| At Triangle Wave Security we wanted to automatically hook our spreadsheet of doom into IOC feeds and sandbox results as the incident unfolded. Bulk copy-and-paste just didn’t have the juice and there are already enough dedicated year-old but abandoned tools. So we built Apipheny to handle the scheduling, full REST + OAuth, and plug directly into Google Sheets. We also added a one-time purchase because we’re tired of endless subscriptions too. As part of the DFIR community, use code 4N64EVA for 80% off. |
| Sponsored by Triangle Wave Security |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Massimo Iuliani at Amped
Deepfake Forensics Workflow for Video Analysis -
Arman Gungor at Metaspike
Conversation Index Analysis in Email Forensics — Part 2 -
Elcomsoft
-
Forensafe
iOS Spotify -
Gaia Calamari at Strange Forensics
XT_ExtractDocsMail -
Intrinsec
-
Kevin Pagano at Stark 4N6
Script Stash – Hunting SEGB Streams -
LEAPPs Blog
-
Mattia Epifani at Zena Forensics
-
North Loop Consulting
A Query, who supports Skout & MeetMe? -
Oleg Afonin at Elcomsoft
-
Amber Schroader at Paraben Corporation
Unmasking the Synthetic: Using Metadata to Spot AI-Generated Images -
Terryn at chocolatecoat4n6
DFIR Note-Taking and Report Guide
Threat hunting/threat intelligence
-
Callie Baron and Ryan Devendorf at Abnormal Security
ARToken: The Device Code Phishing Platform Built for Full Microsoft 365 Takeover -
Callie Baron and Ryan Devendorf at Abnormal Security
ARToken: Device Code Phishing for Microsoft 365 Account Takeover -
Aikido
-
Anthropic
Investigating three real-world incidents in our cybersecurity evaluations -
ASEC
-
Francis Guibernau at AttackIQ
Response to CISA Advisory (AA26-204A): Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite -
CJ Moses at AWS Security
Amazon identifies North Korean hacker group behind open-source supply chain attacks -
Axelarator
We Have Packet Capture at Home Pt. 2 -
Sachin Meti at Barracuda
Threat Spotlight: LogoKit phishing service becomes a cloud-based, real-time deception platform -
Barricade Cyber Solutions
-
BlackFog
-
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
Read This Before You Buy That TV Streaming Stick -
Joshua Penny at Bridewell
Vishing Call to a Shared Com Ecosystem: Full Methodology and Findings -
BushidoToken
UK Cybercrime Journal: H1 2026 Social Media Fraud Trends -
Censys
-
CERT-AGID
-
Check Point
-
Lexi DiScola and Dave Liebenberg at Cisco’s Talos
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains -
Cloud Security Alliance
Hugging Face Incident Initial Post-Mortem -
CloudSEK
Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers -
Micah DeHarty at Cofense
The Evolution of Remote Access Tool Abuse: From Single Payloads to Multi-Stage Campaigns -
Kevin Ratto at CrowdStrike
Inside Astaroth’s New Spambot Component -
Cyberdom
Exploiting Azure IMDS -
Cyble
APTs Top the List of Most Active Threat Actors in H1 2026 -
D3Lab
-
Dark Atlas
The Code Is Real. The Device Is Not: The Definitive Guide to Device Code Phishing -
Darktrace
Uncovering a Multi-Stage Ransomware Attack Through Behavioral Detection -
Lorenzo Susini and Matt Muir at Datadog Security Labs
Detection primitives for eBPF rootkits -
Detect FYI
-
Disconinja
Weekly Threat Infrastructure Investigation(Week31) -
Elastic Security Labs
-
Erik Hjelmvik at Netresec
PureLogs, PureRAT and misleading zgRAT -
Jorn Pieterse at Eye Research
AI-powered Phishing-as-a-Service: Inside Two BEC Kits -
Assaf Morag at Flare
Kali365: The Phishing-as-a-Service Operation Expanding Beyond Microsoft 365 -
Flashpoint
