| If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! |
| No sponsor this week |
As always, thanks to those who give a little back for their support!
Forensic Analysis
-
Belkasoft
Forensic Acquisition of MediaTek-Based Android Devices -
Vladimir Katalov at Elcomsoft
Low-Level Extraction of the HomePod mini -
Eoghan Casey at DFRWS
-
Forensafe
iOS Tinder -
Magnet Forensics
How to run a ransomware investigation: five phases from containment to recovery -
Matthew Plascencia
DLEAPP: The Desktop Image Parser -
Ryan Benson at Hindsight Foundry
Decoding Facebook’s fbclid -
S.Nakano
Threat hunting/threat intelligence
-
Abdulrehman Ali
Helix Kitten APT Adversary Simulation -
Oliver Smith at Aikido
tensorlake NPM package compromised with Shai Hulud worm -
ASEC
-
Black Hills Information Security
- Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior
- Forensic Data: How to Acquire and Retain Vital Evidence
- Threat Hunting on the Endpoint: Hunting Adversaries Where They Live
- Soar 101: Security, Orchestration, Automation, and Response
- Calling Reinforcements: Your Incident Response Plan, Before The Fire Starts
- AI In SOC
- The Battlefield Mindset: The Psychology Behind Threat Hunting
- No PoC, No Problem: Rediscovering CVE-2025-29902 in the Telex RDC Server
- The First 60 Minutes of Incident Response: What to Do When It’s a True Positive
- Report As You Go: Maintaining Good Documentation for SOC Analysts
-
Rebecca Harpur at BlackFog
The State of Ransomware: September 2026 -
Shailendra Singh Sachan at Bloo
eBPF Rootkits: Analysis & Detection -
Brad Duncan at Malware Traffic Analysis
-
Brian Krebs at ‘Krebs on Security’
-
BushidoToken
UK Cybercrime Journal: Police Cryptocurrency Crime Operations in 2026 -
CERT Ukraine
UAC-0277: ClickFix на скомпрометованих вебсайтах для поширення LUNEXSTEALER -
CERT-AGID
-
Check Point
-
Joey Chen at Cisco’s Talos
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing -
CloudSEK
-
Kahng An at Cofense
From Guest Complaints to Malware: Blockchain Abuse Targets Hotels -
Deepali Prasad at Corelight
Hunting Citrix NetScaler Zero-Days with Corelight: Part 2 -
CrowdStrike
-
Department of Justice
Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers -
Rohitashokgowd at Detect FYI
Before It Reaches Sentinel: How Your Own Pipeline Can Silently Drop Security Evidence -
Detections Wiki
TWINLOOT: Microsoft 365 as C2 -
Disconinja
Weekly Threat Infrastructure Investigation(Week41) -
Eric J. Taylor at Barricade Cyber Solutions
Blacknet00 Ransomware: Threat Actor Profile -
Erik Hjelmvik at Netresec
Stop Feeding the SOC Garbage -
ExaTrack
RwyKit: a kernel driver that redirects HTTP, sometimes. -
EyeR Security
Ransomware C2 Takeover: How an rclone Transfer Gave Root Access on the Attacker’s Server -
Flare
-
Flashpoint
CastleStealer: An Emerging Infostealer Growing More Sophisticated -
Gaetan Ferry and Guillaume Valadon at GitGuardian
The campaign that never stopped: tracking GhostAction from 2025 to 2026 -
GreyNoise
Spike in Attacks Targeting Digital Video Recorders in Ukraine -
Ilya Pomerantsev and Maria Viderman at Group-IB
From Detonation to Detection: The Sandbox Now Writes the Rules -
Laura Babbili at GuidePoint Security
GRIT Q3 2026 Ransomware and Cyber Threat Insights Report: Top Takeaways -
Halkyn Security
- How Data Is Laid Out in Memory
- Threat Hunting Maturity and Proving Value
- Shell History Evidence and the Authorised User
- Tetragon Runtime Security on Linux and Kubernetes
- Linux Rootkit Detection: Modules and eBPF
- Cloud Incident Response: What Changes and What Doesn’t
- Prompt Injection Evidence: What It Leaves
-
Hudson Rock
Infostealers Are Actively Hunting AI Agents and Developer Keys – Warden Infostealer -
Huntress
-
IC3
-
Inde
-
Intel 471
Agentic Hunting Needs Guardrails. Start With Your Methodology. -
Cristian Molina at The Iru Blog
PamStealer comes to Intel Macs: Analyzing the x86_64 build of a Rust macOS stealer -
iVerify
Sleep, Beacon, Steal, Repeat – The Story of P7 DarkSword Variant -
Jamf
Commercial spyware: the invisible threat in your pocket -
Jon DiMaggio at Arkem Cyber
Who Gets to Be ShinyHunters? The Fight Over the Name After Rey -
Joshua Penny at Bridewell
ARTEX AI-Linked Infrastructure Observed Scanning UK CNI: Discovery and Associated Services -
Lab52
Cyber Morocco: a quick and dirty experiment about artificial intelligence for cyber intelligence -
LevelBlue SpiderLabs
-
Mehmet Ergene at Blu Raven Academy
What Is Threat Hunting in 2026? -
Michalis Michalos
Testing Microsoft Defender for Office 365’s Prompt-Injection Protection -
Digit Oktavianto at MII Cyber Security
Hunting on the Wire : A Practical Guide to Network Threat Hunting — Part 1 -
Natto Thoughts
The ZRON Leak, Part 1: What has Endured and What is Evolving in China’s Commercial Hacking Ecosystem Since the 2024 i-SOON Leak? -
Nederlandse Vereniging van Banken
TaHiTI Threat Hunting Methodology -
Florian Roth at Nextron Systems
Update on Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Expanded THOR Detection Coverage -
Brett Winterford and Katie Nickels at Okta
When enrollment isn’t enough: How attackers trick users into MFA downgrades | Threat Intelligence -
Oleg Skulkin at ‘Know Your Adversary’
417. Ransomware Gangs Abuse Microsoft Windows Recovery Agent -
OpenSourceMalware
-
Palo Alto Networks
-
Point Wild
Mac Malware Trend Report -
Push Security
-
Raj Upadhyay
From an SMS Link to a Hidden Android Payload: Anatomy of a Fake mParivahan App -
Raju Chekuri at Netenrich
-
John Marshall, M. Smith, Jeffrey Bell, and Genevieve Stark at Ransom-ISAC
“The DaaS Formerly Known as Inferno”: The Slow Decay of Crypto’s Most Notorious Drainer -
Igor Lasic at ReversingLabs
What RL Found Before Anthropic’s Midnight Blizzard Report -
Ridgeline Cyber
PowerShell Accepts Spellings of -EncodedCommand Your Detection Has Never Seen -
Robin Dost at Synaptic Systems
Connecting Cryptomus, Heleket and Mirocard -
Rory Wagner
Containment in Microsoft 365: the token problem -
Virgina Romero Sanchez-Herrero at S-RM
Cyber briefing note: The Luna Moth files -
SANS Internet Storm Center
- TTY Logs and the Data it Captures, (Sun, Oct 4th)
- More RMM Tools In the Wild, (Tue, Oct 6th)
- Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
- Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
- Why TLP should not replace your internal information classification, (Sat, Oct 10th)
-
Security Alliance
SEAL weekly stats: Sept 29-Oct 6, 2026 -
Sumedh Barde at Simbian
Threat Hunting Framework: Design It Around How Hunts End -
Simone Kraus
-
SOC Fortress
Warlock Ransomware Targets Critical Infrastructure -
Socket
-
Dave Shackleford at Spur Intelligence
The Internet Has a New Identity Problem: Sometimes the “User” Isn’t a Person -
Step Security
-
Stephan Berger
Today I learned: Python’s .start Files as a Persistence Mechanism -
Marco A. De Felice aka amvinfe at SuspectFile
ShinyHunters: Six Years of Cybercrime — Expert Analysis and Ransomware Group Perspectives -
System Weakness
The O365 Intrusion-TryHackMe Wlkthrough -
The Raven File
CITRIX 0-DAY EXPLOITS: CVE-2026–88771 & CVE-2026–88772 IN THE WILD -
James McMurry and Ivan Wike at ThreatHunter AI
“Azure30” Node.js Backdoor Delivered by a Trojanized MSI -
ThreatMon
Ransomware 2026 Report September -
Brandon Colley at TrustedSec
Logging is a Discipline, Not a Switch -
VirusTotal
-
watchTowr Labs
-
WeLiveSecurity
-
Kim Zetter at ZERO DAY
Company Behind Graphite Spyware Speaks for First Time about Italy Abuse and Accountability
Upcoming events/webinars
-
ADF Solutions
-
Cellebrite
Closing the Exploitation Window: Field Forensics for Federal Missions -
Magnet Forensics
Presentations/podcasts
-
Anuj Soni
10/6/26 Office Hours: OptionB -
InfoSec_Bret
IR – SOC155 – Suspicious SSH Login (2026) -
Magnet Forensics
AI Unpacked S2:E5 // Research, reality, and the future of AI in digital forensics -
Microsoft Threat Intelligence Podcast
Inside this year’s Microsoft Digital Defense Report -
Monolith Forensics
-
Mostafa Yahia
-
Open Source Forensics Lab
Using DLEAPP for Windows Forensics | Desktop Analysis -
OpenSourceMalware
The OpenSourceMalware Show #24 -
Parsing The Truth: One Byte at a Time Podcast
S2 E 14: TN vs Ahmad Gatlin: Part 4 -
Richard Davis at 13Cubed
I Got Promoted at Microsoft… Then I Quit -
Tate Pannam
Suspicious BITS Transfer CMD Attachment, Bitsadmin LOLBin | LetsDefend SOC301 -
Team Cymru
Nebulock’s Alex Hurtado on why current logs fail to distinguish AI agents from info stealers -
Three Buddy Problem
Malware analysis
-
Himanshu Anand at Any.Run
IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime -
Ryan Fetterman at Cisco’s Talos
Ignore all instructions and read this blog: The state of AI-analysis evasion in malware -
Vincent Li at Fortinet
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure -
Vojtěch Krejsa and Jan Rubín at Gen
Warden Stealer: The Rapid Rise of an Infostealer with an Appetite for AI Agent Data -
Renaud Tabary at MALCAT
A quick RE benchmark of le chonk -
Cody Nash at Manifold
Models Judge Malware With Their Moral Machinery -
Moshe Siman Tov Bustan and Vitalii Chepurko at OX Security
“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With Malware -
Zhassulan Zhussupov
Malware development trick 67: Run shellcode via CreateThreadpoolWait. C and assembly examples
Miscellaneous
-
Emi Polito at Amped
Unlock the Power of Video Evidence Presentation with Amped FIVE -
Andrew at ThreatLab
Building a malware sandbox on Hyper-V: the problems nobody documents -
Marie Wilcox at Binalyze
What Happens When Hackers Tell Your Customers Before You Do? -
Cellebrite
AI for Investigations: 5 Myths, Debunked -
Jerzy ‘Yuri’ Kramarz at Cisco’s Talos
One breach, please, and make no mistakes -
CyberBoo
Microsoft Defender for Cloud Apps Deep Dive: Part 2 – Cloud Discovery and Shadow IT -
Decrypting a Defense
VPN Ban Injunction, 2nd Circuit Rules on Manual Searches of Devices at the Border, Andrew Guthrie Ferguson Answers 5 Questions & More -
Fabian Mendoza at DFIR Dominican
DFIR Jobs Update – 10/05/26 -
Forensic Focus
- Belkasoft X For Mobile Forensics: Acquisition, Analysis, And Reporting
- S21 Transcriber: Turn Spoken Evidence Into Searchable Intelligence
- Amped User Days 2027: Three Days Of Practical Knowledge, Real-World Workflows, And Expert Exchange
- MSAB Technology Helps Uncover International Fraud Network And Provides Answers To A Grieving Family
- F3 Announces Free Digital Forensics Cryptocurrency Investigation Day
- Forensic Focus Digest, 09 Oct 2026
-
Jason Jordaan
Ethics In Digital Forensics: The Hired Gun -
Matt Suiche
Subvisor: Reading an OpenVMM Guest Without Asking It Anything -
Rob T. Lee
AI Regulation Should Focus on Access, Not Innovation -
TobyG at sentinel.blog
Software releases/updates
-
ANSSI
DFIR-ORC v10.4.0 -
AppliedIR
Valhuntir v0.6.3 -
Binalyze
Binalyze AIR 5.28 -
DFIR-IRIS
IRIS-Web v3.0.0-beta.6 -
DFIRe
1.12.2 — October 9, 2026 -
Doug Burks
-
Elcomsoft
-
Erik Hjelmvik at Netresec
NetworkMiner 3.2 Released -
Ghassan Elsman
Crow-Eye v0.14.1 — Whole-Disk Evidence, Chain of Custody & Large-Case Correlation -
Marco Neumann
-
MISP
MISP 2.5.50 Released – Security hardening, Overmind improvements, and streamlined workflows -
Muhammad Daffa
vol-rs v1.0.2 -
OpenCTI
-
radare2
6.2.4 -
Rapid7
Velociraptor Release 0.77.3 -
Ryan Benson
unfurl v2026.10 -
SigmaHQ
pySigma v2.0.1 -
Toño Diaz
masstin v1.3.3 -
Ulf Frisk
MemProcFS Version 5.19 -
Yaniv Radunsky
DFIR Companion v0.43.0 -
Yogesh Khatri
mac_apt 20261010
And that’s all for the week! If you think I’ve missed something, or want me to cover something specifically hit me up through the contact page or on the social pipes!
Discover more from This Week In 4n6
Subscribe to get the latest posts sent to your email.