| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Belkasoft
-
Forensic Science International: Digital Investigation
Volume 58 September 2026 -
HackHunterLabs
Let’s Talk About SRUM: Why SOC Analysts Should Know About It. -
Invictus Incident Response
Google Workspace Incident Response: 3 Logging Problems | Invictus Incident Response -
North Loop Consulting
Jot this down…Text.InputSession Biome Entries -
Rob T. Lee
Living Off the Land, AI Edition: Attackers Are Using the Coding Agents You Gave Your Developers -
Seth Enoka
Windows Registry Forensics: The Registry as Narrative -
Блог Solar 4RAYS
DFIR diggin’ deeper: неочевидные источники значимых артефактов атак
Threat hunting/threat intelligence
-
0xMatheuZ
-
Aikido
-
Anthropic
Detecting and countering misuse of AI: September 2026 -
Australian Cyber Security Centre
Digital camouflage: crypters make malware undetectable -
Jon Williams at Bishop Fox
Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490 -
Jade Brown at Bitdefender
Bitdefender Threat Debrief | September 2026 -
Gábor Lázár at Black Cell
Monthly Adversary Tradecraft Spotlight – August -
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
Microsoft Plugs Nearly 1,000 Security Holes -
Daniel Whitcombe, Alex Jones, and Nathan Richards at Bridewell
Intelligence Insights: August 2026 -
CERT-AGID
Sintesi riepilogativa delle campagne malevole nella settimana del 5 – 11 settembre -
Check Point
- NoName057(16) Renews #OpJapan
- 7th September – Threat Intelligence Report
- The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
- ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
- August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
- PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
-
Cisco’s Talos
-
Gagan Aggarwal at CloudSEK
Tracking BigBear 2.0 Evilginx2 Phishing Campaign -
Cofense
False Allegations, Real Threats: Sexual Misconduct Claims Used as Phishing Lures -
Ben Reardon at Corelight
Hunting LDAP Injection Canaries on Port 389 | Corelight -
Ctrl-Alt-Intel
-
Cyble
-
Cyderes
-
darkdefender
Hunting AI Use — Part Two -
Detections Wiki
TWINLOOT: Microsoft 365 as C2 -
Disconinja
-
Elastic Security Labs
Linux Detection Engineering – Local Privilege Escalation -
Eric J. Taylor at Barricade Cyber Solutions
- Financial Services Breach Response: How Barricade Investigates Bank and Credit Union Incidents
- Kali365 Evolves: From Device-Code Phishing to a Full AiTM Platform, Plus a New Zer0day Spin-off
- Stop Patching Everything – Start With What Ransomware Crews Are Actually Using
- ShieldCrash: New Defender Exploit Shows the ShieldBreak Patch Is Incomplete
-
Gen
-
Genians
AI Agent ‘opencode’로 미끼를 만든 김수키, GitHub PAT 기반 LNK 공격 진화 -
Google Cloud Threat Intelligence
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI -
GreyNoise
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF -
Group-IB
-
Halkyn Security
- Function Calls and Stack Frames Explained
- Staffing a Threat Hunting Team: Build or Buy
- Insider Investigation Authorisation Comes First
- Linux Host Telemetry: Sysmon and Kunai
- Hunting Visibility: Knowing What You Can See
- LLM Evidence on Linux: The Artefact Map
- Finding Hidden Processes and Ports on Linux
-
Hunt IO
-
Huntress
-
Intel 471
Follow the Money: The Financial Sector’s Threat Landscape in 2026 -
Adam Goss at Kraven Security
Lazarus Group: The Complete Guide to North Korea’s Billion-Dollar Hacking Machine -
Serhii Melnyk and Timmy Lister at LevelBlue SpiderLabs
Expanding the Attack Surface: Analyzing Nightmare-Eclipse’s Latest PoCs -
Mehmet Ergene at Blu Raven Academy
A Look into the Borrowing Windows Hello Keys Attack -
Microsoft Security
-
Eugenio Benincasa at Natto Thoughts
Widening the Circle of Chinese Hacker Group QTFY: ELEX’s Intelligence Client List and Lexbell’s PLA Contracts -
Ohad Zaidenberg
Your Sector Is Not Your Threat Model -
Okta
Signing in without actually signing in | Threat Intelligence -
Oleg Skulkin at ‘Know Your Adversary’
414. That’s How Threat Actors Abuse Direct Volume Access -
Neetrox at OSINT Team
Automated Threat Hunting for Wazuh: Here Is What a Real Weekly Report Looks Like -
Palo Alto Networks
-
Ridgeline Cyber
The Linux Process That Lies About Its Own Name -
SANS Internet Storm Center
- Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)
- September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
- Scans for Proxmox Servers, (Wed, Sep 9th)
- Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
- The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
-
Sansec
StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack -
Security Alliance
SEAL weekly stats: Sept 1-8, 2026 -
Sekoia and Kudelski Security
Beyond Lazarus: How North Korea Organizes Its Cyber Operations -
Chandra Kant Bauri at Seqrite
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures -
SOCRadar
Dark Web Market: Anubis Market -
Sygnia
Shai-Hulud in the Wild: What Security and Incident Response Teams Need to Know -
Sysdig
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit -
System Weakness
I Added Wazuh to My SOC Lab. The Biggest Change Wasn’t More Logs. -
The Hunter’s Ledger
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17 -
Lauren Proehl at THOR Collective Dispatch
Open Season: Passive DNS -
James McMurry at ThreatHunter AI
What We Actually Know About Iranian Cyber Activity Against U.S. Targets in 2026 -
ThreatMon
-
John Fokker and Adam Rocker at Trellix
Trellix SecondSight Threat Hunting Report: How AI and Human Intelligence Expose 2026 Cyber Threats -
Umut Bayram at Umut Bayram at Picus Security
DarkTortilla Malware: How It Works and How to Test Your Defenses -
Snehal Patel at Vectra AI
What the Hugging Face Incident Teaches Us About Behavioral Detection in Agentic Attacks by Snehal Patel -
Ankur Saini, Conor Quigley, Sean Koessel, Steven Adair, and Tom Lancaster at Volexity
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows -
Wiz
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-09-14 -
CQURE Academy
Close the Attack Visibility Gap: Detecting Defense Evasion and Reconstructing Attacks in Microsoft Environments -
Magnet Forensics
-
Off By One Security
Breaking Windows: Exploring Security Through Kernel Drivers
Presentations/podcasts
-
Adversary Universe Podcast
Preparing for an AI-Powered Future with Amazon CSO Steve Schmidt -
CYBERWARCON
CYBERWARCON Keynote -
InfoSec_Bret
IR – SOC151 – Unauthorized Root Access -
Karsten Hahn at Malware Analysis For Hedgehogs
Malware Analysis – Hooking V8 JavaScript bytecode -
Magnet Forensics
- Digitas Consulting streamlines multi-source investigations with the Magnet ecosystem
- $10 trillion vs. $300 billion: A former FBI investigator on why cybersecurity investment needs to shift toward recovery
- Cyber Unpacked S3:E5 // What to expect when you’re (not) expecting an incident
- From tip to action: Managing NCMEC cyber tips at scale
-
Maxim Suhanov
Two conference talks (slides) -
Microsoft Threat Intelligence Podcast
Why Threat Actors Love Your RMM -
Monolith Forensics
-
Mostafa Yahia
-
MyDFIR
How Daniel Built Investigation Skills Without Security+ | MYDFIR Forge -
OpenSourceMalware
The OpenSourceMalware Show #20 -
Parsing The Truth: One Byte at a Time Podcast
S2 E11: TN vs Ahmad Gatlin Part 1 -
SANS Cyber Defense
Counterintelligence in the Age of Open Source -
The Weekly Purple Team
Defender Please Stop Hitting Yourself -
Three Buddy Problem
AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit
Malware analysis
-
Moises Cerqueira at Any.Run
HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures -
ASEC
Detection and Removal of the Syslogk Rootkit in a Linux Environment -
Darren Williams at BlackFog
Bee Stealer Targets Codex And Claude, Uses AI To Profile Victims -
Dark Atlas
Hagaseca: Inside a Packed Android RAT Loader -
Rachael Liao at Fortinet
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers -
Socket
-
Sophos
-
Splunk
Peeling Back the Layers: Inside Vidar – From Virtualized Code to Stolen Credentials -
Tony Lambert at ZScaler
SloppyRAT: A New Tool For Ransomware Attacks
Miscellaneous
-
Anton Chuvakin
Survival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers? -
Cellebrite
-
CyberBoo
Microsoft Defender for Office 365 Part 13: Reporting & Monitoring – What to Watch and When to Act -
Sergio Albea at Detect FYI
CYBER HUNTER PROJECT Book — What You Will Find Inside -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 09/07/26 -
Elan at DFIR Diva
Introducing DFIR, OSINT, & Cybersecurity Community Listings -
Forensic Focus
-
Jeffrey Appel
Microsoft Defender XDR Attack Disruption: Automatic Device Isolation Explained -
Mat Fuchs
The First Four Hours: What Actually Matters in a 100k-Endpoint Incident -
Yevgeniy Kapishon at Paraben Corporation
Before Direct NAND Acquisition: Diagnosing an Undetectable Monolithic SD Card
Software releases/updates
-
Binalyze
Binalyze AIR 5.26 -
Digital Sleuth
winfor-salt v2026.12.4 -
Erik Hjelmvik at Netresec
PolarProxy 2.0.2 Released -
Agapios Tsolakis at Falcon Force
Introducing FalconDash, your tuning companion -
LEAPPs
-
Muhammad Daffa
vol-rs v1.0.1 -
OpenCTI
7.260910.0 -
radare2
6.2.2 -
Renzon Cruz
irflow-timeline v1.0.13 -
Security Onion
-
Thiago Canozzo Lahr
Unix-like Artifacts Collector uac-3.4.0 -
Xways
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.