| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Eoghan Casey at DFRWS
Adding Clarity to a Foundational Concept in Cyber Investigations: Technique -
Elcomsoft
- Cracking Legacy ZIP Encryption: The Known-Plaintext Attack and Why It Still Sometimes Works
- Digital Triage and the Rules of Evidence: What Holds Up, and Where
- An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs
- The RAR Mystery: Breaking RAR4 and RAR5 Encryption
- Why Digital Forensic Reports Don’t Survive Cross-Examination
-
Forensafe
iOS SplitWise -
Kenneth G. Hartman at Lucid Truth Technologies
When a Signed PDF Isn’t: What a Printed DocuSign Document Proves in Court -
Matthew Plascencia
Reading a Droid’s Signal -
Joachim Metz at Open Source DFIR
Case study of comparing command line tools -
Seth Enoka
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns -
Tim Korver at ‘Thesis Friday’
Thesis Friday #22: Reading the Unified Log by evidential strength, not by timestamp.
Threat hunting/threat intelligence
-
Any.Run
Kali365 Targets US Organizations with Data Theft via Device Code Phishing -
Arctic Wolf
-
ASEC
-
Francis Guibernau at AttackIQ
Chaos Ransomware: BlackSuit-Linked RaaS Resurgence and Detection Opportunities -
Brian Krebs at ‘Krebs on Security’
LG to Ban Residential Proxies from Smart TV Apps -
BushidoToken
-
CERT Ukraine
UAC-0099: LUNCHPOKE, BURNYBEAR, оновлений MATCHBOIL.V2 та використання Notepad++ 8.8.3 -
CERT-AGID
-
Check Point
-
CloudSEK
France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends -
Cofense
-
Michael Steele at Confiant
SourTrade: Browser-Assembled Malware Delivered Through Malvertising -
Tim Chiu at Corelight
TTP-Based Detection: The Missing Layer in Modern SOCs | Corelight -
John Prieto at CrowdStrike
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks -
Ctrl-Alt-Intel
-
Cyb3rhawk
Part 2: Measuring LLM Breach Hunters; Strategy, Capability, and Generalization -
Andrea Draghetti at D3Lab
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali -
Dark Atlas
APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT -
Detect FYI
-
Disconinja
Weekly Threat Infrastructure Investigation(Week30) -
Doby Baxter
Reconstructing cloud identity intrusions from O365 and CloudTrail logs -
Elastic Security Labs
-
Esentire
Email Bombing, IT Impersonation, Quick Assist, and Edgecution: Breaking Down UNC6692’s Tradecraft -
Brandon Overstreet at Expel
The feature that stops BYOVD (bring your own vulnerable driver) -
Eye Security at Eye Research
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) -
Flare
-
Forescout
2026H1 Threat Review: Vulnerabilities Up 51% Year Over Year -
GitGuardian
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI -
Google Cloud Threat Intelligence
Updated Cyber Threat Actor Naming System -
Group-IB
-
Hornet Security
Monthly Threat Report Juni 2026 -
Tom Moester at Hunt & Hackett
Attackers do not need to break in, they simply log in -
Hunt IO
-
IC3
-
Jon Malm at Jamf
Jamf telemetry basics -
Jeffrey Bellny at CatchingPhish
I Asked Claude for a Housing Map. It Gave Me a Gambling Site -
Keisuke Shikano at JPCERT/CC
TSUBAME Report Overflow (Jan-Mar 2026) -
Kudelski Security
DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure – Kudelski Security Research Center -
LevelBlue SpiderLabs
LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses -
Mat Fuchs
The AI That Cheated on Its Own Exam by Hacking the University -
Microsoft Security
Email threat landscape: Q2 2026 trends and insights -
Thomas Byrne at NetSPI
Azure VM Command Execution using Third-Party Extensions -
Oleg Skulkin at ‘Know Your Adversary’
-
Oliver Smith
TChCh-Changes: A Look at macOS TCC Manipulation in the Wild -
OpenAI
OpenAI and Hugging Face partner to address security incident during model evaluation -
Neetrox at OSINT Team
I Automated Threat Hunting on Wazuh with n8n — Here’s the Workflow, Node by Node -
Palo Alto Networks
Russian Global Webmail Espionage -
Prodaft
-
Proofpoint
-
Ransom-ISAC
-
Anna Širokova and Jan Recinsky at Rapid7
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab -
Recorded Future
-
Red Canary
Intelligence Insights: July 2026 -
Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie, and Connor Short at ReliaQuest
DNS Poisoning Tactics Expand to Hospitality Wi-Fi -
Ridgeline Cyber
One Failed Login Is Noise. The Same Failure Across Sixty Accounts Is a Spray Your Rule Can’t Count. -
SANS Internet Storm Center
-
Securelist
-
SentinelOne
-
Shahar Dorfman at Wiz
-
SOC Fortress
Cookie Crumbles: CVE-2026–0257 and Qilin Ransomware Analysis -
Socket
-
Scott Lang at Spur
How Session Enrichment Improves Edge Security Decisions -
Step Security
-
Sysdig
-
The Raven File
INC RANSOMWARE : THREAT INTELLIGENCE -
ThreatMon
Ransomware 2026 Report June -
Trend Micro
- Volume Is Not Risk: Making Sense of the “Vulnpocalypse”
- Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
- Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
- Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
- 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
- The Signs Were There: What the First Autonomous Ransomware Case Confirms
-
Lumi Taiwo and Danny Dubree at TrustedSec
The New Hotness in Phishing: Device Code Attacks in M365 -
Daniel Kelley at Varonis
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI -
Stephan Hoehl at Vectra AI
Attackers Create Inbox Rules. They Don’t Rewrite Yours. by Stephan Hoehl -
VMRay
-
Блог Solar 4RAYS
Большой обзор open-source-вредоносов
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-07-27 -
Cellebrite
Cellebrite Genesis : Plus qu’une révolution — un tout nouveau paradigme -
Magnet Forensics
-
Off By One Security
The Role of Cryptography in Security -
SANS
Presentations/podcasts
-
FBI
Ahead of the Threat Podcast: Season 2, Episode 8—Frank Cilluffo -
InfoSec_Bret
IR – SOC322 – Named Pipe Token Impersonation Detected -
Magnet Forensics
- From extraction to courtroom: Accelerating digital evidence review and case preparation
- Living off the land: Investigating attacks that leave no malware behind
- Legal Unpacked S1:E10 // Preparing the court for trial: Strategic Motions in Limine in criminal prosecutions
- Six pillars of digital forensics
-
Marcus Hutchins
OpenAI’s New Model Went Rogue and HACKED a Rival Company -
Monolith Forensics
-
Open Source Forensics Lab
Signal Messager Forensic Analysis | Android Forensics -
OpenSourceMalware
The OpenSourceMalware Show #14 -
Parsing The Truth: One Byte at a Time Podcast
S2 E7: The Daubert Standard – What you Need to Know Part 1 -
Proofpoint
StealC Exposed: Tracking, Emulating, and Disrupting a Top Info Stealer -
Richard Davis at 13Cubed
Automate Volatility 3 Memory Analysis with This Tool -
Team Cymru
Modernizing Incident Response: 4 Steps to Bulletproof Your Windows Logging -
The Defender’s Advantage Podcast
Shadow LLMs, Agentic Identities, and Securely Integrating AI -
The Weekly Purple Team
The Great Kerberos Ticket Heist (Does PTT work in 2026) -
Three Buddy Problem
OpenAI’s models breached Hugging Face, reward hacking ethics, benchmarking fast16
Malware analysis
-
0day in {REA_TEAM}
[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis -
Jozsef Gegeny, Ilia Dafchev, and David Catalan Alegre at Acronis
Lampion’s Portugal-focused phishing campaign delivers multistage malware -
Jordyn Dunk, Michael Szeliga, and Takahiro Takeda at Cisco’s Talos
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel -
Xiaopeng Zhang at Fortinet
Inside a TrickBot Variant Using DNS Tunneling for C2 -
herrcore
Kimi K3 Reverse Engineering – Opus Without The Nagging -
Qi’anxin X Lab
僵尸网络新秀:Dysphoria 演进与深度技术分析 -
Zaria Vuksan at ReversingLabs
Hidden in plain sight: How SVGs carry malicious scripts -
Prashil Moon at Seqrite
Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign -
Zhassulan Zhussupov
Malware analysis: part 11. How to create your own mini-GPT for binary analysis.
Miscellaneous
-
Tom DeJong at Black Hills Information Security
The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success -
Cellebrite
-
Craig Ball at ‘Ball in your Court’
Drafting RFPs for Robots to Read -
Cyberdom
Inside Entra Agent ID -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 07/20/26 -
Forensic Focus
-
LEAPPs Blog
-
Lesley Carhart
We Wrote an Academic Paper on Conficker in 2026 -
Magnet Forensics
-
Mari DeGrazia at SANS
When Frontier Models Say No: What the Hugging Face Breach Teaches Us About Local LLMs -
Salvation DATA
【Case Study】Fragmented Video Recovery in a Mall Theft Investigation
Software releases/updates
-
Crowdstrike
Falconpy Version 1.6.4 -
David Augros
sigwood v0.2.8 -
DFIRe
1.5.5 — July 23, 2026 -
Digital Sleuth
winfor-salt v2026.11.27 -
Doug Burks
so-crates v2.1.0 -
Doug Metz at Baker Street Forensics
-
GCHQ
CyberChef v11.3.0 -
Hunterworks
Binocular -
Kevin Pagano at Stark 4N6
Script Stash – Plist Mapping with Python -
LEAPPs
-
Boris Deibel at Nextron Systems
ASGARD Management Center 4.1: More Resilient. More Secure. Ready for THOR 11 -
Open Source DFIR
Plaso 20260720 released -
OpenCTI
7.260722.0 -
Passware
Passware Kit 2026 v3 Now Available -
Three Planet Software
Apple Cloud Notes Parser v0.24 -
Ulf Frisk
MemProcFS Version 5.18 -
Yaniv Radunsky
DFIR Companion v0.33.0 -
Yogesh Khatri
mac_apt 20260719
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.