MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · DFIR
Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of activities at the Border Grill . This year, our focus is preemptive security: helping security teams anticipate credible risk, respond at machine speed, and maintain an accurate view of their security and compliance posture as their environment changes. Visit the Rapid7 booth at Black Hat USA You can find Rapid7 at booth #2445 in the Mandalay Bay Business Hall, open and running on the following days and times: • Tuesday, August 4: 4:00–7:00 p.m. • Wednesday, August 5: 9:00 a.m.–6:00 p.m. • Thursday, August 6: 9:00 a.m.–4:00 p.m.
Help shape the future of enterprise DFIR by sharing your insights in Magnet Forensics’ annual survey by August 31, 2026, and receive early access to the findings – plus a chance to win one of two $500 Amazon gift cards.
Understand how to identify, preserve, extract, analyze, and report digital evidence for modern vehicle forensic investigations. By Steve Gemperle Key takeaways • Vehicle data comes from two main lanes: EDR (crash) data, and infotainment and telematics data. They answer different questions and are strongest when used together. • Confirming legal authority and preserving volatile data before acquisition are the foundations of a defensible investigation. • The right acquisition method depends on the investigation type, not just the vehicle; consent searches call for less invasive access than a warrant might allow. • Cross-referencing timestamps across EDR, infotainment, telematics, and phone or cloud records is essential to building a timeline that holds up to scrutiny.
Read the latest DFIR news – Go malware memory forensics, new iOS notification and Biome artifacts, AI assistant forensic traces, ALEAPP browser updates, and more.
Key takeaways • Applications for the 2027 Magnet Forensics Scholarship Awards are now open worldwide through October 30, 2026. • Recipients can receive one year of unlimited digital forensics training, certification opportunities, and a one-year license of Magnet Axiom. • Awards are available for both officers new to digital forensics and experienced investigators looking to advance their skills, as well a special award for prosecutors. Are you an officer looking to enter — or advance your career in — the field of digital forensics? Magnet Forensics is looking to help agencies address a global talent shortage in digital forensics by offering the Magnet Forensics Scholarship Awards. These awards provide promising officers with unlimited access to training for one year, helping them build skills in a discipline that is becoming increasingly important to modern criminal investigations.
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?” Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The data is siloed, context is missing, and time rapidly slips away. Today, the window between a vulnerability’s disclosure and its active exploitation in the wild has essentially collapsed, making predictive lead time a thing of the past.
Key takeaways • Data exfiltration and IP theft and departing employee cases are common enterprise investigations, and mobile devices are increasingly central to how they get resolved. • Sixty-six percent of DFIR teams report growing mobile device volume, yet 53% can only extract limited data, the top mobile challenge for the third year in a row. • Consent-based, category-scoped extraction is how DFIR teams get defensible mobile evidence without over-collecting an employee’s personal data. When a company suspects an employee of taking a trade secret, client list, or product plans to a competitor, that’s an insider threat. These internal investigations often start with laptops and corporate email. Increasingly, the evidence that proves intent lives somewhere else: a bring your own device (BYOD) phone, in a messaging app the company has no visibility into.
Why wait months for digital evidence when answers could start at the point of contact? Discover how Cellebrite Kiosk helps teams move investigations forward faster.
Explore a selection of the latest DFIR employment opportunities in this week’s Forensic Focus jobs round-up.
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Key takeaways • You can only review what you collect. Review doesn’t create evidence; it reveals evidence that was collected. If critical data isn’t acquired during collection, it won’t exist for investigators or attorneys to find later. • The goal is the relevant data, not more data. Targeted collection and thoughtful culling help teams avoid over-collection while still capturing what matters, and effective discovery scoping balances date and time ranges, data types, and context. • The depth of your collection determines the depth of your evidence. A full file system extraction reaches the encrypted apps and system-level artifacts that prove who was behind a device, and mobile and cloud are increasingly where the evidence lives. • Engage digital forensics early.
Explore the impact of cumulative trauma on digital forensic investigators, faster triage with ADF Pro, feature-phone recovery using MSAB XRY Pro, and Katelyn Rogers’ Chip ID Framework and SpecTacular.
By Christopher Vance Originally published in the July 2026 issue of Magnet Unlocked. Want to be the first to see new content? Sign up for our monthly newsletter, Magnet Unlocked. The anchor I see most often in a digital forensics lab isn’t a person. It’s a workflow template. Something a predecessor built years ago, that we’ve been regenerating on every case since, that nobody on the receiving end has opened in a long time. We keep building it because the request keeps coming. The request keeps coming because we keep building it. That’s the loop, and it’s quietly the single biggest thing holding digital forensics back right now. Not the tooling. Not the backlog. Not the budget. The loop. My colleague, Brandon Epstein wrote recently about the courtroom cost of “ we’ve always done it this way ,” how it can get a method torn apart on the stand.
Key takeaways • Bates numbering gives every page in a document set a unique, sequential ID — creating a defensible, consistent way to track and cite evidence across investigations, regulatory requests, and litigation. • As document volumes grow, it keeps large-scale reviews organized and lets legal teams, investigators, and outside counsel all reference the exact same page without confusion. • Magnet Axiom Cyber builds Bates numbering directly into PDF export workflows, with customizable prefixes, formatting, and reusable templates that keep pace with modern eDiscovery requirements. When investigations or legal matters involve thousands of documents, finding a specific page quickly can become a challenge. That’s where Bates numbering comes in. Bates numbering is the process of assigning a unique, sequential identifier to every page in a document set.
Key takeaways • C2PA support is now built into Magnet Verify Desktop, letting you detect, extract, and validate embedded provenance data without external tools or manual workflows. Note: The Magnet Verify SaaS offering already supports C2PA. • When present in a file, think of C2PA as a “nutrition label for media,” recording a file’s origin, edit history, tools used, and whether AI was involved • C2PA is a signal, not a verdict. The presence of C2PA doesn’t guarantee whether the content is true, and its absence doesn’t imply that it was not AI-generated. • Adoption is still early, but with major tech companies, AI platforms, and device makers integrating the standard, provenance signals will play an increasing role in forensic analysis.
I recently ran across a comment from a SOC manager on social media that said, "Finding initial access is difficult." I thought about it for a moment, and had to ask, "why is that?" For context, I transitioned from military service in 1997, and shortly thereafter, was running vulnerability assessment engagements, leading teams on-site to do the work, and completing reporting to the customer. I did "war dialing" (which was a lot of fun), and full-on, enterprise-wide data collection as part of overall vulnerability assessments. I then transitioned into DF/IR work, doing both consulting and FTE work, and I've also worked as a SOC analyst, and even run an internal, global SOC for a while.
There's a good bit of file analysis that goes into CTI reports, including (but not limited to) malware analysis. But for some reason, not all files appear to be worthy of parsing and analysis. We also tend to see in-depth descriptions of the value of LNK files to forensic analysis, particularly when looking at user activity on an endpoint. However, while LNK files still tend to be a popular delivery mechanism for kicking off attacks, not a great deal of effort goes into analysis if these files, nor does effort go into recording metadata for use in detections or threat intel. Sure, we see reports that include screen capture of command lines embedded in LNK files but what we don't see is LNK file metadata truly, fully exploited.
Key takeaways • Executive Order 14390 directs federal agencies to dismantle the transnational criminal organizations (TCOs) behind cybercrime, fraud, and predatory schemes targeting Americans. • Agencies must deliver a coordinated action plan responding to the EO within 120 days of it being signed, by July 4, 2026 • It targets a range of cyber-enabled crimes, from ransomware to sextortion. Responding to all of them takes more than a single tool. • The order explicitly calls for technical capabilities from commercial cybersecurity firms to help attribute, track, and disrupt these actors. On March 6, 2026, President Donald Trump signed Executive Order (EO) 14390, Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens .
I've worked a lot of places over the years, all for varying lengths of time. While this worked against me in the early days, with potential employers wondering why I didn't stay longer at my previous employer, and wondering how long I'd potentially stay with them, this became less of an issue later in my career. During my career in the private sector, I've run vulnerability assessments, and spent over 26 yrs in digital forensics and incident response, some in FTE roles, and much more in consultant roles. In 2006, I started in a DFIR consulting role at ISS, which evolved 6 months later when the company purchase by IBM was completed. I then became a "plank owner" of the IBM ISS X-Force ERS team, one of the original members of the team, even before we expanded.
I like timelines, particularly when it comes to forensic investigations. There I said it. The first step to addressing an issue is admitting that you have a problem. I've been creating timelines since about 2008-ish, or so. I have a series of blog posts specifically on the topic of timeline analysis starting in Feb 2009 , where I walk through some of the tools I used at the time to create timelines based on a 5-field "TLN" format that I developed... and still use to this day. For example, take a look at this recent Huntress blog post regarding activity attributed to the group "MuddyWater"; the time-based information in the blog post has the "Z" stripped from the time stamp, and spacing reduced, but when I drafted parts of this blog post, those sections included timeline info.
Our TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2. 0 release added musl/Alpine compatibility and support for unencrypted HTTP proxy requests. But there were a few small, yet very important, updates that unfortunately didn’t make it into that release. The new PolarProxy 2. 0. 1 release takes care of this. Bug Fixes The PolarProxy 2. 0. 1 release fixes three bugs affecting non-TLS traffic: two that could block non-TLS connections under certain conditions, and one that could corrupt packets in output PCAP data. Improved Performance Memory overhead has been reduced as part of a major overhaul of PolarProxy’s data-flow logic. PolarProxy now caches less data, reducing CPU and memory use while supporting more simultaneous sessions.
A new major release of PolarProxy is out with a self-contained single-file binary, expanded platform support (musl/ARM64), and improved container and service plumbing. PolarProxy is a transparent TLS/SSL inspection proxy built for incident responders, malware analysts and security researchers. It decrypts and re‑encrypts TLS traffic and writes decrypted sessions to PCAP for analysis in Wireshark or an IDS. What's new • Packaged as a self-contained, single-file binary for easier installation and management. • Improved HTTP proxy server: support for unencrypted HTTP traffic with --nontls allow • Upgraded runtime: migrated from .NET 8 to .NET 10. • More supported platforms: Linux musl (Alpine) builds for the ARM64 architecture added. • Simplified container deployment: Dockerfile and docker-compose.yml included with all musl/Alpine releases.
There's been a lot of chatter over the use of AI in various fields, and because it's my professional focus, I'm most interested in how it's used in cybersecurity. Now, that doesn't mean that I'm not aware of how it's used... or more appropriately, misused... in other fields, as well. For example, how it's been misused in the legal field has been around for more than 2 years now, and just last year, we saw the term "AI slop" be adopted in the software dev/cybersecurity field. Something we also saw in 2025 was the release of the Anthropic report regarding how AI was used by threat actors, in a cyber espionage campaign. The report is 14 pages long, with the title page, table of contents, and a 2-pg Executive Summary; the contents of the report itself starts on pg 6. The "TL;DR" of the report, if you need it, is that nation-state threat actors used Claude to target 30 organizations, and ".
One of the fascinating aspects of Windows systems, from a DF/IR perspective, for me has been the clipboard. Notice I said, "one of", rather than "the"... that's because there are a lot of fascinating aspects of Windows systems when it comes to DF/IR work. I include the clipboard in this mostly because there is various malware... infostealers, etc... that will dump the contents of the clipboard as part of their functionality. Also, there's malware that will place a malicious bitcoin wallet address on the clipboard, in hopes that the user simply pastes that address when they're enabling a transaction. I mention malware that modifies the clipboard in this 2008 blog post . I'll admit that early on in my DF/IR career, this isn't something that I thought about collecting as part of an IR engagement.
