| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Adam at Hexacorn
The boring state of stalled timelines… -
Christopher Eng at Ogmini
-
Forensafe
-
Alexis Brignoni at LEAPPs Blog
Nineteen New Unified Log Artifacts for iLEAPP and DLEAPP -
S.Nakano
a tale of volatile memories. -
Stephan Berger
Field Notes: Reconstructing the Attacker’s LSASS Dump -
Tim Korver at ‘Thesis Friday’
From device to searchable text: how I work with the Unified Log – Thesis Friday #30 -
Yogesh Khatri at ‘Swift Forensics’
Tags in Safari History db
Threat hunting/threat intelligence
-
ASEC
- Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability
- Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
- Beware of phishing emails disguised as quote requests
- August 2026 Threat Trend Report on Ransomware
- Security Issues in the Korean & Global Financial Sector in August 2026
- SilverFox: Tracking the Distribution of a Domestic Variant of a Malicious Installation File Posing as KakaoTalk
- Beware of SMS messages claiming to protect your Pi Coin account—phishing sites are stealing wallets
- Beware of Malware infection in Facebook Ads Offering Cryptocurrency Rewards
- August 2026 Threat Trend Report on APT Attacks (South Korea)
-
BI.Zone
-
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation -
CERT EU
Taking ‘execute logging’ a bit too literally – CVE-2026-88771 -
CERT-AGID
-
Chainalysis
How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget -
Check Point
28th September – Threat Intelligence Report -
Ashley Shen at Cisco’s Talos
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor -
Cleafy Labs
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat -
CloudSEK
-
Eliya Stein at Confiant
Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation -
Ben Reardon at Corelight
Hunting Citrix NetScaler Zero-Days with Corelight -
CQURE Academy
The Nightmare Is Over: World’s Longest-Running DDoS Service Finally Shut Down -
Hananel Livneh at CrowdStrike
Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them -
Daniel Koifman
-
Ialle Teixeira at Debugactiveprocess
Reverse Engineering as Counterintelligence in 2026: From Malware Artifacts to Defensive Decisions -
Disconinja
-
Düzgün
MuddyWater’s Rented Arsenal and Its Traces in the Russian MaaS Market -
Eric J. Taylor at Barricade Cyber Solutions
-
FalconFeeds
Inside the Cybercrime Power Struggle: Rivalries, RaaS Fractures, and Underground Conflict -
Flare
- The Overlooked Healthcare Attack Surface: 1,057 FHIR Endpoints and 656 HL7 Systems Found Without Sending a Single Packet
- Hacker-for-Hire Economy: How Cyber Mercenaries Turned Digital Revenge Into a Business
- The Airport isn’t Online but its Directory is: A Sector-Wide Look at What DNS Reveals About Aviation Infrastructure
-
Flashpoint
Ransomware Risk Model: Flashpoint’s Patented Scoring Method to Inform Vulnerability Prioritization -
John Althouse and Sébastien Féry at FoxIO
Introducing JA4Scan: Active Server Fingerprinting for TLS and QUIC -
Luis Corrons and Jan Rubín at Gen
Your IP, Their Traffic -
Yoni Gottesman and Noam Kesten at Glow
PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies -
Google Cloud Threat Intelligence
-
Group-IB
-
Halkyn Security
- Bitwise Operations: AND, OR, XOR and Shifts
- Threat Hunting Metrics That Convince a Board
- Kunai Threat Hunting Poster: Free A3 Download
- Model File Formats That Execute Code
- Insider Data Exfiltration: What It Looks Like
- LD_PRELOAD Detection: Dynamic Linker Hijacking
- Identity Threat Hunting in Cloud Environments
- Investigating MCP Server Compromise
-
Huntress
-
Intel 471
Insiders for Hire: How the Underground Market for Employee Access is Evolving Insider Risks -
Invictus Incident Response
Stolen GitHub Token (PAT): Incident Response Guide | Invictus Incident Response -
Mateusz Krzywicki at iVerify
WeWorm(s) Armageddon: Mobile Edition -
James McMurry at ThreatHunter AI
-
LevelBlue SpiderLabs
-
Ax Sharma at Manifold
Rogue agents hit US gov sites and a second Australian dashboard -
Manuel Winkel at Deyda Consulting
-
Mat Fuchs
When CreateProcess Is the Write -
Microsoft Security
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
- Star Blizzard refines phishing and malware delivery with the RedFlick technique
- Beyond source code: A path to the keys to the kingdom
- Phishing Abuses RMM Tools for Persistent Access
