrike released the 2023 Global Threat Report

    CrowdStrike has released its 9th Annual Global Threat Report, which provides a comprehensive overview of threat actor behaviour, tactics and trends over the past year. The report is based on the activities of more than 200 cyber adversaries and covers… read more »
  • Mar 3, 2023

    CISA released DECIDER, an open source tool that helps generate MITRE ATT&CK mappings.

    The Cybersecurity and Infrastructure Security Agency (CISA) recently launched a free tool called Decider to help the cybersecurity community map threat actor behaviour to the MITRE ATT&CK Framework. … read more »
  • Mar 2, 2023

    Iron Tiger group creates Linux version of its custom malware

    According to research recently published by cybersecurity firm Trend Micro, Iron Tiger, a Chinese-speaking threat group known for targeting organisations in East Asia, has created a Linux version of its custom malware known as SysUpdate.… read more »
  • Feb 28, 2023

    Blind Eagle has reappeared with a refined toolset

    Blind Eagle, a financially motivated threat actor also known as APT-C-36, has launched attacks targeting organizations in Colombia and Ecuador since at least 2018. … read more »
  • Feb 26, 2023

    Latest PureCrypter campaign targets government organisations

    Researchers at Menlo Security have discovered that a threat actor is targeting government agencies in the Asia-Pacific and North American regions with the PureCrypter malware downloader. … read more »
  • Feb 24, 2023

    StealC: a new advanced infostealer

    Analysts at cybersecurity firm Sekoia have uncovered a new strain of malware called StealC, an advanced infostealer designed to steal sensitive data from victims.… read more »
  • Feb 23, 2023

    How to detect Brute Ratel activities

    Brute Ratel (BRc4) is a Command and Control (C2) framework designed to help attackers evade defence systems and remain undetected while executing malicious commands. Used in simulations of real-world attacks, this tool helps red team members deploy badgers on remote… read more »
  • Feb 22, 2023

    Many threat actors begin to adopt Havoc Framework

    A recent research by security company ZScaler, reports that threat actors are increasingly using the Havoc Framework for their malicious activities. … read more »
  • Feb 21, 2023

    WIP26: a new threat actor targeting telecom service providers

    A new threat actor, dubbed WIP26 by security firm Sentinel One, has recently been identified that is targeting government agencies and telecommunication service providers in the United States.… read more »
  • Feb 20, 2023

    Frebniis: new malware targets Microsoft IIS

    Recent research by security firm Symantec has uncovered a new strain of malware called FrebniiS that is specifically designed to target servers running Microsoft Internet Information Services (IIS) software.… read more »
  • Feb 18, 2023

    Some thoughts on MLOps security

    MLOps, which stands for Machine Learning Operations, is a relatively new field that focuses on the integration of machine learning models into the development and deployment processes of software applications. … read more »
  • Feb 16, 2023

    Beep, a new highly evasive malware

    Analysis by MinervaLabs has revealed a new type of malware called BEEP, a highly stealthy malware that can evade detection by most antivirus software.… read more »
  • Feb 14, 2023

    Clipboard malware found in 450+ PyPI Packages

    A new cybersecurity threat for Python developers has been reported, where malicious actors have published over 451 unique Python packages to the official Python Package Index (PyPI) repository. The aim is to infect developer systems with a clipboard-based crypto wallet… read more »
  • Feb 13, 2023

    How to build a Security Operations Center on a budget

    As organizations continue to face increasingly sophisticated cyber threats, the importance of having a robust SOC has become clear. However, for many organizations, the cost of setting up a SOC can be prohibitive, especially for small to medium-sized businesses.… read more »
  • Feb 12, 2023

    How to detect Sliver C2 framework activities

    Sliver is an open source cross-platform adversary emulation/red team framework, developed for penetration testing purposes but, as other similar softwares like Cobalt Strike, is also used by cybercriminals to malicious activities. … read more »
  • Feb 10, 2023

    Most hi-end Android devices sold in China have pre-installed malware

    A recent study by researchers at the University of Edinburgh and Trinity College Dublin has revealed that most of top-of-the-range Android devices sold in China are being shipped with spyware.… read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician