| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Eoghan Casey and Francesco Servida at DFRWS
Introducing Container Hashes for AFF4-L -
Dr. Neal Krawetz at ‘The Hacker Factor Blog’
SEAL Tested, Hardened, and Honest -
Michael Karsyan at Event Log Explorer blog
7 Best Windows Event Viewer Alternatives for Log Analysis in 2026 -
Forensafe
-
Satyender Yadav at ThreatBreach
Story of a ZIP File -
Tim Korver at ‘Thesis Friday’
Thesis Friday #28: What a busy phone forgets
Threat hunting/threat intelligence
-
Abdulrehman Ali
Charming Kitten APT Adversary Simulation -
Ryan Devendorf at Abnormal Security
ORAX Conducts AiTM Without a Reverse Proxy -
Acronis
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit -
ASEC
-
Eric J. Taylor at Barricade Cyber Solutions
NightSpire Ransomware: Threat Actor Profile -
Ben Kapon at KELA Cyber
-
Bishop Fox
-
Blackpoint Cyber
-
Lawrence Abrams at BleepingComputer
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang -
Brian Krebs at ‘Krebs on Security’
Data Broker Radaris Loses Domains in Privacy Fight -
Bruno Oliveira at SVA Security Log
-
CERT-AGID
-
Chainalysis
DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks -
Check Point
-
Takahiro Takeda, Jordyn Dunk, Michael Szeliga at Cisco’s Talos
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use -
Josh Varden at Cofense
Chatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPT -
Maddie Stewart at CrowdStrike
PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting -
Damien Lewke
Harness Racing -
Datadog Security Labs
-
Sergio Albea at Detect FYI
Threat Hunting with JA4/JA4S (+ Practical KQL Queries) -
Disconinja
Weekly Threat Infrastructure Investigation(Week38) -
Elastic Security Labs
-
Esentire
GhostCode: Dissecting a Novel Device Code Phishing Kit -
Ryan Marshall at Foregenix
Magento “StyleSmuggler” Zero-Day (CVE-2026-75650): Patch Guide -
g0njxa
Approaching stealers devs: a brief interview with Remus -
Gen
-
Group-IB
-
Jean-Pierre Mouton at GuidePoint Security
EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight -
Halkyn Security
-
HP Wolf Security
HP Wolf Security Threat Insights Report: September 2026 -
Shivangi Pandey and Matt Anderson at Huntress
How Attackers Abuse VSS, and How Huntress Detects It -
IC3
- Update on Government of Iran Cyber Actors’ Deployment of Telegram C2 to Push Malware to Identified Targets
- North Korean “WaterPlum,” commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe
-
Kevin Hoganson and Mateusz Krzywicki at iVerify
Proliferation of Coruna and DarkSword -
Yuval Moravchick at JFrog
ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell -
Keisuke Shikano at JPCERT/CC
TSUBAME Report Overflow (Apr-Jun 2026) -
Serhii Melnyk and Timmy Lister at LevelBlue SpiderLabs
One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed -
Maltego
Mapping North Korea’s Illicit Shipping Networks with GEOINT and Maltego -
NCSC
Iranian cyber targeting of dissidents, activists and journalists -
Brandon Schwartz at Nebulock
Hunt Mode: Your Network’s Adversary Might Be Poor Hygiene -
Obsidian Security
-
Ohad Zaidenberg
The Attacker Is Not a Group. It Is a Supply Chain. -
Rafa Bono at Okta
Detecting shadow AI agents with advanced posture checks -
Oleg Skulkin at ‘Know Your Adversary’
415. Threat Actors Abuse IronPython to Deliver Malware -
Palo Alto Networks
-
Recorded Future
Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group -
Ridgeline Cyber
Your Logs Have a Gap. That Is Not Evidence Anybody Deleted Them. -
Casey O’Brien at S-RM
From AI to incidents: What the first half of 2026 tells us about the cyber threat landscape -
HuiSeong Yang and SeungHo Lee at S2W Lab
Ransomware Landscape in H1 2026: Statistics and Key Issues -
SANS Internet Storm Center
-
Sansec
Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware -
Securelist
-
Security Alliance
SEAL weekly stats: Sept. 8-14, 2026 -
SentinelOne
-
Silent Push
-
SOC Fortress
-
Socket
-
SOCRadar
Agentic Ransomware: From Human-Operated to AI-Operated Attacks -
Marchelle David at Sophos
ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split -
Stephan Berger
-
Marco A. De Felice aka amvinfe at SuspectFile
EXCLUSIVE: Storm introduces automated ransomware negotiations: AI enters the process, but humans remain behind the scenes -
Team Cymru
From the Disk to the Flows: Ransomware Infrastructure Analysis -
The Raven File
SETTRA RANSOMWARE -
Josh Rickard at THOR Collective Dispatch
Open Season: Domain Profiling -
James McMurry at ThreatHunter AI
AiTM Phishing: Scoring Identity Risk Is Not the Same as Stopping the Session -
ThreatMon
Xan-RAT A Closer Look at Its Capabilities and Inner Workings -
Trellix
-
Elad Ghvarh at Varonis
TrustSink: How a Rogue External MFA Provider Steals Passwords -
Yali Gottlib, Matan Haim, Itay Harel, and Tal Moriah at Wiz
Building an AI Detection Engine That Understands Agent Intent
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-09-21 -
John Hammond
Payload Podcast 011 – Reunion -
Magnet Forensics
-
SANS
-
Spur Intelligence
Beyond Human vs. Bot
Presentations/podcasts
-
Behind the Binary by Google Cloud Security
EP29 Binary Similarity in the LLM Era with Jonas Wagner and Endre Bangerter of ThreatRay -
Belkasoft
AI in Forensics: Why the Human Investigator Still Makes the Call | BelkaGPT -
Blue Team بالعربي
-
InfoSec_Bret
IR – SOC153 – Suspicious Powershell Script Executed -
John Hammond
My Browser Cache Got Infected -
Magnet Forensics
-
Monolith Forensics
-
Mostafa Yahia
-
MyDFIR
He Applied to Hundreds of SOC Jobs | Here’s What Finally Changed -
OpenSourceMalware
The OpenSourceMalware Show #21 -
Parsing The Truth: One Byte at a Time Podcast
TN vs Amad Gatlin: Part 2 -
Proofpoint
Once in a BlueMoon: Inside the Exploit Chain Four Espionage Groups Adopted in Days -
SANS Cyber Defense
-
Secure View
-
Stephan Berger
BSides Frankfurt: Deconstructing Modern macOS Initial Access Vectors -
Team Cymru
Efani’s Mark Kreitzman on the SIM swap that cost Marks and Spencer 350 million euros
Malware analysis
-
Ashwath Ram at K7 Labs
From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain -
OpenSourceMalware
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials -
Ransom-ISAC
MacOS ClickFix AMOS Campaign -
Shubho57
Analysis of OpnKey Ransomware -
Scott Nusbaum at TrustedSec
Unpacking a laZzzy Donut -
Alexandre Côté Cyr and Romain Dumont at WeLiveSecurity
Beware the SparroWock: The backdoor that bites, the commands that catch -
Zhassulan Zhussupov
MacOS malware persistence 13: man.conf. Simple C example -
Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega at Zimperium
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts -
Sudeep Singh at ZScaler
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Miscellaneous
-
Adam at Hexacorn
Win11_26H2 build xta phantom libraries -
Emi Polito at Amped
How to Prepare Compelling and Safe Digital Multimedia Evidence for Court with Amped Replay -
Berla
-
CyberBoo
Microsoft Defender for Office 365 Part 14: Migrating to MDO from a Third-Party Secure Email Gateway -
Decrypting a Defense
Fighting Beyond Flock, Cell Tower Dump Decision, Government Subpoenas for Digital Corporate Records & More -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 09/14/26 -
Disconinja
CAPEsoloをWindows 11で構築してみた / Getting Started with CAPEsolo on Windows 11 -
Forensic Focus
- Forensic Imaging Is A Workflow Problem, Not Just A Speed Problem
- The Excluded Evidence Problem Semantics 21 Is Exposing
- Semantic Search Vs Keyword Search In Digital Forensics – Why It Matters | BelkaGPT
- Steganos Data Safe Evolves – New Shortcuts for Decryption
- A Stab Vest Is Protection. DFIR “Resilience” Is Not.
- Forensic Focus Digest, September 18 2026
-
Jason Yung
由Azure Sentinel+Logic App+AI砌一套自動化 SOC Playbook — 第一篇:架構設計 -
Kate Carruthers
When the Test Becomes the Threat Model -
Magnet Forensics
-
Amber Schroader at Paraben Corporation
The Four Foundation Questions of Digital Forensics -
Rob T. Lee
Secure What Is Already Here: The doom scenarios deserve an investigation -
Ryan Benson at Hindsight Foundry
Introducing Hindsight Foundry -
Salvation DATA
CDR Analysis: Finding Patterns and Investigative Leads in Communication Data -
Taggart Tech
Everone Is Lying To You For Money
Software releases/updates
-
Brian Maloney
OneDriveExplorer v2026.09.15 -
Canadian Centre for Cyber Security
Assemblyline 4.7.4.20 -
Digital Sleuth
winfor-salt v2026.12.5 -
GCHQ
CyberChef v11.5.0 -
LEAPPs
-
Metadata Forensics
HEART Version 2.2.0.0 -
Olaf Hartong
Sysmon Modular, a new toolkit for building and tuning your configuration -
OpenCTI
7.260917.0 -
Passware
Steganos Data Safe Evolves – New Shortcuts for Decryption -
Ryan Benson
unfurl v2026.09 -
Volatility Foundation
Volatility3 Volatility 3 2.28.2 -
Yamato Security
Hayabusa v4.1.0 – Suzumushi Release -
Yaniv Radunsky
DFIR Companion v0.37.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.