Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Feb 21, 2023

    WIP26: a new threat actor targeting telecom service providers

    A new threat actor, dubbed WIP26 by security firm Sentinel One, has recently been identified that is targeting government agencies and telecommunication service providers in the United States.… read more »
  • Feb 20, 2023

    Frebniis: new malware targets Microsoft IIS

    Recent research by security firm Symantec has uncovered a new strain of malware called FrebniiS that is specifically designed to target servers running Microsoft Internet Information Services (IIS) software.… read more »
  • Feb 18, 2023

    Some thoughts on MLOps security

    MLOps, which stands for Machine Learning Operations, is a relatively new field that focuses on the integration of machine learning models into the development and deployment processes of software applications. … read more »
  • Feb 16, 2023

    Beep, a new highly evasive malware

    Analysis by MinervaLabs has revealed a new type of malware called BEEP, a highly stealthy malware that can evade detection by most antivirus software.… read more »
  • Feb 14, 2023

    Clipboard malware found in 450+ PyPI Packages

    A new cybersecurity threat for Python developers has been reported, where malicious actors have published over 451 unique Python packages to the official Python Package Index (PyPI) repository. The aim is to infect developer systems with a clipboard-based crypto wallet… read more »
  • Feb 13, 2023

    How to build a Security Operations Center on a budget

    As organizations continue to face increasingly sophisticated cyber threats, the importance of having a robust SOC has become clear. However, for many organizations, the cost of setting up a SOC can be prohibitive, especially for small to medium-sized businesses.… read more »
  • Feb 12, 2023

    How to detect Sliver C2 framework activities

    Sliver is an open source cross-platform adversary emulation/red team framework, developed for penetration testing purposes but, as other similar softwares like Cobalt Strike, is also used by cybercriminals to malicious activities. … read more »
  • Feb 10, 2023

    Most hi-end Android devices sold in China have pre-installed malware

    A recent study by researchers at the University of Edinburgh and Trinity College Dublin has revealed that most of top-of-the-range Android devices sold in China are being shipped with spyware.… read more »
  • Feb 8, 2023

    Russian threat group steal screenshots from victims devices

    A Russian threat group, dubbed TA866 by Proofpoint, is suspected of using a new technique to steal sensitive information. The group has been taking screenshots of infected devices and uploading them to a remote server.… read more »
  • Feb 7, 2023

    First Linux version of Clop ransomware has flaw in encryption algorithm

    The first Linux version of the Clop ransomware has been discovered, with a flaw in its encryption algorithm that allows it to be decrypted without paying the ransom.… read more »
  • Feb 6, 2023

    GuLoader: new version uses Nullsoft Scriptable Install System

    Several e-commerce industries in South Korea and the United States are being targeted by a GuLoader malware campaign, according to a report from cybersecurity firm Trellix. … read more »
  • Feb 3, 2023

    When the sunlight shines through the leaves of trees

    I have released my new musical work, Komorebi: a 4-track album that explores the world of electronic, lo-fi music, with each track designed to create a relaxing and peaceful atmosphere… read more »
  • Feb 2, 2023

    Prilex malware evolves to target NFC-enabled POS

    Kaspersky Lab cybersecurity experts have discovered a new version of the Prilex point-of-sale (PoS) malware that has been enhanced to target transactions using NFC technology … read more »
  • Feb 1, 2023

    NIST releases new framework for responsible use and development of AI

    The National Institute of Standards and Technology (NIST) has released the Artificial Intelligence Risk Management Framework which provides guidelines for organizations to manage risks and promote responsible use of AI systems. … read more »
  • Jan 31, 2023

    TrickGate: a shellcode-based packer undetected for years

    TrickGate is a shellcode-based packer that has been operating successfully and undetected for over six years. … read more »
  • Jan 30, 2023

    UNC2565: New enhancements to GOOTLOADER malware

    The UNC2565 group behind the GOOTLOADER malware continues to improve its code by adding new components and obfuscation techniques to evade detection. … read more »
  • Jan 28, 2023

    SwiftSlicer: a new Golang-based wiper malware

    Cyber security firm ESET has reported that Ukraine has been hit by a new cyber attack from Russia using a previously undocumented data wiper called SwiftSlicer. … read more »
  • Jan 27, 2023

    New PlugX malware variant spreads via removable USB storage devices

    Cyber-security researchers at Palo Alto Networks’ Unit 42 have discovered a new variant of the PlugX malware that can infect connected USB removable media devices to spread to additional systems.… read more »
  • Jan 25, 2023

    PY#RATION: new Python-based malware

    Researchers at threat analytics firm Securonix have uncovered a new Python-based malware named PY#RATION, a remote access trojan (RAT) that gives its operators control over breached systems… read more »
  • Jan 25, 2023

    Static malware analysis: a basic workflow

    Static malware analysis is the process of analysing malware samples without executing them. In this post, I'd like to share my basic workflow for static malware analysis, with tools and techniques that can be used at each stage.… read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician