# Zeek Newsletter - Issue 64 - June 2026

**URL:** <https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006>\
**Category:** Announcements\
**Tags:** newsletter\
**Created:** [July 2, 2026, 7:53pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006 "2026-07-02T19:53:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelle](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/michelle/32/772_2.png) [@michelle](https://community.zeek.org/u/michelle)\
**Post date:** [July 2, 2026, 7:53pm UTC](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006/1 "2026-07-02T19:53:09Z")

</div>

![image](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/7573e82c2c2e66f64ceac539529b2954adb7e2c3.jpeg)

# Welcome to the Zeek Newsletter

## In this Issue:

- [Community News](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006#p-29791-community-news-reminders-3)
- [Development Updates](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006#p-29791-development-updates-4)
- [Zeek Techniques](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006#p-29791-zeek-techniques-5)
- [Packages](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006#p-29791-packages-6)
- [Get Involved](https://community.zeek.org/t/zeek-newsletter-issue-64-june-2026/8006#p-29791-get-involved-7)

**TL;DR:** Zeek 8.0.9 and 8.2.1 are releasing next week with Zeek 9 on track for the end of August. Lots of community happenings, including the 2026 Zeek Project Survey and an extended CFP deadline for the upcoming Berkeley workshop.

* * *

## Community News & Reminders

- **Community Call Recap:** This month we covered the 8.0.9 and 8.2.1 patch releases, the Berkeley Workshop CFP, our new Contributor Guide, and the 2026 Community Survey. [Watch the recording here](https://youtu.be/9vMEeksxxl8). The next call is August 5 at 10am PT – [use this Zoom link](https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09) to join.

- **Berkeley Workshop CFP extended:** We’ve extended the call for presentations deadline to July 8. If you’ve been meaning to submit a talk and haven’t gotten to it yet, now’s your chance. [Learn more and submit your talk here.](https://zeek.org/zeek-workshop-berkeley-2026/call-for-presentations-berkeley/)

- **The 2026 Project Survey is live:** The annual community survey launched and runs through August 14. This year includes an optional focus group sign-up if you’re interested in providing feedback on future releases. [Take the survey here.](https://docs.google.com/forms/d/e/1FAIpQLScjP10NYCE0Wa4XPnVb4tgnVJgCsFacJbUByOcuoV-ZR58XHg/viewform)

- **Topic of the Month:** Last week we wrapped up “Detection Techniques”, you can find the [recap from the conversation here](https://zeek.org/2026/07/what-actually-ca%E2%80%A6-zeek-deployment/). This month’s topic will be announced on Monday – [join us on Slack](http://zeek.org/slack) to find out what it is!

* * *

## Development Updates

Zeek 8.0.9 and 8.2.1 are releasing next week. These are larger than usual patch releases (roughly four times the normal issue count), for a few reasons: an increase in community-submitted bug reports, expanded fuzzing coverage with UBSan now part of the OSS-Fuzz setup, and relatively long wait since the last patch releases in mid-May. As always, you should go ahead and update, but the release notes are worth reading carefully given the volume of changes. A PDG security notification will go out before the end of the week.

Zeek 9 remains on track for the end of August. Feature work slowed slightly to accommodate the patch cycle but nothing material has shifted.

The [LDAP analyzer has been extended](https://github.com/zeek/zeek/pull/5601) to forward NTLM and Kerberos authentication data to the respective analyzers by first time contributor Swastik Bose. If you see a lot of LDAP traffic in your environment, this should provide more visibility via the ntlm.log and kerberos.log logs. Feedback on the new behavior is welcome!

Shubham Kumar [added DPD signatures for QUIC v1 and v2](https://github.com/zeek/zeek/pull/5602). Zeek will now attempt to decrypt QUIC INITIAL packets when not using port 443.

As always, follow development progress on [GitHub](https://github.com/zeek) to stay current with the latest changes.

* * *

## 💡 Zeek Techniques

Analyzing email traffic and tired of manually stitching together separate body segments or multiple MIME attachments? Zeek has a built-in event that does the heavy lifting for you!

Instead of tracking individual entities, you can hook into the mime\_all\_data event. It automatically combines all decoded MIME data from a single email message (SMTP or POP3) into a single, cohesive string for seamless analysis.

[Documentation here](https://docs.zeek.org/en/current/scripts/base/bif/plugins/Zeek_MIME.events.bif.zeek.html#id-mime_all_data)

⚠ **Keep in Mind:** Because Zeek has to buffer the data to glue everything together, using this event can be resource-heavy on high-volume networks. Additionally, this feature currently supports SMTP and POP3 traffic, so it won’t catch MIME entities extracted from HTTP sessions just yet.

Share your tricks, shortcuts, or techniques with us [using this form](https://forms.gle/1DR2ei98E1n54dg39).

* * *

## Packages

Anyone in the community can write add-on functionality for Zeek via packages.

- Browse Zeek packages: [https://packages.zeek.org](https://packages.zeek.org)
- Head to our [zkg package manager documentation](https://docs.zeek.org/projects/package-manager/en/stable/index.html) to get started on your own
- Questions? Check out [#package-sharing](https://zeekorg.slack.com/archives/CTGDGK6EA) to get help

Recently added or updated packages are always visible on GitHub directly, via the following search of pull requests to our package repository:

[https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed](https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed)

Recent Updates:

> **[GitHub - detection-labs/spicy-whois: Spicy-based WHOIS (RFC 3912) protocol analyzer for...](https://github.com/detection-labs/spicy-whois)**
>
> Spicy-based WHOIS (RFC 3912) protocol analyzer for Zeek.

> **[GitHub - Flowtriq/zeek-flowtriq: Zeek package for DDoS detection with Flowtriq...](https://github.com/Flowtriq/zeek-flowtriq)**
>
> Zeek package for DDoS detection with Flowtriq webhook alerting

* * *

## Get Involved

- Share ideas or content: [news@zeek.org](mailto:news@zeek.org) or [#security-news](https://zeekorg.slack.com/archives/CT0J1PSR2) on Slack.
- Stay connected: [Discourse](https://community.zeek.org) • [YouTube](https://youtube.com/c/Zeekurity) • [Mastodon](https://infosec.exchange/@zeek) • [Bluesky](https://bsky.app/profile/zeek.org) • [LinkedIn](https://www.linkedin.com/company/zeekurity)
- Check out [Leadership Team meeting notes](https://community.zeek.org/c/lt-meeting-notes/13) for insider updates.
- Looking for Zeek jobs? [See openings on LinkedIn](https://www.linkedin.com/jobs/search/?keywords=zeek).

**Thanks for being part of the community. We’ll see you next time!**
