Blog Directory
Directory Blog
A

Andrea Fortuna

Andrea Fortuna — Cybersecurity expert and digital forensics analyst

Cybersecurity expert, software developer, experienced digital forensic analyst, musician

Most organizations don't fail at security because they lack tools, they fail because they can't sustain attention at 2:00 AM.

andreafortuna.org

A cybersecurity blog that bridges the gap between hands-on technical analysis and strategic thinking. Andrea writes about everything from iOS forensics to building 24/7 security operations on small teams, often opening with real-world scenarios that pull you into complex topics. His European perspective on security regulation and infrastructure adds a dimension you won't find on most infosec blogs.

Written by Andrea Fortuna.

About This Blog
Activity

Very Active

Publishes multiple times per week

Followers

3

Category

Independent Blog

Languages

English

Feed Accessibility

How this blog's content is accessed through Blogs Are Back.

Full Content

RSS feed includes complete post content for reading in-app

Direct Access

Feed can be fetched directly from your browser

Direct Post Links

Post pages can be loaded directly in the reader

Embeddable

Posts can be displayed inline in the reader view

Latest Posts

Recent posts from Andrea Fortuna's RSS feed.

When the web shell isn’t on disk: the F5 BIG-IP rootkit that lives in memory

A web shell normally leaves something behind. A PHP file, a timestamp, a suspicious parameter, perhaps an eval() buried in a directory that nobody remembers creating. Investigators hunt for these artifacts because they anchor the investigation to the filesystem, where tools are mature and evidence is relatively stable. Now imagine opening the filesystem and finding nothing. The PHP files are legitimate. Their hashes match known-good versions. File integrity monitoring shows no changes. Yet A...

Weekly Wire #9: The Patch Race Tightens

The week’s loudest number was Microsoft’s: 974 patches in a single batch, and the 2026 year-to-date total already more than doubles the entire output of the record year 2020, with three months still to go. The more telling number was smaller: four espionage groups, one shared exploit chain, and a window measured in days between upstream fixes and weaponized attacks. When the patches themselves start breaking Remote Desktop Services, the defender’s problem stops being finding the needle and start...

Apple’s Audio Intelligence turns your watch into something that listens all day

There is a specific kind of Apple keynote moment where a feature gets announced with a straight face and a privacy paper gets published on the same day, as if the second document were meant to pre-empt the first hour of press coverage. That is roughly what happened with Audio Intelligence, the new suite of always-on listening features Apple introduced for Apple Watch Series 12 and Apple Watch Ultra 4. The watch now summarizes your conversations, lets you rewind the last fifteen seconds of what s...

Panzer ransomware: a new RaaS hits Italian manufacturers and telecom providers

Italian ransomware activity crossed a threshold in early September. According to Ransomfeed, claims against Italian organizations reached 212 for the year to date, already surpassing the 169 recorded in all of 2025. Into this acceleration stepped Panzer, a ransomware-as-a-service operation that appeared on August 5 and within a month had published victims across eleven countries. Two of them were Italian: a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro. T...

Weekly Wire #8: When Trust Chains Break

The week’s readings share a quieter, more structural alarm: the chains of trust we build (identity verifiers, home routers, blockchain ledgers, edge appliances, coding platforms) keep turning into the very thing that lets attackers in. Krebs spent the week tracing 153 million driver’s licenses back to the moments people handed their IDs to a rental counter or a dispensary scanner. Separately, ClickFix operators realized Polygon’s immutability makes it a better C2 layer than any domain they could...

Follow Andrea Fortuna

Whether you're a security practitioner or just trying to understand the threat landscape, Andrea breaks down complex security topics with real-world clarity.

https://andreafortuna.org/feed.xml