| At Triangle Wave Security we wanted to automatically hook our spreadsheet of doom into IOC feeds and sandbox results as the incident unfolded. Bulk copy-and-paste just didn’t have the juice and there are already enough dedicated year-old but abandoned tools. So we built Apipheny to handle the scheduling, full REST + OAuth, and plug directly into Google Sheets. We also added a one-time purchase because we’re tired of endless subscriptions too. As part of the DFIR community, use code 4N64EVA for 80% off. |
| Sponsored by Triangle Wave Security |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Oleg Afonin at Elcomsoft
The True Meaning of Consent in ‘Consent Extractions’ -
Invictus Incident Response
OpenAI Forensics: Investigating AI Evidence & Logs | Invictus | Invictus Incident Response -
Alexis Brignoni at LEAPPs Blog
The App Is Gone. The Story Isn’t. -
MII Cyber Security
-
Monty Shyama
Freezing the Crime Scene: A Step-by-Step Guide to Container Checkpointing & Forensics on Amazon EKS -
Tim Korver at ‘Thesis Friday’
Thesis Friday #26: Same unlock, three different stories
Threat hunting/threat intelligence
-
Ryan Devendorf and Callie Baron at Abnormal Security
ZeroTokens Gives Operators Real-Time Control of Phishing Flow -
Hitesh Duseja at Altered Security
Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector -
Any.Run
A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign -
Arctic Wolf
Dark Caracal Reloaded: New Malware, Same Hunting Grounds -
ASEC
-
Nisha Kashyap at AWS Security
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation -
Saravana Govindarajan at Barracuda
Fake invoices, real scammers: The callback phishing playbook -
Brian Krebs at ‘Krebs on Security’
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia -
BushidoToken
UK Cybercrime Journal: ACRO Breach Report -
Silas Cutler at Censys
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption -
CERT-AGID
-
Check Point
24th August – Threat Intelligence Report -
CISA
A Tale of Two SOCs: Insights From Two Red Team Assessments -
CloudSEK
Caught in 4K: The Aurora Files -
Marie Mamaril at Cofense
Understanding Browser Trust Abuse: Exploiting Enterprise’s Most Trusted Interface -
Roshan at Confiant
Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning -
Cyb3rhawk
As My Agents got Better, their Evidence trails got Quieter. -
Dan Lisichkin
A WIF Of Fresh Access: How a GitHub Issue on Gemini-CLI Led to GCP Project Compromise -
Darktrace
-
Denis at D3Lab
-
Detect FYI
-
Manuel Winkel at Deyda Consulting
NetScaler CVE Checklist: Updates, Security Assessment and Incident Response -
Disconinja
Weekly Threat Infrastructure Investigation(Week34) -
Olaf Hartong at Falcon Force
I’m in your logs now: deceiving analysts and blinding EDRs -
Flare
-
GreyNoise
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets -
Group-IB
-
Paolo Coba at GuidePoint Security
Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database -
Halkyn Security
-
Hudson Rock
Inside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police Unit -
Huntress
- RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress
- Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
- A Detection Engineer’s Guide for Delegating Work to AI
- Insights into Suspected DPRK Workers
- PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
- The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
-
Itochu Cyber & Intelligence
-
iVerify
-
Jeffrey Bell at CatchingPhish
ClickExfil: My iteration on ClickFix and FileFix -
Adam Goss at Kraven Security
Sigma Rules Explained: Architecture, pySigma, Modifiers, & Correlation -
LevelBlue SpiderLabs
-
Cody Nash at Manifold Security
OpenAI & Hugging Face: Why The Chain-of-Thought Police Won’t Save You -
MDSec
When it Snows it Pours – Anatomy of a ServiceNow Red Team -
Microsoft Security
-
Brad LaPorte at Morphisec
When Your AI Coding Assistant Becomes the Attack: The Hades Supply Chain Campaign -
Natto Thoughts
From the Frontier AI Arms Race to AI-enabled Defense-in-Depth: Qi An Xin Chief Outlines His Vision -
Ankur Chadda at Netskope
Detection Isn’t Proof: The 72-Hour-Evidence Problem -
Oleg Skulkin at ‘Know Your Adversary’
413. Threat Actors Abuse Multiple Services for System Location Discovery -
OpenSourceMalware
NPM Isn’t Prepared For North Korean PolinRider Attack -
OSINT Team
-
OX Security
-
Sara McBroom at Palo Alto Networks
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution -
Patrick Wardle at Objective-See
Detecting (Evil) Dylibs -
Itai Boublil at Profero
WindowsAudit, Part Three: How an IR Investigation Ended in a Police Arrest -
Dani [Varys] Z, Ellis Stannard, Eric Taylor, Nick Smart, Rakesh Krishnan, and Yashraj Solanki at Ransom-ISAC
CRPx0 ClickFix Ransomware Analysis -
Rapid7
-
Recorded Future
BlueDelta Targets Defense and Diplomacy with HOOKEDGE -
Ryan Greenblatt at Redwood Research
Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident -
ReliaQuest
Gryxa: The AI-Built Toolkit That Watches How You Remove It -
Zaria Vuksan at ReversingLabs
Infostealers highlight malware-as-a-service trend -
Ridgeline Cyber
Your Secret Rotation Ran Correctly. Both Credentials Are Still Valid. -
Rob T. Lee
“Permadeath,” Persistence, Delegation, Coordination: the OpenAI postmortem & METR indepentent review -
SANS Internet Storm Center
-
Securelist
-
SentinelOne
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter -
Silent Push
Danglegeddon: The Full Research Report Is Now Available -
Simone Kraus
THE HUMAN EXPLOITATION ECOSYSTEM -
Socket
-
SOCRadar
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain -
Mitch Pronschinske at Sophos
The State of Ransomware in Education 2026 -
Alastair Parr at Spur Intelligence
Law Enforcement Playbook for Investigating Residential Proxies -
Step Security
-
Sucuri
Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk -
Marco A. De Felice aka amvinfe at SuspectFile
1.4 TB of Data and Thousands of Patients: PEAR Claims Attack on South Plains Rural Health Services (SPRHS) -
ThreatMon
-
Maulik Maheta and Henry Bernabe at Trellix
No Privileges, No Lockout, No Trace: Kerberoasting with SPN Misconfigurations -
Umut Bayram at Picus Security
ModeloRAT Malware: How the CrashFix Campaign Delivers a Python RAT -
Kenneth Kinion at Valdin
Inhospitable: Tracking Russian Cyber Espionage Infrastructure -
Vasilis Orlof at Cyber Intelligence Insights
Behind the Leak -
Wiz
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-08-31 -
Cellebrite
-
Magnet Forensics
-
Off By One Security
Watching Offensive AI Agents Work
Presentations/podcasts
-
Alexis Brignoni
Digital Forensics Now Podcast S3 – 7 -
Behind the Binary by Google Cloud Security
EP28 macOS Security Internals: Kernel Exploitation, PAC Defenses, and the Rise of macOS Infostealers with Olivia Gallucci -
Belkasoft
Fully Offline AI for Digital Forensics – No Cloud, No Data Leaks | BelkaGPT -
Black Hat
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-08-24 -
Dr Josh Stroschein
Defeating Modified UPX Packers | Packing & Obfuscation Lesson 03 -
FIRST
FIRSTCON26 -
Huntress
How Huntress Phishing Simulations Work (Live ClickFix Demo) -
InfoSec_Bret
IR – SOC189 – VBScript Suspicious Behavior Detected -
John Hammond
GitHub Hacker EXPOSED BY HIS CAT -
Magnet Forensics
-
Microsoft Threat Intelligence Podcast
JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack -
Monolith Forensics
-
MyDFIR
Cybersecurity SOC Analyst Lab: SmartApeSG PCAP Analysis (ClickFix) -
Open Source Forensics Lab
Oxygen Forensic Detective Overview -
OpenSourceMalware
The OpenSourceMalware Show #19 -
Parsing The Truth: One Byte at a Time Podcast
S2 E10: When nothing is all you got -
SANS Cyber Defense
PromptINT: Using Prompt Leaks as a New OSINT Source -
SOC Fortress
How I Caught a certutil Attack on My Open-Source SIEM -
THE Security Insights Show
The AI & Security Insights Show Episode – 000 | Just the Security Savages you know. -
Three Buddy Problem
A Thousand Agents Walk Into Hugging Face
Malware analysis
-
Darrel Virtusio and Subhajeet Singha at Acronis
Cambodia-focused cluster uses multistage infection chain with localized lures -
Ilyas Makari at Aikido
Popular code generator for TanStack Query hit by supply chain worm -
Cellebrite
Intro to Android Mobile Reverse Engineering -
James Hodgkinson at Cisco’s Talos
JavaScript obfuscation: From party trick to phishing kit -
Dominik at R136a1
SLEEPWALKER: A Passive Backdoor With Its Own Command Language -
Andrey Pautov at InfoSec Write-ups
Assembly for Malware Analysis -
Vini Egerland at Netskope
EtherHiding in the Browser: ClickFix Chain Ends in Amatera -
Proofpoint
Carry-On Compromise: TA4922 Packs PackClient -
Shubho57
Analysis of a javascript file leads to a highly malicious stealer -
Zhassulan Zhussupov
Miscellaneous
-
Anton Chuvakin
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3) -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 08/24/26 -
Eoghan Casey at DFRWS
Digital Forensics Conference USA 2026 Highlights -
Dr. Neal Krawetz at ‘The Hacker Factor Blog’
C2PA and Pixel Glitter Milk -
Forensic Focus
- Speed Against The Backlog: What’s Slowing You Down And How To Fix It
- 10 Best Practices For AI-Assisted Investigations: A Guide For Legal And Compliance Teams
- Digital Forensics Round-Up, August 26 2026
- How Semantics 21 Are Using Global Intelligence To Pre-Categorise Up To 70% Of Investigations
- Walk A Mile In Their Shoes: The Hidden World Of The Digital Forensic Investigator
-
Heather Barnhart at Smarter Forensics
AI-Assisted. Human-Led. Why DFIR Needed Its Own AI Frameworks. -
Josh Brunty
CTF Training -
Magnet Forensics
Investigating at scale: Lessons from three DFIR leaders -
Raju Chekuri at Netenrich
The Feedback Loop: Empowering Detection Engineering -
Sekoia
AI Agents in the SOC: 5 Production Questions To Ask Beforehand
Software releases/updates
-
Binalyze
Binalyze AIR 5.25 -
Canadian Centre for Cyber Security
Assemblyline 4.7.4.13 -
David Augros
sigwood v0.6.0 -
Didier Stevens
Update: base64dump.py Version 0.0.31 -
Digital Sleuth
winfor-salt v2026.12.2 -
Doug Burks
-
Foxton Forensics
Browser History Examiner — Version History – Version 1.23.5 -
Get-Sybers
DX_DFIR v0.5.0 — minimal hardened containers, offline packaging, CAR logic + per-OS validation -
Joey Victorino
phylaram PhylaRAM v0.1.0-alpha (pre-release) -
LEAPPs
-
Marco Neumann at ‘Be-binary 4n6’
Introducing Peach: A Companion for crush forensics, Built for Logs -
Metadata Forensics
HEART by Metadata Forensics Version 2.1.0.2 -
MISP
MISP v2.5.45 released – Overmind Everywhere, LDAP Reworked, Security Hardened and Many Fixes -
OpenCTI
7.260828.0 -
Renzon Cruz
irflow-timeline IRFlow Timeline 1.0.12 -
WithSecure Labs
Chainsaw v2.16.5 -
Yamato Security
suzaku v2.0.1 – El Niño Release -
Yaniv Radunsky
DFIR Companion v0.36.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.