Zeek: Introducing Zeek 8.2
https://zeek.org/2026/05/introducing-zeek-8-2/
Read on HackerWorkspace: https://hackerworkspace.com/article/zeek-introducing-zeek-8-2
Zeek: Introducing Zeek 8.2
https://zeek.org/2026/05/introducing-zeek-8-2/
Read on HackerWorkspace: https://hackerworkspace.com/article/zeek-introducing-zeek-8-2
NEW by me:
Many immigrants have enough anxiety these days without their lawyer leaking their files and having the files all wind up in the hands of criminals. Read about what happened with a NYC law firm in my new post.
No need to hack when it’s leaking: Dalbir Singh & Associates law firm edition:
#dataleak #immigration #incidentresponse #misconfiguration #KillSec #DSDLaw
How to Investigate with Windows Prefetch Files

Kazuar: Anatomy of a nation-state botnet | Microsoft Security Blog
https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/
Read on HackerWorkspace: https://hackerworkspace.com/article/kazuar-anatomy-of-a-nation-state-botnet-microsoft-security-blog

Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments.
NATO Locked Shields 2026: RL Joins Live-Fire Cyber Event | RL Blog
https://www.reversinglabs.com/blog/locked-shields-2026
Read on HackerWorkspace: https://hackerworkspace.com/article/nato-locked-shields-2026-rl-joins-live-fire-cyber-event-rl-blog
Mustang Panda Linked to FDMTP Backdoor in Asia-Pacific Espionage
https://www.infosecurity-magazine.com/news/mustang-panda-fdmtp-backdoor-apj/
Read on HackerWorkspace: https://hackerworkspace.com/article/mustang-panda-linked-to-fdmtp-backdoor-in-asia-pacific-espionage
Say what you want about internal corporate Copilot. Having to write several incident reports in one day, Copilot is doing the heavy lifting of editing the mess of text I am dumping into the report template.
Do I like what it has produced? No, it is not in my style of writing.
Will I make my deadlines? Yep

RE: https://infosec.exchange/@amvinfe/116567370386921171
I realize my view on whether it is ever okay to pay #ransom in a #hackandleak situation is contentious. Great thanks to @amvinfe for asking me to articulate my views. #incidentresponse #mitigation #responsibility #ethics
A Guide to LNK File Forensics