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
- Insights from the 2026 Microsoft Digital Defense Report
-
MII Cyber Security
-
Mostafa Farghaly
Unmasking Lawxsz: Attributing the Developer Behind Valkyrie and Prysmax Stealers -
Alex Hurtado at Nebulock
The GATES Method: When a Threat Hunt Becomes a Detection -
Florian Roth at Nextron Systems
New THOR Detection Coverage for Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 -
Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko at OX Security
PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels -
Palo Alto Networks
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild -
Promon
App Threat Report Q3 2026: GPU debugger abuse in Android apps -
Proofpoint
-
Resecurity
Session Cookie Authentication Bypass: Predictable Signing Secret Enableds Account Impersonations -
Zaria Vuksan at ReversingLabs
Restrospective: How Malicious Updates Poison Your Environment -
Robin Dost at Synaptic Systems
How Russia’s “Media Land” Kept Routing After Sanctions -
SANS Internet Storm Center
- Wireshark 4.6.9 Released, (Sun, Sep 27th)
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
- Scans for Wordfence Protected Websites, (Tue, Sep 29th)
- ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
- YARA-X 1.21.0 Release, (Sat, Oct 3rd)
- User Agent Strings Curiosities, (Sun, Oct 4th)
-
Security Alliance
-
SentinelOne
-
Ayush Singh Sachan at Seqrite
Inside DragonForce: How a Ransomware Cartel’s Payload Actually Runs -
Sina Kheirkhah at watchTowr Labs
-
Sarah Gooding at Socket
New AISI Report Details How GPT-6 Astra Turned CTF Challenges Into Supply Chain Attacks -
Gabriel Barbosa at Sucuri
SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor -
Marco A. De Felice aka amvinfe at SuspectFile
ShinyHunters vs. Cl0p: The Attack on the Site, the Dispute, and Qilin’s Position -
Omer Kidron, Roey Bartov, Josh Geise, and Avishay Asido at Sygnia
Actively Exploited NetScaler Vulnerabilities -
Symantec Enterprise
Warlock Ransomware Attackers Hit Water and Telecom Operators -
The Hunter’s Ledger
FACEIT ClickFix Pages Point CS2 Players to a Script URL That VirusTotal Ties to a Steam-Focused Executable -
Sydney Marrone at THOR Collective Dispatch
Teaching Machines to Be Curious -
ThreatMon
-
Ugur Koc and Bert-Jan Pals at Kusto Insights
Kusto Insights – Summer Update -
Lucie Cardiet at Vectra AI
ShinyHunters Breached the FBI by Bypassing the Fix -
Tomáš Foltýn at WeLiveSecurity
The devil is still in the email – but wearing a new mask -
Wiz
-
ZScaler
-
Блог Solar 4RAYS
Partisan Zmiy: снова на радаре
Upcoming events/webinars
-
ADF Solutions
-
Black Hills Information Security
BHIS – Talkin’ Bout [infosec] News 2026-10-07 -
CQURE Academy
HOT: Uncovering New Identity Theft Vectors and How to Mitigate Them -
Magnet Forensics
-
SANS
Stay Ahead of Ransomware: From Takedowns to Hacking Back -
Silent Push
Danglegeddon: Find your vulnerable subdomains before AI agents take them over
Presentations/podcasts
-
Alexis Brignoni
Digital Forensics Now Podcast S3 – 8 -
Ayush Anand
Catch the Network Scan 45+ Ransomware Gangs Run -
CQURE Academy
CQURE Hacks #84: Understanding Event ID 4624 in Action -
InfoSec_Bret
IR – SOC157 – Suspicious WAR File (2026) -
Microsoft Threat Intelligence Podcast
From Identity Compromise to AI Defense: Inside Modern Incident Response -
Monolith Forensics
-
MyDFIR
Certs vs Labs vs Projects: What SOC Analysts Actually Need -
NVISO Belgium
NVISO Podcast Episode #1 Attacker & Defender Strategies in a Shifting Threat Landscape -
Open Source Forensics Lab
How to Acquire Android data with Oxygen Forensic Detective (Archive) -
OpenSourceMalware
The OpenSourceMalware Show #23 -
Paraben Corporation
Micro Webinar Use AI to Fast Track USN Journal -
Parsing The Truth: One Byte at a Time Podcast
TN vs Ahmad Gatlin: Part 3 -
Proofpoint
FOMO as an Attack Vector: How Fake Party Invites Are Hijacking Inboxes -
Sandfly Security
Linux Forensics Tools | Intrusion Detection, Threat Hunting & Malware Detect Linux Commands Cheat Sheet -
SANS Cloud Security
Beyond MFA: A Defender’s Guide to Token Theft and AiTM -
SANS Cyber Defense
-
Security BSides Dublin
Security BSides Dublin -
The Cyber Mentors
DEF CON CTF Walkthrough: Packet Analysis -
The Weekly Purple Team
Raising the Dead! Bringing Tombstoned Accounts Back to Life -
Three Buddy Problem
Why is Anthropic Afraid of GLM 5.3?