Sometimes I'll get questions via different routes... webinars or podcasts, via social media, DM, or even email. Getting questions is good, because it keeps me aware that I'm in somewhat of a bubble, given the work I do and the environment in which I do it. Given the nature of "social" media (hint: it's rarely "social"), it's tough to draw a bead on where you are at any given moment, so questions can be invaluable. Here's an interesting question I got from Brian Carrier during a webinar he invited me to... If you have the entire Registry and limited time, what do you do? The Cyber Triage LinkedIn post has 9 pages, and as you can see from the first one, my answer to the above question is: I cheat. For me, it's pretty simple. Beginning with the second slide from that LinkedIn post, I explain what I mean by " I cheat ".
This started out as a bit of an end-of-the-year grab bag of posts, but I don't like simply linking to things, dropping links with no explanation as to why; instead, I'd rather share the why behind what I found interesting about the post or article. And don't worry... I know after 2025, there are folks out there expecting a flaming bag full of dog poop dropped off on their doorstep, but rest assured... this isn't that. Anyway, as I was working on this post, it just sort of rolled into 2026, so I'll start off my first post of the year with a grab bag of things I found interesting right there at the end of 2025. What's in your Registry? CloudSEK recently shared this write-up on Silver Fox; what I found most interesting was from "Stage 4 - Valley RAT", "Stage 2".
I ran across a LinkedIn post the other day that mentioned using Windows Defender Support Logs (actually, I think the post referred to them as "diagnostic" logs). These logs are found in the following folder: C:\ProgramData\Microsoft\Windows Defender\Support\ ...and follow the naming convention: MpWppTracing-YYYYMMDD-HHMMSS-00000003-fffffffeffffffff.bin The post mentions using strings to parse the files, but I was wondering if there was a parser available, and like Deadpool, I figured I'd go looking... and I found something called mplog_parser . I've had a few opportunities to pull down some of these files from endpoints, but nothing has popped out as being related to the incident in question. That's okay, though...I'll keep this one in my kit, and I'll have to give the parser from Github a shot.
I received a question recently, one I receive every now and again, asking if there are any updates to an open source tool I created a while back, called "RegRipper". This time, the question came in this way: Is there any update on reg tool? After a little more back and forth, I was able to tease out that the question was about RegRipper, and the question was really directed more at asking about reg keys updates for win11 . My response was the usual, that everything's online. After all, in addition to my blog, the GitHub repo is publicly available, so anyone can take a look at it and see what's new. I mean, I don't have to do your Googling for you.
I'm not a fan of many podcasts. I do like a conversational style, and there are some podcasts that I listen to, albeit not on a regular basis, and not for technical content. They're mostly about either "easter eggs" in Marvel or DC movies, or the conspiracies or speculation about an upcoming movie. Yeah, I know what you're thinking... why spoil it? The fact of the matter is that the way things are going with these superhero movies, it's going to be 2 or more years before the movie even comes out, and there's no way I'm going to remember the podcast. When it comes to technical content, however, my podcast or video preferences are much more stringent. I'm not a big fan of gratuitous small talk and hilarity; for technical content, I take a more focused approach, and would tend to look for show notes, rather than sit through chatter, ads, and shoutz to sponsors.
Every now and then, I get contacted by someone who tells me that they used the open source tools I've released in either a college course they took, or in a course provided by one of the many training vendors in the industry. I even once responded to an incident for a large energy sector organization, and while I was orienting myself to the incident, I looked over one of their analyst's shoulders and recognized the output of the tool they were using... it was one of mine. What I've seen pretty consistently throughout my time in the industry is that once tools are known, people begin downloading them, and including them in their distros/toolsets, and some even add them to training courses (colleges, LE, the federal gov't, private sector, etc.)