Demystifying The Com and Nihilistic Violent Extremism: What You Need To Know -
Kelli Vanderlee and Stuart Carrera at Google Cloud Threat Intelligence
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise -
Hidden Layer
Dead Drops in Public: What the AI Agent Stashed on Hugging Face -
Hugging Face
-
IC3
-
InfoSec Write-ups
-
Intel 471
Software Supply Chain Attacks: Weaponizing Trusted Developer Workflows -
Gilbert Kallenborn at Intrinsec
Enterprise LLM Threat Atlas : real-world incidents, research cases, Mitre mappings -
Intrusion Truth
-
Kevin Beaumont at DoublePulsar
Adform compromised to serve crypto stealer via supply chain attack -
Adam Goss at Kraven Security
CTI For SMB: When Your Small Business Is Actually Ready For Threat Intelligence -
Lauren Proehl at THOR Collective Dispatch
-
LevelBlue SpiderLabs
-
Microsoft Security
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft -
MII Cyber Security
Progression of Remote Access Malware -
Eugenio Benincasa at Natto Thoughts
UKCT Report: “One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships” -
Asritha Narina at Netenrich
Deconstructing npm Registry & Supply Chain Attacks | Netenrich -
Thomas Byrne at NetSPI
Azure VM Command Execution using Third-Party Extensions – Salt Minion -
Nick Thanos at Triskele Labs
-
Moussa Diallo at Okta
Behind the scenes of a vishing operation -
Oleg Skulkin at ‘Know Your Adversary’
-
OpenSourceMalware
-
Palo Alto Networks
-
Prodaft
The Mantis Grip: Endpoint Defenses Pinned Before Encryption -
Proofpoint
-
Ransom-ISAC
-
RansomNews
RedACT Report Semestrale -
Resecurity
When AI Becomes the Attacker: Understanding Autonomous Offensive Security Agents -
Ridgeline Cyber
The Automation That Reports Success and Does Nothing -
SANS Internet Storm Center
- Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
- Java Spring Boot “heapdump” scans, (Mon, Jul 27th)
- AutoIT Payload Injector , (Tue, Jul 28th)
- Apple Patches Everything (July 2026), (Wed, Jul 29th)
- Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
- zipdump.py: Metadata Encoding, (Fri, Jul 31st)
- Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
- Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
-
Securelist
-
Silent Push
Welcome to Danglegeddon -
Socket
-
SOCRadar
-
Morgan Demboski at Sophos
Chaos in Teams vishing -
Splunk
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft -
Step Security
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan -
Stephan Berger
Field Notes: NSSM – the Non-Sucking Service Manager -
System Weakness
-
Team Cymru
From C2 Detection to Possible Victim Identification -
The Hunter’s Ledger
GOCLOUD: A Commodity Cryptojacking Operation, Captured Whole -
Third Eye intelligence
Hugging Face “Frontier Lab Model Intrusion” -
ThreatMon
-
Trend Micro
-
Umut Bayram at Picus Security
- Vidar Malware: How the Multithreaded Windows Stealer Works
- FrigidStealer Explained: macOS Infostealer and Gatekeeper Bypass
- Astaroth (Guildma) Uses Steganography and Ngrok for C2 Resilience
- HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel
- INC Ransomware Explained: How It Attacks Healthcare and Education
-
UnderDefense
Inside a ClickFix Attack: How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract -
Блог Solar 4RAYS
Обзор сетевых уязвимостей в 2-м квартале 2026 года
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-08-03 -
Cellebrite
-
Cyfirma
Frontier AI and Cyber Warfare: How Nation States Are Weaponizing AI -
John Hammond
Payload Podcast 010 – Olaf Hartong -
Sygnia
When Ransomware Hides in OneDrive: Inside SafePay’s Exfiltration Play -
XposedOrNot
You are being watched
Presentations/podcasts
-
Cyber Social Hub
How to Preview Digital Evidence in ADF Pro and MDI -
FIRST
Episode 63: John Hollenberger, Fortinet, FIRSTCON26 Speaker -
Hacker Valley Blue
Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White -
Huntress
_declassified | Know Your Adversary – Watch Party with Commentary -
InfoSec_Bret
IR – SOC331 – Zebrocy Malware Activity Detected (APT28) -
Microsoft Threat Intelligence Podcast
A Farewell from Sherrod: New Season Coming Soon -
Monolith Forensics
-
MSAB
-
MyDFIR
-
Off By One Security
Building the First Public Linux UEFI Bootkit Framework, with Alejandro Vazquez -
OpenSourceMalware
The OpenSourceMalware Show #15 -
Parsing The Truth: One Byte at a Time Podcast
S2 E8: The Daubert Standard Part 2 -
SANS Cloud Security
AI Driven DevSecOps Part 4: Observing Microservices with OpenTelemetry and Grafana -
Team Cymru
Rogue LLMs, Clop’s 8th Zero-Day, and Threat Hunting at Scale -
THE Security Insights Show
The AI & Security Insights Show Episode 296 | Black Hat and Defcon – Here we come! AI goes Wild! Don’t Hack me bro. -
Three Buddy Problem
Malware analysis
-
Arctic Wolf
Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection -
Blackpoint Cyber
Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors -
Qi’anxin X Lab
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria -
Shubho57
Analysis of TokyoCore Ransomware -
Zhassulan Zhussupov
-
ZScaler
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor -
Шифровальщики-вымогатели The Digest “Crypto-Ransomware”
NBLock Black
Miscellaneous
-
Vitaliy Mokosiy at Atola
Remote drive acquisition using Atola Boot Image -
Abuse.ch
Introducing the abuse.ch Community Hub: recognition matters -
Dan “Haircutfish” Rearden at Black Hills Information Security
Report As You Go: Maintaining Good Documentation for SOC Analysts -
Cellebrite
When a Drone Is Recovered, the Clock Starts -
Craig Ball at ‘Ball in your Court’
The AI Protective Order Double Standard -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 07/27/26 -
Elan at DFIR Diva
The Events Site is Being Rebuilt -
Forensic Focus
- Digital Forensics At The Point Of Contact: Closing The Gap Between Detection And Analysis
- Passware Kit 2026 v3: BitLocker PIN Recovery For TPM-Protected Devices
- Digital Forensics Jobs Round-Up, July 27 2026
- The First 60 Minutes of Digital Evidence: The Investigator Advantage
- Deepfakes Are Now An Investigative Risk – Unmasked: Authenticity Must Be Assessed
- Magnet Forensics Invites You To Share Your Thoughts On The Current State Of Enterprise DFIR
-
Jeffrey Appel
How to collect Microsoft Defender Client Analyzer Files via MDE Live Response -
Magnet Forensics
-
Chris A at NCSC
Making forensic observability the norm for network devices -
Nebulock
-
Obsidian Security
The Frontier Models Were Doing Their Jobs. That’s the Part Enterprises Should Plan For -
Sophena Wilson at sentinel.blog
Finding Patterns: The Art of Cybersecurity
Software releases/updates
-
ACELab
Direct connection of native USB SSDs without soldering -
ANSSI-FR
DFIR-ORC v10.3.4 -
Brian Maloney
OneDriveExplorer v2026.07.31 -
David Augros
sigwood v0.2.9 -
DFIRe
1.6.0 — July 29, 2026 -
Digital Sleuth
-
Doug Burks
so-crates v3.0.0 -
Elcomsoft
Elcomsoft Phone Breaker 11.04: more reliable downloads from iCloud Drive -
Ghassan Elsman
Crow-Eye 0.12.6 -
LEAPPs
-
OpenCTI
7.260728.0 -
Security Onion
Security Onion 3.2.0 Now Available with Agentic AI and Much More! -
SigmaHQ
pySigma v1.5.0 -
VirusTotal
YARA v4.5.8 -
WithSecure Labs
Chainsaw v2.16.3-beta.1 -
Yaniv Radunsky
DFIR Companion v0.34.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.