Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Nov 27, 2025

    How artificial intelligence is transforming incident response in security operations centers

    Imagine a Security Operations Center where analysts are drowning in thousands of alerts every day. It’s like trying to spot a single suspicious person in a crowded stadium while everyone is shouting for your attention at once. This is the… read more »
  • Nov 24, 2025

    Shai-Hulud strikes again: massive supply chain attack compromises Zapier, ENS, and hundreds of npm packages

    The software supply chain ecosystem faced another severe threat as security researchers at Aikido Security detected a second wave of the notorious Shai-Hulud malware campaign on November 24, 2025. This sophisticated attack compromised 425 npm packages with a combined 132… read more »
  • Nov 21, 2025

    Rust vs C++: a modern take on performance and safety

    … read more »
  • Nov 20, 2025

    OSINT and Artificial Intelligence: A New Era of Intelligence Gathering

    … read more »
  • Nov 19, 2025

    When security becomes the systemic risk: lessons from the Cloudflare outage

    … read more »
  • Nov 17, 2025

    Strategic disconnection: a guide to effective leadership

    … read more »
  • Nov 17, 2025

    Every log must fire: applying Chekhov's gun to cybersecurity incident reports

    … read more »
  • Nov 14, 2025

    The virtual CISO: a strategic security leadership for modern organizations

    … read more »
  • Nov 10, 2025

    How organizations can adopt AI security tools without losing control

    … read more »
  • Nov 5, 2025

    Setting standards for digital investigations in the age of open source intelligence

    … read more »
  • Nov 4, 2025

    The dangerous confidence gap in corporate cybersecurity

    There’s a peculiar comfort in believing you’re safe. In cybersecurity, that comfort might be the most dangerous vulnerability of all. Recent research from CrowdStrike reveals what security professionals have suspected for years: companies consistently overestimate their preparedness for cyber threats,… read more »
  • Nov 2, 2025

    Beyond incident response: measuring what never happened

    Prevention vs. Response: The Hidden Value Prevention (Invisible) 🛡️ Attacks blocked: 1,247 Time saved: 340 hours Cost avoided: $850K Business Impact: HIGH Incident Response (Visible) 🚨 Incidents handled: 3 Response time: 120 hours Actual cost: $420K Visibility: HIGH Which matters… read more »
  • Nov 1, 2025

    Why security teams struggle with motivation

    … read more »
  • Nov 1, 2025

    Chat control proposal fails again after massive public opposition

    The European Union's controversial Chat Control proposal has been withdrawn once again following intense public pressure. This marks another defeat for legislation that would have mandated scanning of encrypted messages across the EU.… read more »
  • Oct 24, 2025

    ChatGPT Atlas and the hidden privacy risks behind AI-powered browsing

    … read more »
  • Oct 21, 2025

    When compromised data becomes the invisible weapon: understanding threat intelligence poisoning

    The cybersecurity landscape has evolved beyond traditional attack vectors, with threat actors now targeting the very foundations of our defense mechanisms. Among these emerging threats, data poisoning in threat intelligence feeds represents a particularly insidious form of warfare that turns… read more »
  • Oct 20, 2025

    Exploiting data voids to weaponize Microsoft Copilot for malware distribution

    Recent research presented at DEFCON 33 has unveiled a sophisticated attack vector that exploits the inherent trust users place in AI assistants like Microsoft Copilot. … read more »
  • Oct 18, 2025

    North Korean hackers merge BeaverTail and OtterCookie malware

    North Korean state-sponsored hackers have significantly enhanced their malware arsenal by merging capabilities from two previously distinct malware families, creating a more sophisticated threat to organizations worldwide. This evolution represents a critical shift in the operational tactics of one of… read more »
  • Oct 17, 2025

    Operation Zero Disco: Cisco SNMP vulnerability exploited to deploy Linux rootkits

    Cybersecurity researchers have uncovered a sophisticated attack campaign targeting Cisco network devices through a critical SNMP vulnerability. The operation demonstrates how threat actors are exploiting enterprise infrastructure vulnerabilities to establish persistent access and deploy advanced rootkits on Linux-based systems. … read more »
  • Oct 17, 2025

    Indicators of leakage: DLP is having its EDR moment

    Traditional data loss prevention systems have reached their breaking point. After years of relying on rigid policies and keyword matching, organizations continue to experience devastating data breaches despite investing millions in DLP solutions. The industry now stands at a critical… read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician