Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Jan 23, 2020

    DevSecOps: the value of "Security Champions"

    In a previous article [1], I've started to talk about DevSecOps and the concept of "shifting left" security.In order to move security checks to the early steps of development, a great help may be the presence of a security-aware person… read more »
  • Jan 22, 2020

    FBI got data from a locked iPhone 11 using GrayKey: how does this tool work?

    The recent deadly shooting last month at a naval air station in Pensacola, Fla., brought in the spotlight the issue of iOS security: attorney General William P. Barr requested Apple to provide access to two phones used by the killer.… read more »
  • Jan 21, 2020

    Security researcher found a hardcoded SSH Key in Fortinet SIEM appliances

    Security researcher Andrew Klaus, from Cybera, discovered a hardcoded SSH public key in Fortinet’s Security Information and Event Management FortiSIEM that can be used in order to generate a denial of service against the FortiSIEM Supervisor. Fortinet devices share the… read more »
  • Jan 16, 2020

    CVE-2020-0601: a critical Windows vulnerability discovered by...NSA!

    Recently, Microsoft released a patch that fixes a critical vulnerability in the Windows' crypto library. According to the advisory [1]: A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit… read more »
  • Jan 15, 2020

    Some thoughts about "Shift Left" security in DevSecOps

    A popular term in DevOps context is “shift left”: it refers to the effort by a DevOps team to implement measures to guarantee application quality at the most early point in the software development life cycle. In a application security context,… read more »
  • Jan 14, 2020

    CVE-2019-19781: my clippings on the infamous Citrix Netscaler vulnerability

    Many Proof-of-concept exploits has been released for the unpatched remote-code-execution vulnerability in the Citrix Application Delivery Controller and Citrix Gateway products. Below a list of useful links/quotes/posts on this topic. The vulnerability The vulnerability (CVE-2019-19781), already packs a double-punch in… read more »
  • Jan 10, 2020

    iOS Forensics: BFU (Before First Unlock) acquisition, using checkra1n

    iOS forensic is quite complex: in many cases, jailbreaking is the only way to gather all most information available in iOS devices. Ok, logical acquisition is easy, safe and it always works: however, this kind of acquisition mostly gives you… read more »
  • Jan 9, 2020

    TikTok fixed several vulnerabilities that could allow hijacking of any account

    Security experts from CheckPoint discovered multiple vulnerabilities in the popular TikTok app that could be chained by remote attackers to hijack any user accounts, execute malicious code on the target system and perform unwanted actions. Those vulnerabilities (that includes SMS… read more »
  • Jan 8, 2020

    Some thoughts about smartphones data extraction

    In an interesting article, editors by Privacy International examines some aspects of digital forensics on mobile phones, from the acquisition process to the data analysis phase. All the topics in the article [1] has been discussed in detail in the… read more »
  • Jan 3, 2020

    Ring camera accounts breach: Amazon blames users, EFF respond!

    Recently, digital intruders entered the Ring surveillance camera in the bedroom of an 8-year-old girl in Mississippi and started talking to her [1], then various other intrusions took place and it emerged that 3600 e-mail addresses, passwords, localizations and other… read more »
  • Jan 2, 2020

    Happy Birthday, Isaac Asimov!

    100 years ago, Isaac Asimov was born: was one of the writers who brought science fiction out of its niche market and a great scientific popularizer with many articles and essays. His legacy is estimated in about 500 books of… read more »
  • Jan 1, 2020

    Millennium Bug, 20 years on: a disaster that never happened... or not?

    20 years ago the entire world was afraid to descend into chaos as a result of computers not being able to cope with displaying a date containing year 2000: both computer experts and general public alike were convinced that computers… read more »
  • Dec 24, 2019

    The Hitchhiker's Guide To The Galaxy: the Christmas Special

    “The Hitchhiker’s Guide to the Galaxy” is a cultural icon in science-fiction that spawned  five books, stage shows, a 1981 TV series, a computer game, comic books and a major motion picture. But originally it was just a radio comedy… read more »
  • Dec 23, 2019

    Privileged containers in Docker? A bad idea!

    By default, containers run in unprivileged mode, that is, we cannot run Docker daemon inside a Docker container. However, a privileged Docker container is allowed to access to all the devices on the host woth the same privileges of the… read more »
  • Dec 20, 2019

    Pockint: a portable OSINT Swiss Army Knife

    POCKINT stands for “Pocket Intelligence”. It is an OSINT multi purposes GUI program designed to be a lightweight and portable. … read more »
  • Dec 19, 2019

    Cybersecurity Trends for 2020

    According to a TrendMicro’s report, ‘The New Norm’, the major cybersecurity risks for organizations in 2020 comes from DevOps, third-party libraries, container components and even remote workers. … read more »
  • Dec 18, 2019

    BreakingApp: a vulnerability in WhatsApp let one message render the app unusable for entire groups

    Security research group Check Point Research recently uncovered a flaw in WhatsApp through which a single malicious user could crash the apps of all members of a group chat. … read more »
  • Dec 17, 2019

    IBM System/360: the turning point

    Some days ago, I’ve been looking at a website named “IBM 360 Model 20 Rescue and Restoration”: a group of brave engineer started the project of restoration of an IBM System 360 Model 20, documenting all steps of the process.… read more »
  • Dec 13, 2019

    Google and Facebook surveillance threatens human rights, Amnesty International says

    Google and Facebook help connect the world and provide crucial services to billions users, but this services come at a systemic cost. … read more »
  • Dec 12, 2019

    PenTest Chronicles: a mistery box on a ship

    British security firm Pen Test Partners tells us a creepy cybersecurity story set in a place difficult to associate with computers: the engine room of a ship. … read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician