| At Triangle Wave Security we wanted to automatically hook our spreadsheet of doom into IOC feeds and sandbox results as the incident unfolded. Bulk copy-and-paste just didn’t have the juice and there are already enough dedicated year-old but abandoned tools. So we built Apipheny to handle the scheduling, full REST + OAuth, and plug directly into Google Sheets. We also added a one-time purchase because we’re tired of endless subscriptions too. As part of the DFIR community, use code 4N64EVA for 80% off. |
| Sponsored by Triangle Wave Security |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Belkasoft
Plist Files: Structure, Forensic Value, and How to Analyze Them -
CKE Ltd
NIST Digital Forensics Artifact Catalog: Where Digital Evidence Becomes Forensic Science -
Digital Forensics Myanmar
iPhone/iPad တွေကနေ ဖျက်လိုက်တဲ့ File တွေကိုဖျက်လိုက်ရင် ဘာဖြစ်မလဲ ? What happens when you delete files on an iPhone/iPad? -
Django Faiola at ‘Appunti di Informatica Forense’
What’s in Your Lidl Plus App? An iOS Forensic Analysis -
Forensafe
Android Auth Tokens -
Fiza Ahmad at InfoSec Write-ups
A Deep Dive into LNK Files | Windows Forensics -
Kenneth G. Hartman at Lucid Truth Technologies
Cloud Storage Evidence Attribution: Who Actually Put That File There? -
Kevin Pagano at Stark 4N6
Consensual Forensics with Android Intrusion Logging -
Alexis Brignoni at LEAPPs Blog
iOS App Snapshots, Seven Years Later: The Screen, the Scene, and Three Clocks -
Matthew Plascencia
ABX and XML: What’s the Difference? -
Tim Korver at ‘Thesis Friday’
Thesis Friday #24: Recovering a dialed number from the Unified Log -
Heather Barnhart at Smarter Forensics
The Idaho Murders: Remembering Kaylee, Xana, Maddie, and Ethan
Threat hunting/threat intelligence
-
Callie Baron and Ryan Devendorf at Abnormal Security
LinXcoded: M365 Phishing Platform Steals Post-MFA Sessions via HTML Attachments -
ASEC
-
Axel Z at Victory Road
Pulling the Thread: APT should not usurp the identity of Leroy Merlin or there will be consequences -
Christine Barry at Barracuda
Phantom Project: A cybercrime toolkit bundle -
BI.Zone
-
Jade Brown at Bitdefender
Bitdefender Threat Debrief -
Darren Williams at BlackFog
The Gentlemen: How GentleKiller Clears the Path to Encryption -
Shailendra Singh Sachan at Bloo
Linux Credential Dumping: From SSSD Cache to Kernel Keyring -
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
-
Daniel Whitcombe at Bridewell
UK CNI Infostealer Threat Insights -
BushidoToken
UK Cybercrime Journal: Evolution of Courier Fraud Campaigns -
CERT Ukraine
Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування -
CERT-AGID
-
Check Point
-
CloudSEK
-
Cofense
You’re Invited to get Phished! Why Invitation-themed Emails Remain Effective -
Cyble
-
Detect FYI
-
Disconinja
-
Michael Rothschild at Dragos
Water Under Attack: A Decade of Warnings, and the Same Gaps Still Open -
Dream
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia -
Chase Snyder at Eclypsium
When Patching Isn’t Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk -
Elastic Security Labs
13 million tool calls: auditing every AI coding agent action with Elastic Agent -
Eric Lawrence at text/plain
Attack Technique: AI Clones -
Flashpoint
Navigating AI-Driven Cyber Threats: Insights from Flashpoint’s 2026 GTIR Midyear Edition -
Gen
-
Genians
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM -
Guillaume Valadon at GitGuardian
Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations -
Jason Baker at GuidePoint Security
Bird Watching: Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations -
Reegun Jayapaul and Rahul Ramesh at Howler Cell
ShieldBreak: Windows Zero-Day That Breaks Microsoft’s RoguePlanet Fix -
Hudson Rock
-
Hunt IO
Inside a Russian-Speaking Operator’s Toolkit for Compromising Ukrainian IP Cameras -
Infoblox
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows -
InfoSec Write-ups
-
Insinuator
-
Intel 471
Threat Hunting Case Study: The Gentlemen -
Thijs Xhaflaire at Jamf
AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers -
Jeffrey Bell at CatchingPhish
MFA is in Retrograde, Phishing Kit Analysis -
Adam Goss at Kraven Security
How to Detect North Korean Remote Workers Hiding Inside Your Company -
Kudelski Security
Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware – Kudelski Security Research Center -
LevelBlue SpiderLabs
-
Mehmet Ergene at Blu Raven Academy
Device Roles in Microsoft Defender XDR: Better Context for Threat Hunting and Detection Engineering -
Eugenio Benincasa at Natto Thoughts
Whack-a-Mole: How China’s War on Cybercrime Pushed Fraud Offshore – and Ignited a U.S. Crackdown -
Rafa Bono and Katie Nickels at Okta
Using advanced posture checks as a tooling watchdog -
Oleg Skulkin at ‘Know Your Adversary’
-
Jenn Gile at OpenSourceMalware
A Developer’s Guide to Getting Rid of PolinRider -
Moshe Siman Tov Bustan at OX Security
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP -
Practical Security Analytics
Emulating APT28 PRISMEX with SpecterInsight -
Dan Green at Push Security
How browser attacks are evolving in 2026 so far -
Recorded Future
-
Ridgeline Cyber
The Mac With No Malware On It: When Consent Is the Attack Path -
SANS Internet Storm Center
-
Securelist
- IT threat evolution in Q2 2026. Non-mobile statistics
- IT threat evolution in Q2 2026. Mobile statistics
- Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
- Armored Likho expands its cyber-espionage toolkit
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
-
Securonix
Episode II: Attack of The Claudes -
Gabriel Bernadett-Shapiro at SentinelOne
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders -
Kush Pandya at Socket
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection -
SOCRadar
LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies -
Scott Lang at Spur
Vishing Attacks on Financial Firms: How to Detect Account Takeover Attempts -
Step Security
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. -
Marco A. De Felice aka amvinfe at SuspectFile
Exclusive: 500 Hosts, 1 TB and No Negotiation: Anubis Reveals Its Fairlife Attack -
Symantec Enterprise
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side -
Mnik at System Weakness
Detecting macOS Gatekeeper Quarantine Attribute Removal with Sigma -
Team Cymru
Cl0p Til you Drop – 6 Years, 10 Campaigns, 8 Zero-Days -
Tenable
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure -
The Hunter’s Ledger
The Middle Tier: A Non-APT Operator’s Reach Into Four Southeast Asian Governments -
The Raven File
MAJINAHANASHI RANSOMWARE: Yet Another Japanese Locker -
Josh Rickard at THOR Collective Dispatch
Open Season: CZDS -
ThreatMon
-
Trellix
-
Umut Bayram at Picus Security
-
Hai Vaknin at Varonis
WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking -
Joseliyo Sánchez at VirusTotal
Enriched URL Reports: VirusTotal URL Scanning 2.0 -
VMRay
-
Sina Kheirkhah at watchTowr Labs
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) -
Wiz
-
ZScaler
-
Sergey Belyaev at Блог Solar 4RAYS
Уязвимости в ИИ-средствах автоматизации
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-08-17 -
Cellebrite
- From Evidence Overload to Case Clarity, Faster
- Genesis in the DFU: The Art of the Possible
- Finding Answers Faster: Genesis for Private Sector Investigations
- Full Perimeter: Complete Facility Security, From Confiscated Phones to Recovered Drones
- From Seizure to Command Decision: Mission Systems for APAC Defence, Intelligence and Border Security
-
Magnet Forensics
-
Off By One Security
AI Found a Vulnerability. Now Prove It! – Stephen Sims -
Sygnia
Live Webinar: Shai-Hulud in the Wild – What Security and IR Teams Need to Know -
The Volatility Foundation
The 14th Annual Volatility Plugin Contest is Open!
Presentations/podcasts
-
0day in {REA_TEAM}
[SBC2025] APT35: The Silent Adversary Under the Radar -
Adversary Universe Podcast
AI as a Weapon, Target, and Enterprise Reality with CoreWeave’s Natasha Eastman -
Any.Run
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup -
Belkasoft
Analyze Evidence in 100+ Languages Without Google Translate | BelkaGPT -
Black Hat
- Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply Chain
- Black Hat Asia 2026 | Inside Cybercrime Inc: Lessons From Covering the Global Fraud Boom
- Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers You’re Not Using (Yet)
- Black Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mare
- Black Hat Asia 2026 | Cyber-Paleontology in the Age of AI
-
CactusCon
CactusCon 14 -
Cyber Social Hub
Targeted Mobile Extraction: Collecting Only the Evidence You Need with ADF Pro and MDI -
Dr Josh Stroschein
How Packers Work: UPX & Executable Obfuscation | Packing & Obfuscation Lesson 01 -
Ido Veltzman
Inside Event Tracing for Windows with EtwSuite -
InfoSec_Bret
IR – SOC328 – Akira Ransomware IOC’s Detected -
John Hammond
I Found an MFA-Bypassing Phishing Attack on Microsoft 365 -
Karsten Hahn at Malware Analysis For Hedgehogs
Compiled JavaScript – V8 compilation pipeline and Bytenode -
Magnet Forensics
AI Unpacked S2:E4 // The art and science of AI prompting in digital investigations -
Microsoft Threat Intelligence Podcast
Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report -
Monolith Forensics
-
MyDFIR
-
OpenSourceMalware
The OpenSourceMalware Show #17 -
Parsing The Truth: One Byte at a Time Podcast
S2 E9: The Problem with Deepfakes -
Proofpoint
Half-Click is so Hot Right Now: How Russian and Chinese Attackers Exploit Mailservers -
Richard Davis at 13Cubed
The Threat Hunting Course I Wish I Had -
SANS Cloud Security
Entra Agent ID: from Detection to Response -
The Defender’s Advantage Podcast
The New Frontline of Supply Chain Attacks -
THE Security Insights Show
The AI & Security Insights Show Episode 297 | Black Hat and Defcon Recap, plus the return of Mona G. to talk Project Perception or Inception? -
The Weekly Purple Team
ShieldBreak: Privilege Escalation & Detection -
Volatility Foundation
- COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT
- CTADL: Customizable Static Taint Analysis
- Rethinking DMA Attacks with Erebus
- Thorium
- Detecting and Preventing Obfuscated Script Execution with Tree-sitter
- Mission Auth Possible: Passwordless Phishing
- Open Cloud Security, Lessons Learned Building Prowler
- The Forensics of Zoom’s Remote Control
- Detection and Analysis of Memory-Only Linux Rootkits
- Adventures of Wallet Hacking
-
Watson Infosec
Private AI-Powered SOC Triage Lab
Malware analysis
-
Darrel Virtusio, Santiago Pontiroli, and Subhajeet Singha at Acronis
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure -
Aditya K Sood and Bikash Dash at Aryaka
Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain -
Chetan Raghuprasad at Cisco’s Talos
Dissecting the JWR phishing framework -
Cara Lin at Fortinet
Multi-Functional Linux Botnet “Evooo1Bot” -
Alexander Grabko and Konstantinos Angelopoulos at Group-IB
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme -
Daniel Kelley at iVerify
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps -
Praveen Babu at K7 Labs
When SQL Server Becomes the Initial Launcher: A Deep Dive into Weaxor Ransomware Execution -
Sav Wheeler at Malwarebytes
Fake CCleaner installs GhostDesk Chrome spyware -
Microsoft Security
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure -
Vini Egerland at Netskope
AI Sidebar Extension Monetizes Its Own Updates -
Palo Alto Networks
-
Shubho57
Analysis of a python loader -
SOC Fortress
DeadLock Ransomware: Analysis of Rust Encryption and Decentralized Recovery -
Sophos
Miscellaneous
-
Anton Chuvakin
-
Cellebrite
-
Cyber Triage
-
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 08/10/26 -
Dr. Neal Krawetz at ‘The Hacker Factor Blog’
Mark My Words -
John Hollenberger & Jennifer Hollenberger at FIRST
Mind Over Malware: The Hidden Psychological Toll of Incident Response -
Forensic Focus
- Misconduct Or Mental Injury? A Question Policing Can No Longer Avoid
- How To Process A Clear-Key BitLocker Image File To Generate A Decrypted Raw Image
- Digital Forensics Jobs Round-Up, August 10 2026
- Unmasked: Early Intelligence Should Not Be Manual
- Digital Forensics Round-Up, August 12 2026
- UPCOMING WEBINAR – Reducing ICAC Backlogs: Prioritizing Digital Evidence For Faster Investigations
- Protecting Those Who Protect Children: Inspection Findings And The Evidence Base For Investigator Well-Being
-
Hackers Arise
Digital Forensics: Attacking SAM and Extracting Hashes With 7z -
Magnet Forensics
From alert to forensic insight, automatically, with the Magnet Nexus API -
Raju Chekuri at Netenrich
Detecting Advanced Persistent Threats (APT) via Sequences -
Nextron Systems
-
Justin Palk at Red Siege Information Security
Improving Your Simple Windows Domain for Offensive Testing: Sysmon -
Luke Herbrandson at Sucuri
The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.
Software releases/updates
-
Binalyze
Binalyze Air 5.24 -
Canadian Centre for Cyber Security
Assemblyline 4.7.4.9 -
Datadog Security Labs
GuardDog Release v3.2.0 -
David Augros
sigwood v0.3.0 -
DFIRe
1.7.3 — August 15, 2026 -
Doug Burks
-
Get-Sybers
DX_DFIR v0.1.0 — DFIR pipeline: processing + signatures + MITRE CAR on Kusto -
LEAPPs
-
MISP
CTI-Transmute 1.5 released with 16 security fixes and a first-class public API -
Nedim Šabić
fibratus v3.1.0 -
OpenCTI
-
Rapid7
-
Renzon Cruz
IRFlow Timeline 1.0.11
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.