MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · DFIR
Key takeaways : • Magnet Axiom and Magnet Griffeye Advanced create a complete end-to-end investigative workflow. Rather than choosing between comprehensive digital forensics and specialized media investigation, investigators can use both together. • The combined solution helps investigators find critical evidence faster while reducing manual review. • The combined Axiom + Griffeye Advanced workflow enables teams to review larger datasets, maintain operational efficiency, and better support specialized investigations. A major challenge in modern digital investigations isn’t collecting the evidence. It’s finding the evidence that matters. Today’s digital devices create enormous collections of images and videos that must be reviewed during an investigation. For examiners, this creates several challenges: • Large media datasets can be time-consuming to review manually.
Authored by Karl Stonebarger Originally published in the September 2026 issue of Magnet Unlocked. Want to be the first to see new content? Sign up for our monthly newsletter, Magnet Unlocked. When hearing discussion around speed, it’s easy to assume it’s about efficiency: shorter processing times, faster software, smaller backlogs . Those things matter, but they’re not what I think about. What I think about is a specific window that exists in nearly every active investigation. It’s the time between when investigators gain access to digital evidence and when a suspect has had enough time to build a story around it. Over more than a decade working in digital forensics and ICAC investigations , I came to see that window as one of the most important, least-discussed realities of the job. Evidence doesn’t lose value because it takes longer to process.
By Chad Gish In digital forensics, the difference between a missed lead and a breakthrough can come down to a single artifact, a single decision, or one detail hidden in a sea of data. The goal is not to simply to collect more evidence, but to collect more of the evidence that matters. Effective investigations depend on identifying the right sources, preserving the most relevant data, understanding what the evidence means, and avoiding the missteps that can leave critical information undiscovered. Evidence that once existed only in notebooks, photographs, and witness statements now lives across smartphones, computers, cloud platforms, vehicles, applications, and countless connected devices. This evolution has created incredible opportunities for investigators, but has also introduced significant challenges: • The volume of digital evidence continues to grow.
Investigative capability shouldn’t be split across licences, modules and bolt-ons – S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach The ShinyHunters extortion gang says it broke into FBI systems through a new, unpatched Oracle PeopleSoft zero-day. It claims it then moved into FBI-managed AWS GovCloud infrastructure and took 2 to 3TB of data on current and former employees and job applicants. The group defaced the FBI Jobs site with its logo, and the FBI has confirmed it is investigating “claims regarding unauthorized activity affecting FBIjobs. gov.” It has not confirmed a breach. ShinyHunters calls the attack retaliation for a May 2026 FBI FLASH report about the group and has given the bureau a week to correct or remove it. It also says it is now using the same PeopleSoft flaw against Fortune 500 companies. None of these claims has been independently verified, so organizations running PeopleSoft should watch closely for an Oracle advisory.
Your iPhone quietly builds a knowledge graph about you: who you know, where you go, what you run. iLEAPP now reads it, and the inferred locations line up with a documented activity log on Josh Hickman's public iOS 17 image.
Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification.
Why screenshots alone may not be enough: ProofSnap founder Radim Motycka explains how hashes, timestamps, WARC, network artefacts and independent verification can strengthen the preservation of web evidence.
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal. It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown.. A malware detection signature was developed and released after undergoing our Q&A process on June 23rd 2026. All Wordfence Premium , Wordfence Care , and Wordfence Response customers received this signature immediately. Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026. 2. 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
A Claude Code user has reported a severe data-loss incident in which an autonomous coding agent allegedly deleted 48,218 live files from a Windows project tree and destroyed the repository’s Git object store. The deletion reportedly occurred in just 103 seconds, between 10:10:31 p. m. and 10:12:14 p. m. ET, after the agent was authorized to rebuild a mirror for a task identified as “#873.” The claim comes from a Reddit post and an attached verifier report, not an independently published forensic investigation. According to the report shared on Reddit , the agent discovered that build_mirror.py could not refresh the mirror in place and therefore created a Python-based remover for an older copy stored in a temporary location.
Cellebrite’s Matt Goeckel demos Genesis on a real enterprise case – UFDRs, CDRs, documents, audio and video – showing how agentic AI surfaces leads and timelines while linking every finding back to its source.
Gyazo server flaw exploited to steal 23.6 million user records The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23. 6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords. Critical Orkes Conductor Vulnerability Exploited in Attacks A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.
Identifying malware families is hard. Malware samples are often packed, strings encrypted and configurations may only appear after several stages of execution. Even experienced reverse engineers can get the malware family wrong and commercial sandboxes do not always produce correct classifications. Malware C2 network traffic can provide another way to approach the problem. C2 traffic often contains enough information to identify the application-layer protocol and the malware family using it. FlowCarp FlowCarp identifies application-layer protocols in network traffic by analyzing observable characteristics of the traffic. It computes statistical measurements from a capture and compares them with models for known protocols. Unlike traditional IDS signatures, FlowCarp protocol models do not describe protocols using specific strings or byte sequences.
CrowdSec has disclosed that a May 2026 compromise tied to the TanStack npm supply-chain incident enabled attackers to clone roughly 170 private GitHub repositories, exposing internal source code and limited sensitive contact data. The company said the intrusion was traced to a former employee’s GitHub OAuth token, which attackers allegedly obtained through the broader TanStack compromise attributed to TeamPCP, also tracked as UNC6780. CrowdSec emphasized that its production infrastructure, databases, CI/CD pipelines , and open-source code were not altered or directly compromised. TanStack NPM Supply Chain Attack TeamPCP compromised the TanStack npm ecosystem on May 11, backdooring 42 packages with the credential-harvesting malware known as Shai Hulud. The malicious campaign targeted developer environments for GitHub tokens, cloud credentials, SSH keys, and other secrets.
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an insufficiently protected API endpoint, potentially handing attackers root-level command execution. Cisco has released patched versions across the 3. 1 through 3. 5 branches and warns there are no workarounds, only mitigations like restricting management traffic with access control lists, while CISA has ordered federal agencies to patch by September 19.
Discover what’s new on Forensic Focus – explore why forensic imaging is about workflow as much as speed, examine what institutional silence says about DFI well-being, see how semantic search can uncover what keyword searches miss with BelkaGPT, and more.
We would never tell a police officer to face a blade with “resilience” instead of body armour, so why do we expect digital forensic investigators to face repeated trauma with little more than resilience to protect them?
Spain Gets Its First Taste of AI-Aided Cyber Attack Spain’s data protection agency, the AEPD, has logged the country’s first personal data breach attributed to an autonomous AI agent, with the agency’s president confirming an individual deployed an agent built on a known large language model to carry out a multi-stage attack against an organization. The agent scanned generic files, logged into the target’s systems, ran vulnerability scans to find flaws granting read/write access to files containing personal data, then modified records and accessed invoices — chaining together multiple attack phases with minimal human steering at each step.
There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disrupt shipping and energy markets via actions in the Strait of Hormuz. So what does a prolonged conflict mean for cybersecurity here at home? U. S. agencies need to prepare for sustained Iranian cyber operations and conduct defensive wargames now. I spent part of my career in Navy intelligence supporting expeditionary and special warfare operations. This experience taught me to look beyond individual attacks to the larger objectives they serve. Iran’s likely objectives are relatively straightforward: impose enough pain on critical infrastructure , businesses, and public services to increase pressure on Washington, while disrupting the industrial and civilian systems that allow the U. S.
International Cyber Expo has revealed the ten finalists shortlisted for its 2026 Innovation Awards & Trail, with cybersecurity technologies featuring prominently among the products selected by the independent judging panel. Making its debut at International Cyber Expo following its success at International Security Expo , the Innovation Awards & Trail will showcase technologies addressing some of today’s most pressing cyber and security challenges. The winner will be announced on Tuesday 29 September during the Networking Drinks Reception at approximately 5.15pm. Cybersecurity products lead the shortlist Among the finalists is Reliance Cyber with RADAR, an agentic security operations platform designed to combine Detection-as-Code, AI agents and human security analysts within a managed service. Also representing the cybersecurity sector is Cairnlytics with Cairn Index.
Passware Kit now supports password recovery and decryption for Steganos Data Safe v. 15 and later, including newer . SHEADER vaults and additional protection options such as 2FA, Emergency Passwords, and USB-stored keys.
Iranian Cyber Spies Used Fake MRI Scan Results to Hack ‘Enemy of Regime’ The UK’s National Cyber Security Centre, the FBI, and the Netherlands’ AIVD issued a joint advisory naming CHOSEN BRICK, a Windows spyware family Iranian state actors have used since at least 2025 to target dissidents, activists, and journalists in the UK, US, and Netherlands. Operators build rapport with targets over WhatsApp or Telegram for days while posing as someone the victim already knows, then deliver the malware disguised as legitimate files — including a fake MRI scan of a disk herniation — that display a convincing decoy while quietly installing a persistent implant capable of harvesting contacts, emails, and social media messages, capturing the screen, and activating the microphone.
