| At Triangle Wave Security we wanted to automatically hook our spreadsheet of doom into IOC feeds and sandbox results as the incident unfolded. Bulk copy-and-paste just didn’t have the juice and there are already enough dedicated year-old but abandoned tools. So we built Apipheny to handle the scheduling, full REST + OAuth, and plug directly into Google Sheets. We also added a one-time purchase because we’re tired of endless subscriptions too. As part of the DFIR community, use code 4N64EVA for 80% off. |
| Sponsored by Triangle Wave Security |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Christopher Eng at Ogmini
Examining Tailscale Artifacts – Part 8 -
Brian Carrier at Cyber Triage
DFIR+AI: Making Tool Decisions in a GenAI World -
Elcomsoft
-
Forensafe
iOS BeReal -
Hal Pomeranz at ‘Righteous IT’
Workaround For Duplicate LVM Names -
LEAPPs Blog
-
Mohit Dhabuwala
The email said it was from HR but the headers said something else. -
Tim Korver at ‘Thesis Friday’
Thesis Friday #23: The anchor comes from outside the log
Threat hunting/threat intelligence
-
Abnormal Security
Introducing Matrix: A Microsoft 365 AiTM Platform Overlapping the Sneaky2FA Lineage -
Christian Papathanasiou at AllSecure
ClickFix, EtherHiding & a DPRK Wallet Trail -
Any.Run
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers -
Arctic Wolf
Payroll Pirates: Strange New Tides in Business Email Compromise -
ASEC
-
Ayelen Torello at AttackIQ
Analyzing Nova Ransomware: A Rust-Based Encryptor with Multi-Layered Microsoft Defender Evasion Techniques -
Azeemnow
APT41’s Dodgebox: Defense Evasion and Detection Strategies -
Eric J. Taylor at Barricade Cyber Solutions
Threat Actor Profile: NightSpire Ransomware -
Rebecca Harpur at BlackFog
The State of Ransomware: July 2026 -
Brian Krebs at ‘Krebs on Security’
Canadian Man Pleads Guilty in Snowflake Extortions -
BushidoToken
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 -
CERT Polska
Follow-Up Report of the December 2025 Energy Sector Incident -
CERT-AGID
- Phishing a tema SPID in corso
- Phishing a tema “multe” sfrutta il nome della Polizia di Stato e di pagoPA
- Phishing ai danni di ARERA utilizza il tema “bonus sociale idrico”
- Sintesi riepilogativa delle campagne malevole nella settimana del 1 – 7 agosto
- XSS2Shell: nuova vulnerabilità nel core di WordPress può portare all’esecuzione di codice remoto
-
Check Point
3rd August – Threat Intelligence Report -
Nick Biasini, Dmytro Korzhevin, Jaeson Schultz, Vanja Svajcer, Vitor Ventura, and Arnaud Zobec at Cisco’s Talos
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI -
CloudSEK
Access For Sale: Inside a Russian-Speaking Access Broker’s Dual Operation -
CrowdStrike
-
CTF导航
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments -
Cyble
-
Christophe Tafani-Dereeper, Nick Frichette, Sebastian Obregoso, and Martin McCloskey at Datadog Security Labs
Worm compromises hundreds of popular npm packages -
Detect FYI
-
Dirk-jan Mollema
Borrowing Windows Hello keys for authentication and persistence -
Elastic Security Labs
-
Eric Lawrence at text/plain
-
Aaron Walton at Expel
Reading the certificate leaves: Understanding GoldenEyeDog’s teams—CylindricalCanine and CuboidalCanine—through code-signing certificates -
FalconFeeds
- Threat Intelligence in the Era of Fragmented Cybercrime: The Transition from Monolithic RaaS Syndicates to a Post-Trust Ecosystem
- Threat Actor Operational Mistakes: The Small Errors That Lead to Attribution
- Cyber Threat Intelligence as Geopolitical Intelligence: Early Warning Indicators of Macro-Stability and Conflict
- The Internet’s Forgotten Infrastructure: Why Old Servers Still Matter
-
Flare
FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure -
GitGuardian
-
Tyler McLellan and Austin Larsen at Google Cloud Threat Intelligence
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments -
Hunt IO
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 -
LevelBlue SpiderLabs
-
Ax Sharma and Cody Nash at Manifold Security
77 “evil twin” Open VSX extensions: 19 copy private repo and CI data to a new domain -
Microsoft Security
-
Netskope
-
Swachchhanda Shrawan at Nextron Systems
Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain -
Jeremy Kirk and Mathew Woodyard at Okta
Free tokens for sale: How fake signups drive AI fraud -
Oleg Skulkin at ‘Know Your Adversary’
-
OpenSourceMalware
-
Moshe Siman Tov Bustan at OX Security
A New Infostealer Worm Hits npm, affecting Keyv and Cacheable -
Palo Alto Networks
-
Resecurity
ExfilSquad Targets New Victims, Shares Data via Torrents -
Ridgeline Cyber
The Hunt That Found Nothing -
Ron Ben Yizhak at Safebreach
Forgotten but Not Gone: Unauthenticated RCEs and Privilege Escalations in Legacy Linux Services -
SANS Internet Storm Center
- Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
- Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
- 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
- Linux Shell Forensic: Let’s Dive Into Atuin!, (Fri, Aug 7th)
-
Securelist
-
Security Scorecard
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity -
Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee at Securonix
Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures -
Shayan Ahmed Khan
From Alert to Answer: AI-Driven DFIR with Claude Code & Velociraptor -
Ian at Shells.Systems
Abusing Extended Attributes to Bypass Application Control For Business -
Socket
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack -
SOCRadar
-
Sergio Bestulic, Andrew Bonwell, Karla Soler, and Michael Warner at Sophos
Interlock ransomware gang creates volatile situation -
Step Security
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 -
Sygnia
-
System Weakness
SOC153 – Suspicious Powershell Script Executed | LetsDefend Walkthrough -
Team Cymru
Behind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry -
The Hunter’s Ledger
CloudSync: An Assembler’s Intrusion Toolkit -
The Raven File
CRPX0 — SCAMMER TURNED RANSOMWARE OPERATOR -
The Shadowserver Foundation
Shadowserver Critical Community Infrastructure Cyber Resilience Project -
Edwin David at TrustedSec
The Art of Hunting Azure Cloud Secrets -
Umut Bayram at Picus Security
Dropping Elephant (Patchwork): Espionage APT Tactics and Tools -
Wiz
-
Victor M. Alvarez at YARA-X
Beware of the wildcard -
ZScaler
-
Блог Solar 4RAYS
AI-Killchain в нынешних реалиях
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-08-10 -
Rebecca Harpur at BlackFog
WEBINAR: The First Half Of 2026 In Ransomware – Register Now! -
Amy Ciminnisi at Cisco’s Talos
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents -
Huntress
Tradecraft Tuesday | Fake Claude install guide, real macOS stealer -
Magnet Forensics
AI Unpacked S2:E4 // The art and science of AI prompting in digital investigations
Presentations/podcasts
-
ADF Solutions
-
Adversary Universe Podcast
Unpacking the CrowdStrike 2026 Threat Hunting Report with CrowdStrike’s Katie Blankenship -
Belkasoft
- iOS Agent-Based Acquisition: Full File System and Keychain Extraction with Belkasoft X
- iOS Acquisition Methods Explained: iTunes, Checkm8, Agent-Based, and iCloud
- iOS Forensics: The Good, the Bad, and the Ugly—Acquisition, iCloud, and System Artifacts
