Andrea Fortuna
Andrea Fortuna — Cybersecurity expert and digital forensics analyst
Cybersecurity expert, software developer, experienced digital forensic analyst, musician
andreafortuna.orgMost organizations don't fail at security because they lack tools, they fail because they can't sustain attention at 2:00 AM.
A cybersecurity blog that bridges the gap between hands-on technical analysis and strategic thinking. Andrea writes about everything from iOS forensics to building 24/7 security operations on small teams, often opening with real-world scenarios that pull you into complex topics. His European perspective on security regulation and infrastructure adds a dimension you won't find on most infosec blogs.
Written by Andrea Fortuna.
Very Active
Publishes multiple times per week
3
Independent Blog
English
How this blog's content is accessed through Blogs Are Back.
Full Content
RSS feed includes complete post content for reading in-app
Direct Access
Feed can be fetched directly from your browser
Direct Post Links
Post pages can be loaded directly in the reader
Embeddable
Posts can be displayed inline in the reader view
Recent posts from Andrea Fortuna's RSS feed.
When the web shell isn’t on disk: the F5 BIG-IP rootkit that lives in memory
A web shell normally leaves something behind. A PHP file, a timestamp, a suspicious parameter, perhaps an eval() buried in a directory that nobody remembers creating. Investigators hunt for these artifacts because they anchor the investigation to the filesystem, where tools are mature and evidence is relatively stable. Now imagine opening the filesystem and finding nothing. The PHP files are legitimate. Their hashes match known-good versions. File integrity monitoring shows no changes. Yet A...
Weekly Wire #9: The Patch Race Tightens
The week’s loudest number was Microsoft’s: 974 patches in a single batch, and the 2026 year-to-date total already more than doubles the entire output of the record year 2020, with three months still to go. The more telling number was smaller: four espionage groups, one shared exploit chain, and a window measured in days between upstream fixes and weaponized attacks. When the patches themselves start breaking Remote Desktop Services, the defender’s problem stops being finding the needle and start...
Apple’s Audio Intelligence turns your watch into something that listens all day
There is a specific kind of Apple keynote moment where a feature gets announced with a straight face and a privacy paper gets published on the same day, as if the second document were meant to pre-empt the first hour of press coverage. That is roughly what happened with Audio Intelligence, the new suite of always-on listening features Apple introduced for Apple Watch Series 12 and Apple Watch Ultra 4. The watch now summarizes your conversations, lets you rewind the last fifteen seconds of what s...
Panzer ransomware: a new RaaS hits Italian manufacturers and telecom providers
Italian ransomware activity crossed a threshold in early September. According to Ransomfeed, claims against Italian organizations reached 212 for the year to date, already surpassing the 169 recorded in all of 2025. Into this acceleration stepped Panzer, a ransomware-as-a-service operation that appeared on August 5 and within a month had published victims across eleven countries. Two of them were Italian: a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro. T...
Weekly Wire #8: When Trust Chains Break
The week’s readings share a quieter, more structural alarm: the chains of trust we build (identity verifiers, home routers, blockchain ledgers, edge appliances, coding platforms) keep turning into the very thing that lets attackers in. Krebs spent the week tracing 153 million driver’s licenses back to the moments people handed their IDs to a rental counter or a dispensary scanner. Separately, ClickFix operators realized Polygon’s immutability makes it a better C2 layer than any domain they could...
If you enjoy Andrea Fortuna, you might also like these blogs.

Troy Hunt
troyhunt.comSecurity researcher and creator of Have I Been Pwned. Expert analysis on data breaches and web security.
Filippo Valsorda
words.filippo.ioGo security team member writing about cryptography and open source maintenance.

Robert Heaton
robertheaton.comThoughtful essays on programming, security, and the human side of software.

Perishable Press
perishablepress.comWeb Dev + WordPress + Security
Follow Andrea Fortuna
Whether you're a security practitioner or just trying to understand the threat landscape, Andrea breaks down complex security topics with real-world clarity.