Keyword search misses what semantic search catches – see how BelkaGPT uses AI to uncover misspellings, crypto abbreviations, and hidden context that traditional keyword lists can overlook.
What’s new: • Examine what’s inside a PDF — objects, layers, and embedded elements, not just the metadata on the surface • Surface provenance and authenticity signals in the File Examination Dashboard, so you can explain your findings, not just report them • Analyze images, video, audio, and now PDF formats in one Magnet Verify workflow Many digital investigators and forensic examiners are facing this situation: a PDF comes in as evidence. A bank statement, invoice, contract, or maybe a screenshot someone exported, and it looks fine. Clean layout, sensible dates, nothing visibly off. But “looks fine” isn’t a finding you can put in a report, and if that document ends up in a legal proceeding, there’s a good chance that opposing counsel is going to ask how you know it wasn’t altered. Right now, answering that question is harder than it should be.
Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday. The vulnerability — CVE-2026-76461 — was exploited before Cisco disclosed and patched the defect Monday and allows unauthenticated, remote attackers to execute commands with root privileges on vulnerable systems. “In practical terms, that gives the attacker control of the gateway itself,” Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop. Cisco said its product security incident response team became aware of active exploitation of the defect affecting Cisco AsyncOS Software for Cisco Secure Email Gateway in September. When asked for further details, a company spokesperson pointed to the advisory and reiterated that the company is aware of active exploitation of the vulnerability.
A completed import does not guarantee complete visibility. Semantics 21 explains why investigators need to test for hidden blind spots and keep every file visible, accountable and available for review.
Revolut Confirms Customer Data Breach Through Fake Government Requests British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency’s email domain, in what the company describes as a sophisticated impersonation scam rather than a system intrusion. The exposed data included identity and contact details, dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories — though Revolut says a “limited number” of customers were affected and that funds and core systems were unaffected.
Atola TaskForce 2 helps forensic labs reduce imaging backlogs by combining fast parallel acquisition, automation, smarter workflows, and high-speed connectivity to keep evidence moving.
I didn't start out in threat intel. I didn't start my career in cybersecurity in DF/IR work. I started doing vulnerability assessments using commercial tools (ISS's Internet Scanner) and well as freely-available tools (i. e. , ToneLoc and THCScan, for war dialing). Around 2000, I transitioned to DF/IR work, largely as part of an internal, FTE role. We really didn't have "threat intelligence" at the time; in fact, while I heard the term and saw folks pointing at things they called "threat intel" or "CTI", I didn't really start engaging more directly with "threat intelligence" until about 2013 or so. I don't have an intel background from the military, nor from LE, but I've been ancillary to and a consumer of "cyber threat intel" long enough to know what I find to be "of value", and truly actionable.
I ran across this Ctrl-Alt-Intel blog post today, which discusses RustGate v2, and noticed that for all of what was addressed in the blog, there wasn't a great deal of content regarding the delivery method, the LNK file itself. Figure 1 illustrates what the blog states regarding LNK file metadata, beyond the embedded command line. Figure 1: Blog excerpt Okay, but what else can we see from the LNK structure itself? What other IOCs or intelligence can we derive from the file?
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign KnowBe4 Threat Lab observed a phishing campaign abusing Microsoft 365’s Direct Send feature — a legitimate mechanism meant for printers and legacy devices to send mail without a dedicated account — identifying nearly 29,800 confirmed phishing emails across July and August that followed a distinctly human, business-hours delivery pattern peaking around 2pm US Eastern time on Mondays and Tuesdays. Because Direct Send lets a message appear to originate from an organization’s own domain without ever compromising an employee account, the campaign can bypass the usual assumption that internal-looking mail is safe, with roughly 35% of observed messages carrying malicious attachments and thousands using mismatched reply-to addresses to redirect victim responses.
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Audio
Quality & Standards
Magnet Forensics spoke with Miguel Clarke, a former FBI Supervisory Special Agent turned cybersecurity director, about the widening gap between the cybercrime economy and the industry built to fight it. Watch the full conversation below. Key Takeaways • The cybercrime economy is estimated at more than $10 trillion, against a cybersecurity industry of roughly $300 billion. Miguel Clarke argues that gap means investment needs to rebalance toward recovery, not just detection. • Most incident response programs stop at containment. The handoff between the SOC and the digital forensics team is rarely planned out, and that’s where the investigative gap opens up. • Unifying evidence across endpoint, cloud, mobile, and memory, and using AI to clear repetitive work, can help cybersecurity teams move from raw data to a decision they can stand behind.
FOOTER
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8. One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint.