| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Belkasoft
Apple Biome Forensics: Artifacts, Locations, and SEGB format -
Dr. Neal Krawetz at ‘The Hacker Factor Blog’
Validation Workflows -
Elcomsoft
-
Kenneth G. Hartman at Lucid Truth Technologies
How to Prove a Document Existed on a Given Date -
LEAPPs Blog
-
Jamie Mamroe and Matt Arbaugh & Joel Bowers at LevelBlue SpiderLabs
File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”) -
Ahmad Zaidi Said, Elsayed Elrefaei, Kaspersky Security Services at Securelist
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO -
Tim Korver at ‘Thesis Friday’
The stop rule: absence needs proven coverage – Thesis Friday #29:
Threat hunting/threat intelligence
-
Adam at Hexacorn
-
Oliver Smith at Aikido
Graphalgo campaign spreads to Terraform providers and Go Modules -
Any.Run
CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access -
Arctic Wolf
The Psychedelic Stealer: When a CAPTCHA Becomes an Installer -
ASEC
-
Jon Williams at Bishop Fox
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326 -
Nevan Beal, Sam Decker & Andi Ursry at Blackpoint Cyber
RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft -
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions -
BushidoToken
UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec -
Censys
Introducing Censys CLI Skills: AI-Assisted Investigations at Scale -
CERT Polska
-
CERT-AGID
- In corso un phishing a tema “bollo auto” ai danni di ACI
- MintsLoader via PEC: falsi solleciti di pagamento per diffondere malware
- Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows
- Sintesi riepilogativa delle campagne malevole nella settimana del 19 – 25 settembre
-
Check Point
21st September – Threat Intelligence Report -
Iris Suaner at Cofense
From Payment Plan to Ransomware – Inside a Global Group Attack -
Ctrl-Alt-Intel
Russian and Allied Government Systems Compromised in Targeted Campaigns -
Andrea Draghetti at D3Lab
An Italian Phishing Campaign Delivering an iOS Exploit Chain -
Dark Atlas
Rokarolla Android Banking Trojan: Analysis & Detection -
Darktrace
-
Detect FYI
-
Elastic Security Labs
Cloud Threat Emulation on Autopilot: Context is Everything -
Erik Hjelmvik at Netresec
Unmasking Malware Families -
Eyal Sela at Gambit Security
Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign -
Eye Research
-
FalconFeeds
CL0P: From Zero-Day Weaponization to Pure Extortion and the Underground War with ShinyHunters -
Flare
-
Flashpoint
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique -
g0njxa
Approaching stealers devs: a brief interview with Warden -
Gaetan Ferry at GitGuardian
GitHub App Private Keys: 474 Leaked Keys Exposed -
Google Cloud Threat Intelligence
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft -
Andrew Thompson, Mark Mager at GreyNoise
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation -
Halkyn Security
-
Huntress
- The Tale of Two INC Ransom Notes: A Ransomware Timeline | Huntress
- Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM
- OAuth Token Theft Through Microsoft’s Front Door | Huntress
- Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
- The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
-
Evgen Blohm at InfoGuard Labs
Iranopasmigirim – Unmasking an ever-evolving Espionage Campaign Against Iranian Dissidents – Part 1 -
Intel 471
2026 SANS Threat Hunting Survey: Adversaries Prizing Stealth over Speed? Defenders Cooling on AI? -
Adam Goss at Kraven Security
Detection as Code: A Pipeline That Won’t Flood Your SOC -
Matthew Coady at LevelBlue SpiderLabs
Enumerating Users and MFA via Microsoft’s Password Reset Portal -
Manifold
-
Microsoft Security
-
Eugenio Benincasa at Natto Thoughts
HuWang—“Protect the Network”: Inside China’s Largest Nationwide Live-Fire Cyber Exercise -
Ohad Zaidenberg
What Attackers Actually Do With AI -
Oleg Skulkin at ‘Know Your Adversary’
416. A Curious Case of Inhibit System Recovery -
OpenSourceMalware
PolinRider is A/B Testing its Way Past Your Detections -
Margaret Kelley at Palo Alto Networks
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies -
Proofpoint
Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts -
Push Security
The numbers behind ClickFix attacks in H2 2026 -
Recorded Future
The Lure Isn’t The Malware. It’s Your Logo. -
Robin Dost at Synaptic Systems
North Korea’s Hangro Revisited -
Ryan Fetterman at Cisco’s Talos
-
SANS Internet Storm Center
-
Security Alliance
SEAL weekly stats: Sept. 15-22, 2026 -
Akshay Gaikwad and Aaron Beardslee at Securonix
TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access -
Sekoia
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework -
SOCRadar
-
Spur Intelligence
Mellowtel: The Hidden Proxy Network Inside Everyday Browser Extensions -
Stephan Berger
The .zshrc.zwc You Forgot to Check -
Sygnia
When IT Support Is the Attack: How Law Firms Can Defend Against Silent Ransom Group -
Crystal Morin at Sysdig
Risky identities continue to plague cloud infrastructures -
The Hunter’s Ledger
Gotenberg CVE-2026-42589 Mass Exploitation and Cryptomining -
James McMurry at ThreatHunter AI
Living Off the Land: A Valid Signature Is Not a Business Reason -
Jack Cable, Daniel Chiu, Francisco Pernice, Selena Zhang, James Anthony, Tetiana Bas, Gary Shen, Conrad Stosz, and Jacob Steinhardt at Transluce
Early rogue AI agent activity and attempts to hack found on urlquery.net -
Trellix
-
Daniel Kelley at Varonis
Meet AvisLoader: A Windows Loader Built to Outlast a Takedown -
Damien Cash and Tom Lancaster at Volexity
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits -
Sina Kheirkhah (@SinSinology) at watchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) -
ZScaler
-
Блог Solar 4RAYS
Blockchain и ВПО: децентрализованное зазеркалье
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-09-28 -
John Hammond
Payload Podcast 012 – Yarden Shafir -
Magnet Forensics
Mobile Unpacked S4:E9 // Siri-ous intelligence: What iOS 27 means for digital forensics -
Sygnia
When IT Support Is the Attack: Defending Law Firms Against Silent Ransom Group
Presentations/podcasts
-
Adversary Universe Podcast
China’s 15th Five-Year Plan: What You Need to Know -
CQURE Academy
CQURE Hacks #83: Attack on Active Directory Certificate Services (AD CS) – ESC16 -
Huntress
-
InfoSec_Bret
IR – SOC154 – Service Configuration File Changed by Non Admin User (2026) -
Insane Forensics
Water Attacks, Typhoons, and Worst-Day Planning in OT | OT Office Hours -
Magnet Forensics
-
Monolith Forensics
-
Mostafa Yahia
Module 4: Investigating Network Threats – Agenda -
Open Source Forensics Lab
Extracting iOS Devices Using Oxygen Forensic Device Extractor (Archived) -
OpenSourceMalware
-
Paraben Corporation
Micro Webinar Apple Watch Data -
SANS Cyber Defense
-
Three Buddy Problem
Kernel Exploits in the iOS App Store, ShinyHunters Inside the FBI
Malware analysis
-
DCSO CyTec
Sauron Loader: A New Loader Lurking in Underground Forums -
Xiaopeng Zhang at Fortinet
Uncovering a SectopRAT Variant Embedded in Legitimate Software -
Karsten Hahn at G Data Software
OpenSUpdater Hides in Recompiled 7zip SFX -
Bruno Bijelić at Group-IB
RemControl: AI Built the Overlays. Victims Lose their PINs -
Itochu Cyber & Intelligence
PureRAT and PureLogs Campaign Targeting Japanese Organizations -
Jamf
PamStealer adapts again: a move to Swift with a server-side decryption chain -
Deepa B at K7 Labs
The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder -
Karlo Zanki at Socket
-
Lenny Zeltser
AI-Assisted Malware Analysis Tips -
Gabriele Orini at Malwarebytes
Kothamine malware uses Tailscale’s tailcat to evade network detection -
Rhys Downing at Ontinue
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD -
Ellis Stannard, Nick Smart, and Yashraj Solanki at Ransom-ISAC
XCTDH Adopts Hash Hiding -
Lucija Valentić at ReversingLabs
Malicious npm campaign targets developers integrating Twilio -
Sergey Puzan at Securelist
MacSync under the microscope: new delivery methods and a new payload -
Shubho57
Analysis of a VBScript Downloader -
Rohan Prabhu at Step Security
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes -
Janet Katile at Wordfence
Inside a Malicious, Stealthy WordPress Must Use Plugin -
Zhassulan Zhussupov
Malware analysis: part 12. Section entropy from scratch in pure C: a tiny packed/encrypted detector.
Miscellaneous
-
Christopher Eng at Ogmini
CISA IR Training – Ransomware Threat Hunting Workshop (IR309) -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 09/14/26 -
Elan at DFIR Diva
Techno Security & Digital Forensics Conference: October 20-22, 2026 -
Forensic Focus
- Finding Answers Faster: Genesis For Private Sector Investigations
- Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification
- Radim Motycka, Founder, Proofsnap
- How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics
- Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics
- Go Beyond The Basics With XRY Kiosk From MSAB
-
Google Cloud Threat Intelligence
Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure -
Jason Yung
Building an Automated SOC Playbook with Azure Sentinel, Logic Apps, and Microsoft Defender — Part 1 -
Jeffrey Appel
How to track browser extension installations with Microsoft Defender -
Jesse Spangenberger at ‘Cyber Fenix DFIR & Technology’
Metadata (Part 1): A Brief History -
Magnet Forensics
-
Matthew Plascencia
Extracting Phone Data With Oxygen Forensic Device Extractor -
MII Cyber Security
-
Bineesh P at Seqrite
Best Malware Analysis Platforms for Security Teams -
Kim Zetter at ZERO DAY
US-Based Digital Forensics Firm Hid its Russian Ownership from U.S. Government Customers
Software releases/updates
-
Alexandre Borges
Malwoverview 8.2.0 -
Binalyze
Binalyze AIR 5.27 -
Canadian Centre for Cyber Security
Assemblyline v4.7.4.stable21 -
DFIR-IRIS
IRIS-Web v3.0.0-beta.2 -
Digital Sleuth
winfor-salt v2026.12.6 -
Doug Burks
-
Halil Öztürkci
DFIR Swarm -
Marco Neumann
-
Martin Korman
-
Microsoft
msticpy ScanMalware TI Provider, Python 3.14 and dependency updates -
OpenCTI
7.260921.0 -
Ryan Benson at Hindsight Foundry
Parsers for Gmail, Outlook Safe Links, Social Media IDs added in Unfurl -
SigmaHQ
pySigma v1.5.1 -
Stark4n6
Arc2Lite v3.2.0 -
Yaniv Radunsky
DFIR Companion v0.38.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!