| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
ADF Solutions
Finding Evidence After an App Is Deleted -
Alexis Brignoni at LEAPPs Blog
-
Andrew Garrett & Owen Garrett
Are You Receiving the Native File or a Curated Version in Discovery? -
Ian Whiffin at DFIR Review
BrowserState.db last_viewed_time? -
Forensafe
-
Kenneth G. Hartman at Lucid Truth Technologies
Share Link Forensic Artifacts: What a Share Link Records, and What It Doesn’t -
Kevin Pagano at Stark 4N6
Pouring Pints – Untappd for Android Analysis -
MII Cyber Security
-
Ovie Caroll
SAIDI in the Inbox: When the Account Sent It, but the Person Did Not Write It -
S.Nakano
Don’t Make AI Your Forensic Analyst -
The DFIR Report
BengalSEO Part 1: Anatomy of the Operation -
Tim Korver at ‘Thesis Friday’
Thesis Friday #27: Backward reasoning from a provable endpoint
Threat hunting/threat intelligence
-
0xMatheuZ
Singularity Rootkit: Evading Elastic Defend Module Load Detection -
Hunter Schwartz at Aikido
The dark figure of supply chain detection -
Larry Cashdollar at Akamai
Analyzing a Go-Based IoT Self-Propagating DDoS Botnet -
ASEC
-
Ayelen Torello at AttackIQ
Updated Response to CISA Advisory (AA25-071A): #StopRansomware: Medusa Ransomware -
AWS Security
-
Rebecca Harpur at BlackFog
The State of Ransomware: August 2026 -
Mayank Parmar at BleepingComputer
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage -
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
FBI Probes Service Selling 153M+ Drivers Licenses -
BushidoToken
UK Cybercrime Journal: ExfilSquad Emerges -
Alex Gartner at Censys
So Your CFO’s Phone Has Been Pwned: A DFIR Journey -
CERT-AGID
-
Check Point
-
Reegun Jayapaul, Mohammed Fayiz, Hodlur Shravan, and Brian Hussey at Cyderes
Inside an Indian Data Brokerage Running on Unauthorized KYC Access -
Dark Atlas
DragonForce Ransomware Analysis: Inside a Verified Windows Locker -
Martin McCloskey at Datadog Security Labs
Password spraying campaign targets AWS root user accounts across 150+ organizations -
Brian Donohue and Oren Biderman at Daylight Security
A Defender’s Guide to the Hugging Face Intrusion -
Disconinja
Weekly Threat Infrastructure Investigation(Week35) -
Dzianis Skliar
Internal OSINT: Post-Compromise Reconnaissance Beyond BloodHound -
Elastic Security Labs
-
Eric J. Taylor at Barricade Cyber Solutions
-
Erik Hjelmvik at Netresec
OT Networks Still Need Monitoring -
Martin Chlumecký and Luis Corrons at Gen
The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign -
Google Cloud Threat Intelligence
Financially Motivated Threat Actor BREEZE COMET Targets Brazil -
Viacheslav Shevchenko and Brandon Tan at Group-IB
The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action -
Ryan Voit at GuidePoint Security
Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials -
Halkyn Security
- How the Stack Works in Assembly Language
- Building a Threat Hunting Business Case
- Insider Threat Investigation: Evidence and Process
- SSH Forensics: What an Intrusion Leaves Behind
- Writing a Threat Hunting Hypothesis That Works
- Investigating Self-Hosted LLM Systems on Linux
- Building a Quick Linux Host Timeline
- Autopsy Plugins for Linux Evidence
-
Hunt IO
Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia -
Loay Salah at InfoSec Write-ups
WebStrike Blue Team Lab (CyberDefenders) -
Intel 471
Chinese-speaking threat actors targeting Mexican Android users with remote access Trojan -
Invictus Incident Response
AI-Generated BEC Phishing from a Compromised Mailbox | Invictus Incident Response -
Andrew Heller at Lares
Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026) -
Chris Botelho at LimaCharlie
Threat Hunting to Detection Engineering, Part 2: Validating Rules Against Live Malware with Claude and LimaCharlie -
Microsoft Security
-
Roberto Rodriguez and Neha Hudait at NVIDIA
Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron -
Palo Alto Networks
-
Recorded Future
H1 2026 Malware Vulnerability Trends -
Reversec Labs
Virtual//Attack -
Ridgeline Cyber
The Ransomware Step That Happens Before the Encryption -
SANS Internet Storm Center
- YARA-X 1.20.0 Release, (Sun, Aug 30th)
- The Coding-Agent Trap: When a “Free” LLM Endpoint Is the Adversary, (Mon, Aug 31st)
- Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
- Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
- numbat – AI agent observability, (Fri, Sep 4th)
-
Sansec
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack -
Securelist
-
Security Alliance
SEAL weekly stats: August 25-31, 2026 -
Securonix
Clop Never Left: Inside the PTC Windchill Data Theft Campaign -
Siddhant Mishra
Unmasking SideCopy and Mshta-Based Staging in South Asian Espionage -
Simone Kraus
-
Sophos
Ungentlemanly behavior: Insights into a ransomware operation -
Evelyne Diaz Araque at Stairwell
From ClickFix to SilentEncryptor: A Simple Yet Destructive Path to Ransomware Deployment -
Start With Linux
Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint -
Sygnia
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure -
Symantec Enterprise
Node.js: Old Technique Makes a Comeback -
Quentin Roland at Synacktiv
Simuler des services Active Directory légitimes sur un réseau interne : le cas de l’exploitation de GPO -
System Weakness
-
Lefebvre Fabien and Vincent Fournier at Tehtris
Threat Intelligence report – September 2025 -
The Hunter’s Ledger
Carrier Credential Harvesting Through a Customer’s Router -
Adam G. Tomeo at Trellix
The Invisible Office Break-In: Understanding Kerberoasting Attacks and SPN Exploits -
Lilly Mayo at TrustedSec
waf-fu, or Some Log Replay Nonsense -
Lucie Cardiet at Vectra AI
The Credentials Were Rotated. They Still Worked. -
VMRay
Pivoting in MISP: From Individual Indicators to Broader Threat Context -
Блог Solar 4RAYS
Solar 4RAYS: хроники DFIR в первом полугодии 2026 года
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-09-08 -
Huntress
Tradecraft Tuesday | Borrowed Faces, Borrowed Certs: Inside a Post-DEF CON Malware Campaign -
Magnet Forensics
Presentations/podcasts
-
Dr Josh Stroschein
In-Memory Unpacking & PE-Sieve Analysis | Packing & Obfuscation Lesson 04 -
Endace
Integrating CrowdStrike NG SIEM with Endace Always-on Packet Capture -
Huntress
-
Magnet Forensics
-
Monolith Forensics
-
Paraben Corporation
-
Proofpoint
Intercepted: How Hackers Take On the Cloud -
Richard Davis at 13Cubed
Windows Forensics on a Mac?! You Have to See This! -
SANS Cyber Defense
Keynote: GenAI as an OSINT Force Multiplier -
Team Cymru
Ironbridge CISO Consulting’s Jim Almerico on the end of AI euphoria and the flaws emerging -
Three Buddy Problem
Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs. -
Watson Infosec
COPILOT HUNTS A RAT
Malware analysis
-
ASEC
“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing -
Chamindu Pushpika at ChamX
Anatomy of SystemOptimizer – A BYOVD EDR Killer with a UAC Bypass -
Julio Guapo Menezes and Miguel Salazar at Group-IB
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem -
Allen Golbig at Jamf
Contagious Interview steps outside the developer workflow -
Netskope
-
Rapid7
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors -
Pavel Bukhtenko at Securelist
ValleyRAT masquerading as adware -
Shubho57
Analysis of a sample leads to the activities atrributed to a Wiper -
Kush Pandya at Socket
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds -
ThreatFabric
Uncovering StreamRat: From Meta Ads to Full Device Takeover -
Zhassulan Zhussupov
-
Шифровальщики-вымогатели The Digest “Crypto-Ransomware”
TargetZimbra, Elock
Miscellaneous
-
Chris Tappin at 5∩6
A New Model of Incident Response -
Amnesty International Security Lab
Strengthening the tools behind consensual forensics investigations: Mobile Verification Toolkit & Android Quick Forensic Secure Design Assessment -
Cellebrite
-
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 08/31/26 -
Mike Nichols and Jamie Hynds at Elastic Security Labs
Data access: the hidden cost of security vendor lock-in -
Forensic Focus
- Techno Security & Digital Forensics Conference Returns To San Diego October 20–22, 2026
- Digital Forensics Round-Up, September 02 2026
- Semantics 21 Asks The Uncomfortable Question Every Review Team Should Be Asking
- Cellebrite Genesis: Turn Digital Evidence Into Actionable Leads In Minutes
- Belkasoft Named A Major Player In The IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment
- “The Skills And Resilience To Do One Of The Hardest Jobs In Policing” — Why This DFIR Recruitment Language Gets The Evidence Wrong
- Forensic Focus Digest, September 04 2026
-
Jurjen Harskamp at Hunt & Hackett
Recent cyberattacks show how little organisations really know during an incident -
IC3
Communicating Under Pressure: Best Practices for Service Providers -
Kevin Pagano at Stark 4N6
-
Steve Gemperle at Magnet Forensics
Digital fraud in a connected world: how it works and how to prevent it -
Matthew Plascencia
Belkasoft X vs Oxygen Forensic Detective vs ADF Pro… -
NSB Cyber
#NSBCS.140 – What Policing Taught Me About Ransomware Investigations -
Rob T. Lee
Investigation template defined for AI accidents? (Hugging Face OpenAI Updates, Risks) -
Sysdig
Defending the battlefield: Stateful detections for an agentic threat landscape
Software releases/updates
-
13Cubed
Abeebus 2.1 -
Arsenal Recon
Swap Recon Changelog – v1.0.0.16 -
Canadian Centre for Cyber Security
Assemblyline 4.7.4.17 -
David Augros
sigwood v1.0.0 -
Elcomsoft
Elcomsoft Quick Triage 2.2 adds a timeline, a plugin system, and file system snapshots -
Exterro
FTK Imager 8.3 -
Get-Sybers
DX_DFIR v0.6.0 — materialized MITRE CAR -
Ghassan Elsman
Crow-Eye v0.13.0 Registry Depth & Timeline Coverage -
LEAPPs
VLEAPP v2026.3.2 -
Metaspike
Forensic Email Intelligence 2.3.916 -
North Loop Consulting
Maps! Galleries! Speed! Sedgwick Version 2.0! -
OpenCTI
7.260904.0 -
Xways
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.