Malware analysis
-
Dr. Web
-
Thijs Xhaflaire at Jamf
CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode -
Harihara Sudhan at K7 Labs
From KMS Auto to Scareware: Tracking a Multi-Stage Intrusion Linked to APT36? -
Lab52
Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce -
Sophos
-
Zhassulan Zhussupov
Reversing embedded WebAssembly: part 1. Cracking the WAMR .aot container in pure C. -
Muhammed Irfan V A (Security Researcher II) at ZScaler
2CLoader: A New Malware Loader Delivering Vidar and Remus
Miscellaneous
-
Adam at Hexacorn
EtwCheckCoverage API -
Brett Shavers
-
Cellebrite
-
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 09/28/26 -
F-Response
F-Response and Windows 11 25H2+, Windows 2025 Server -
Forensic Focus
- ADF Solutions Named A Major Player In IDC MarketScape For Worldwide Digital Forensics Platforms 2026 Vendor Assessment
- Green Meets Blue: A Brief RCS Forensic Excursion
- Belkasoft Releases Belkasoft X v2.12, Adding Offline Translation And AI-Assisted Database Analysis
- Roadblocks Ahead! Navigating The Major Issues Of Mobile Forensics
- Berla Introduces iVe 5.0, Adding Support For More Than 38,500 Additional Vehicles
- Semantics 21’s CCTV Review Tool Is Built For Footage That Cannot Wait
- Trust Is Not A Feature. It Is The Foundation.
- Passware Kit Mobile 2026 v5 Decrypts Samsung Galaxy Watch
- Forensic Focus Digest, October 02 2026
- Block Hash Scan: Illegal File Triage Completed On Site
-
Gaia Calamari at Strange Forensics
Cloud Forensics -
Matthew Green at InfoGuard Labs
AI Ate My Velociraptor -
Kevin Pagano at Stark 4N6
Forensics StartMe Updates (October 2026) -
Chad Gish at Magnet Forensics
The importance of digital forensics examiner training -
Matthew Plascencia
News Break: Oxygen Forensics -
Stanislaw Mrozowski at Nextron Systems
THOR at Locked Shields 2026: How Teams Used It and What They Told Us -
Amber Schroader at Paraben Corporation
How Government Buyers Can Verify Digital Forensics Vendor Provenance: A Practical Guide -
Seojun Kim and Kelly Jang at Plainbit
CrowdStrike Fal.Con 2026 in Las Vegas -
Salvation DATA
Movement Pattern Analysis in Digital Forensics: From Data Chaos to Case Timeline -
Emad Abedini at System Weakness
Dumplyzer | Memory Dump Analysis Platform
Software releases/updates
-
Arkime
v6.8.0 -
Crowdstrike
Falconpy Version 1.6.6 -
DFIR-IRIS
IRIS-Web v3.0.0-beta.4 -
Didier Stevens
Update: search-for-compression.py Version 0.0.8 -
Digital Sleuth
winfor-salt v2026.12.9 -
Doug Burks
-
Gaia Calamari at Strange Forensics
WEBCQUISITION -
Ghassan Elsman
Crow-Eye v0.14.0 — Visualizations & Browser Forensics -
LEAPPs
-
Marco Neumann
-
OpenCTI
7.261002.0 -
Passmark Software
OSForensics V11.1 build 1017 29th September 2026 -
PuffyCid
Artemis v0.20.0 – Released! -
radare2
2.5.6 -
Yaniv Radunsky
DFIR Companion v0.41.0
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.