- Forensics In The Cloud: How To Conduct An Office 365 Investigation
- Distribute AI Forensic Processing Across Your Network | BelkaGPT Hub
-
Black Hat
-
CySecK
Cyber Aware Karnataka | Email Phishing Attack | Ep. 01 -
Endace
Secure Networks Ep 67 – The Packet Forensics Files – with Erik Dove from Cisco -
InfoSec_Bret
IR – SOC333 – Denis Malware Activity Detected (APT32) -
Magnet Forensics
-
Monolith Forensics
-
MyDFIR
-
Open Source Forensics Lab
Android XML Analysis |xml2abx Overview -
OpenSourceMalware
The OpenSourceMalware Show #16 -
Proofpoint
Half-Click, Full Compromise: Inside Russia’s TA458 and TA488 Espionage Playbook -
Team Cymru
Agentic Escapes and Spyware Fingerprints -
The Weekly Purple Team
Certighost: Certificate Authority Exploitation & Detection | Weekly Purple Team -
Three Buddy Problem
Inside OpenAI’s Black Hat Confession
Malware analysis
-
Fortinet
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant -
Ferdous Saljooki at Jamf
Fake Zoom installer uses .NET dropper to deliver Overlord RAT on macOS -
Baran S at K7 Labs
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application -
Shayan Ahmed Khan
Autonomous Reverse Engineering: Evaluating AI with Interactive Disassembly -
Shubho57
Analysis of JavaScript File leads to NetSupport RAT -
Liran Tal and Lion Kontorer at Snyk
Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks -
Paolo Tresso at Wordfence
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
Miscellaneous
-
CCL Solutions
A LEAPP forward for web browser forensics -
Daniel Wyleczuk-Stern
Stop Making Your Detection Engineers Triage Alerts -
Decrypting a Defense
Authoritarian Data Collection, Search Warrants in the Digital Age Still Require Probable Cause, Jumana Musa Answers 5 Questions & More -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 08/03/26 -
Forensic Focus
- How To Perform Targeted Mobile Extraction In ADF Pro
- From Backlogs To Breakthroughs: How The Metropolitan Police Service Triaged 6,000 Devices
- Ticking A Box, Missing The Person – Reflections From FEE 2026
- Digital Forensics Round-Up, August 05 2026
- Unmasked: Exposure Is A Workflow Choice
- Practical AI In Digital Forensics: Running Offline AI On Your Own Evidence With BelkaGPT
- The Evolution Of Atola TaskForce: Eight Years Of Non-Stop Innovation
- Forensic Focus Digest, August 07 2026
-
Ihsan Alamal Ahmad at Intellibron
The Detection Engineer’s New Best Friend -
Jeffrey Appel
Microsoft Defender Threat Intelligence: Native Defender Integration and API Access -
Kevin Pagano at Stark 4N6
Forensics StartMe Updates (August 2026) -
Magnet Forensics
Forensic Early Case Assessment: is eDiscovery collecting the right data? -
Oxygen Forensics
How to export and transfer public sector annotations from Oxygen Review Center to Oxygen Forensic® Detective -
Salvation DATA
Vehicle Data Acquisition: The Role of EDR and OBD in Digital Forensics -
Security Onion
Security Onion Documentation Printed Book Now Updated for Security Onion 3.2! -
UltimaCybr
WRAITH — Part 1 -
Eli Rozen at Vega
Vega Introduces Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense
Software releases/updates
-
ACELab
-
Alexandre Borges
Malwoverview 8.1.0 -
Arsenal Recon
Arsenal Image Mounter Changelog – v3.13.368 -
Doug Burks
-
Elcomsoft
EIFT Firewall: a new free tool for controlled agent sideloading -
Ghassan Elsman
Crow-Eye v0.12.7 -
Metaspike
Forensic Email Collector (FEC) Changelog – 4.5.888.111 -
MOBILedit
MOBILedit Forensic 9.8.1 released -
OpenCTI
7.260807.0 -
radare2
6.2.0 -
WithSecure Labs
-
Yamato Security
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.