Please turn JavaScript on

Andrea Fortuna

Want to stay in touch with the latest updates from Andrea Fortuna? That's easy! Just subscribe clicking the Follow button below, choose topics or keywords for filtering if you want to, and we send the news to your inbox, to your phone via push notifications or we put them on your personal page here on follow.it.

Reading your RSS feed has never been easier!

Website title: Andrea Fortuna | Cybersecurity expert, software developer, experienced digital forensic analyst, musician

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.37 / day

Message History

I read the story of Brandon Klayme twice, and the second time I found myself doing something I rarely do while reading about a legal case: I opened my own list of old accounts and started deleting things. Not because I was scared of ending up in an interrogation room. Because the case reminded me, with an almost physical discomfort, of how thin the thread is between “identifi...


Read full story

Windows has trusted VHD files for over a decade. Since Windows 8, double-clicking one mounts it as a logical volume with no warning dialog, no “are you sure,” nothing. It behaves like opening a ZIP archive, except what’s inside can now touch kernel memory directly. That trust model just got a fresh reminder of why it deserves scrutiny: three new vulnerabilities in the NTFS dr...


Read full story

This week, the White House formally authorized private U.S. companies to hack foreign criminal networks, a memo that does not so much create a new capability as acknowledge one that has been building quietly for years. The same week, researchers at Israeli firm Dream observed the first near-autonomous AI attack on a government target, while SentinelLabs published a frame...


Read full story

Every August, without exception, someone’s SOC dashboard turns red at 3 a.m. while the two people who actually know how to respond are on a beach or a ferry, phone on airplane mode, out of office autoreply cheerfully promising a response “as soon as possible.” Attackers know this. They have known it for years, and they plan around it with the same discipline that legitimate b...


Read full story

GitHub rejected it. eBay accepted it, at least until someone told them not to. Same cryptographically valid, silently forged authentication assertion, two completely different outcomes, because one relying party actually checked a single bit in the response and the other didn’t. That bit is the whole story of why passkeys, the technology everyone was told would finally kill c...


Read full story