| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Christopher Eng at Ogmini
-
Dr. Brian Carrier at Cyber Triage
SANS vs SKL DFIR AI Frameworks: When to Use Each -
Elcomsoft
-
Forensafe
Android Google Pay Account -
LEAPPs Blog
-
Magnet Forensics
Introducing Time-Based Metadata: Unlocking a new layer of data in media forensics -
Tim Korver at ‘Thesis Friday’
Thesis Friday #21: Why a single artifact never tells the whole story
Threat hunting/threat intelligence
-
Amnesty International Security Lab
Inside Pegasus: The evolution of the world’s most notorious spyware system -
Any.Run
-
ASEC
-
Francis Guibernau at AttackIQ
Response to CISA Advisory (AA26-194A): Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting -
Christine Barry at Barracuda
None and done? kittykatkrew’s short-lived ransomware play -
Eric J. Taylor at Barricade Cyber Solutions
CTI Report: BRG-26182 Chains a Fake Human-Check to Microsoft 365 AiTM Session Theft -
Ben Bornholm at HoldMyBeer
Hunting malware and malicious MCPs in memory on Kubernetes with FleetDM + Osquery + YARA -
Bitdefender
-
Brad Duncan at Malware Traffic Analysis
2026-05-27: SmartApeSG ClickFix –> Unidentified RAT –> NetSupport RAT -
Brian Krebs at ‘Krebs on Security’
-
Bridewell
From a Fake IT Ticket to Scattered Spider: Inside a Com-Affiliated Vishing Campaign -
BushidoToken
UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters -
CERT Ukraine
Вектори первинної компрометації UAC-0145 станом на липень 2026 року -
CERT-AGID
-
Check Point
-
CISA
-
Cisco’s Talos
-
Marie Mamaril at Cofense
When Routine Becomes the Threat: The Evolution of Finance-Themed Phishing -
Ctrl-Alt-Intel
Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links -
Cyb3rhawk
Part 1: Measuring LLM Breach Hunters; Sharing, Provenance, and Blind Spots -
Christophe Tafani-Dereeper, Sebastian Obregoso, and Eslam Salem at Datadog Security Labs
Compromised AsyncAPI packages on npm deliver malware -
Rohitashokgowd at Detect FYI
You Assume Your Logs Are Flowing. -
Disconinja
-
Elastic Security Labs
-
Aaron Walton at Expel
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident -
Oleg Lypko at Flare
Arrest and Sentencing Disparities Across Russian-Speaking Threat Actors -
Flashpoint
-
Sai Molige at Forescout
SeasonalInvite: New Phishing Campaign Abuses eCards and RMM -
Google Cloud Threat Intelligence
-
Group-IB
-
Hornet Security
Kali365-Gerätecode-Phishing verwandelt einen Zahlungsköder in den Diebstahl von Microsoft-365-Tokens -
Reegun Jayapaul, Rahul Ramesh, and Baskar M at Howler Cell
DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel -
Hugging Face
Security incident disclosure — July 2026 -
Harlan Carvey and Lindsey O’Donnell-Welch at Huntress
Threat Actors Achieve Persistence After SQL Injection -
Tom Kopchak at Hurricane Labs
The DOJ Just Proved that Windows is Spying on You -
InfoSec Write-ups
-
Intel 471
-
Yuma Masubuchi at JPCERT/CC
Update on Attacks by Threat Group APT-C-60 in 2026 -
LevelBlue SpiderLabs
-
Microsoft Security
-
Ariel Parnes at Mitiga
The Logs We’ve Never Had: J-Space and the Next Layer of Detection -
Moonlock Lab Team at Moonlock
Moonlock’s mid-2026 macOS threat report -
Eugenio Benincasa at Natto Thoughts
China’s Cybersecurity Powerhouses Face PLA Procurement Curbs -
Stephanie Kirmer at Nebulock
Classical ML for threat hunting, not just an LLM -
Yuki Umemura at Nicter
7-Zip攻撃キャンペーンのインフラ調査によるドメインの発見 -
NSB Cyber
#NSBCS.133 – Who Did It? The Cost of Getting Ransomware Attribution Wrong -
Brett Winterford at Okta
How to stop attackers from self-serving their way into accounts -
Oleg Skulkin at ‘Know Your Adversary’
-
OpenSourceMalware
-
Palo Alto Networks
-
Benjamin Adolphi at Promon
App Threat Report Q2 2026: Coretax Android Banking Malware -
Rachel Rabin at Proofpoint
OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration -
Pulsedive
Blind Spots in the Build: A Supply Chain & SBOM Security Primer -
Qi’anxin X Lab
NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era -
Jan Blažek at Rapid7
Investigating Persistence Mechanisms in AWS -
ReliaQuest
-
Resecurity
From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks -
Ridgeline Cyber
Your Sigma Rule Converts Cleanly and Still Never Fires. Here’s the Test That Catches It. -
SANS Internet Storm Center
-
Securelist
-
Marco Pedrinazzi at SecurityBreak
The Payload Is in the Header -
Sarah Gooding at Socket
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping -
SOCRadar
Dark Web Profile: Krybit Ransomware -
Sophos
The State of Ransomware 2026: Payments are dropping but encryption is climbing -
Sujay Adkesar
Prefetch Alternate Data Stream How Malware Hides Execution -
Marco A. De Felice aka amvinfe at SuspectFile
Hyflock and Nova: A Private Conversation Provides a Glimpse into Ransomware Group Dynamics -
Sygnia
Ransomware Incident Response in 2026: What Has Changed and What CISOs Are Still Getting Wrong -
Symantec Enterprise
-
Sysdig
No single pane of glass: Anatomy of an Azure permission takeover -
Nchiminyi Jezreel at System Weakness
