
DFIR Weekly Recap | This week brought zero-days, supply chain hits, and persistent access campaigns across nearly every layer of the enterprise stack. - CVE-2024-40766: SonicWall patch closed the bug but misconfigured devices stayed exposed. - Turla's STOCKSTAY expands the Russian 🇷🇺 group's intelligence-gathering toolset. - CVE-2026-33017 Langflow flaw weaponized to drop a Monero cryptominer. - VBScript campaign uses WhatsApp to distribute RMM software for stealthy access. - CVE-2026-20245 zero-day actively exploited in Cisco Catalyst SD-WAN Manager. - Klue supply chain attackdetectable through artifacts left in Salesforce instances. - Photo ZIP phishing hits hospitality sector, delivering a Node.js implant for persistence. - netlogon.log captures Kerberos authentication detail that Event 1644 simply misses. - StealC and Amadey expose the layered cybercrime-as-a-service economy behind infostealer delivery. - Payouts King ransomware broker deploys new Edgecution malware as an initial access tool. Top stories in the thread below. #DFIR_Radar
Post summary
A weekly summary covering multiple CVEs, noting patch availability for one, active exploitation of another, and various other emerging threats with limited technical detail.