What Your PHP Logs Actually Look Like During an SQL Injection Attack -
The Raven File
KUDANKULAM NUCLEAR POWER PLANT LEAK: AN ACCIDENTAL DISCLOSURE -
James McMurry at ThreatHunter AI
July 2026 Patch Tuesday: 570 Patches, and the One That Matters Is Rated Moderate -
Joseph C Chen, Philippe Lin, Lucas Silva, Vladimir Kropotov, and Fyodor Yarochkin at Trend Micro
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet -
Justin Mahon at TrustedSec
Pandora’s Container Part 1: Unpacking Azure Container Security -
Sean Koessel and Steven Adair at Volexity
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation -
Martin Smolár at WeLiveSecurity
Forgotten UEFI shims undermining Secure Boot -
Rami McCarthy and Merav Bar at Wiz
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions -
Kim Zetter at Zero Day
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals -
Ruchna Nigam at ZScaler
ClaudeFix: Shared Claude Chats Meet ClickFix -
Блог Solar 4RAYS
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-07-13 -
Eclypsium
Living on the Edge: How Threat Actors Use Network Infrastructure Against You -
Huntress
-
John Hammond
Payload Podcast 009 – Steven Flores
Presentations/podcasts
-
ADF Solutions
Maximizing Efficiency with Preview Mode: A Guide for Digital Forensics Professionals -
Behind the Binary by Google Cloud Security
EP27 The Challenges of Reversing Modern Languages: From C++ to Go and Rust with Jae Young Kim -
Black Hat
Black Hat Stories | Shanna Daly, CEO of Torin Cyber Group -
Black Hills Information Security
What Is WebView2? From “Proxy Execution with Microsoft Edge WebView2 – Matthew Eidelberg” -
InfoSec_Bret
IR – SOC327 – Suspicious Docker Image Creation Detected -
Insane Forensics
The Anatomy of an OT Cybersecurity Flyaway Kit -
Microsoft Threat Intelligence Podcast
Behind the Book: Threat-Driven Software Development -
Monolith Forensics
-
OpenSourceMalware
The OpenSourceMalware Show #13 -
Paraben Corporation
Zandra AI ver 2 Overview -
Team Cymru
ORB Networks, Ceasefire Cyber Warfare, and AI Infrastructure Exploits -
The Defender’s Advantage Podcast
Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows -
THE Security Insights Show
The AI & Security Insights Show – We’ll be back! -
Three Buddy Problem
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack
Malware analysis
-
0day in {REA_TEAM}
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India) -
Aikido
-
Esentire
DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150’s Evolving Tradecraft -
Yurren Wan at Fortinet
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader -
Genians
Operation Capsule Vault: EMBED_PAYLOAD_v2 기반 RokRAT 공격 체인 분석 -
Thijs Xhaflaire at Jamf
CrashStealer: C++ macOS infostealer posing as crash reporter -
Chris Navarrete, Asher Davila and Doel Santos at Palo Alto Networks
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development -
ReversingLabs
-
Seqrite
-
Socket
-
Step Security
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories -
Zhassulan Zhussupov
Malware development trick 60: Function stomping (remote process). Simple C example
Miscellaneous
-
Gerard Johansen at Black Hills Information Security
KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet -
Brett Shavers at ‘The X-Ways Forensics Practitioner’s Guide/2E’
The X-Ways Forensics Practitioner’s Course Is Retiring -
Damien Lewke
A Test in Time -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 07/13/26 -
Martin Korman at DFIR Dudes
regipy-rs: Parsing a SOFTWARE Hive in 0.3 Seconds Instead of 12 Minutes -
Magdalena Karwat at EclecticIQ
EclecticIQ MCP Server: Connect your AI agents directly to your threat intelligence -
Forensic Focus
- Digital Forensics Jobs Round-Up, July 13 2026
- Katelyn Rogers, Digital Forensic Analyst, Mississippi Cyber Initiative
- The End Of Manual Transcription Starts Here
- Forensic Focus Briefs National Policing and Forensic Bodies on Investigator Well-Being
- Want To Put An End To Manual Transcribing? Watch S21 Transcriber v2.0 In Action
-
Alexis Brignoni at LEAPPs Blog
Be Careful What You Wish For -
Matthew Plascencia
The Real Hacking of Forensic Investigation: Hashcat -
Vaishnavi M.A. at Paraben Corporation
Transition from Traditional Forensic Science to Digital Forensics: Challenges, Lessons, and Opportunities -
Sandfly Security
-
Seth Enoka
GCFE vs GCFA: What Actually Changes (and When You’re Ready) -
Ryan G. Cox at The Cybersec Café
Building an Agentic SOC
Software releases/updates
-
Digital Sleuth
winfor-salt v2026.11.18 -
Doug Burks
so-crates v2.0.0 -
Elcomsoft
Elcomsoft Phone Breaker 11.03: universal binary for Macs, SMS two-factor authentication restored -
Ghassan Elsman
Crow-Eye v0.12.5 -
Renaud Tabary at MALCAT
0.9.15 is out: capa scanning at native speed -
Martin Korman
-
Metadata Forensics
HEART Version 2.1.0.0 -
Metaspike
FEC Remote Authenticator 1.51.2 -
Microsoft
msticpy v3.0.2 -
MISP
MISP 2.5.44: Hotfix release (pull mechanism) and Overmind theme update -
OpenCTI
7.260715.0 -
Xways
-
Yaniv Radunsky
DFIR Companion v0.32.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.