August 1, 2025 Part 1 of 3: Starting A Digital Forensic Business " First say to yourself what you would be; and then do what you have to do.” -Epictetus Interestingly, I still get inquiries about starting a digital forensic business, even after penning an article entitled “ So You Want to Start a Digital Forensic Business ” over 5 years ago, wherein I cautioned would-be entrepreneurs about setting up their own shop, using personal anecdotes of essentially what not to do. Since then, a lot has changed. My company was acquired by a larger, nationwide digital forensics & e-discovery provider and we’ve grown immensely in that time. Access to digital forensic tools has evolved, particularly for those of us in the private sector.
June 1, 2025 Checks & Balances in DF/IR " Freedom is not secured by the fulfilling of one’s desires, but by the removal of desire where it is not appropriate. " -Epictetus Discourses AUTHOR’S NOTE : As some of you may have seen, I was away for the first of the month, so I posted a place-holder for this article. My apologies… I was out seeing some of our beautiful country. One of the benefits to writing, speaking & posting regularly is that I have the built-in opportunity to network with other DF/IR professionals. I’m also fortunate that I can combine these activities with things that are of value to me professionally and to my employer. What inevitably comes from these networking opportunities are conversations on a litany of topics that affect our practice areas.
May 1, 2025 Due Diligence In The Search For & Practice of Digital Forensics "If someone is able to show me that what I think or do is not right, I will happily change, for I seek the truth, by which no one was ever truly harmed. It is the person who continues in his self-deception and ignorance who is harmed." -Marcus Aurelius Meditations There’s been a lot of chatter lately about the qualifications, credentials, experience, education and credibility of digital forensic practitioners. If you don’t know what I’m talking about, I suggest searching on LinkedIn or other related platforms. Notably, a longtime practitioner in the Midwest has recently been placed under investigation by the FBI for essentially perjuring himself with regard to many of these listed characteristics, a definite bellwether for bad tidings and a position I don’t think anyone reading this post would want to be in.
April 1, 2025 The Business of Digital Forensics & Incident Response: A Brief Guide For Law Enforcement & Private Sector Practitioners "It is not from the benevolence of the butcher, the brewer, or the baker that we expect our dinner, but from their regard to their own interest." -Adam Smith The Wealth of Nations I read a lot of your posts. Yes, yours. Virtually all of you in DF/IR, in the practice both in and outside of law enforcement. A bunch of you in professional litigation support and incident response services. Those of you who run, operate and work with digital forensic teams across the US and across the World. I read the posts about the psychological toll that DF/IR work can take on a person. I read the posts about the new artifacts that are discovered in iOS. I read the deep-dives into location data and SEGB files.
March 1, 2025 Dabblers v. Professionals " If you do the job in a principled way, with diligence, energy, and patience, if you keep yourself free of distractions, and keep the spirit inside you undamaged… then everything you do will be suffused with justice." -Marcus Aurelius I recently had a discussion with a colleague or two while attending the American Academy of Forensic Sciences (AAFS) annual meeting in Baltimore, MD. These discussions revolved around the observation that digital forensics, unlike any other forensic discipline, attracts all kinds of “practitioners” who think they can do the job to an professional, expert-level degree (and tell their clientele they can do the job), but in reality, they are lacking many of the baser elements to practicing a true forensic science discipline.
The Pyramid of DF/IR Expertise "First say to yourself what you would be; and then do what you have to do." -Epictetus I woke up one day and realized I’m an Executive at a Nationwide Digital Forensic & E-Discovery professional services firm. How did that happen? I also woke up one day and realized I have 25 years in the justice system. If I’d stayed in law enforcement, I could retire this year. All of these things are simultaneously shocking and sobering. They cause one to really reflect on the steps that it took to get them to where they have arrived. It also causes one to take inventor of all of the opportunities, successes, mistakes, failures, training, experience, case work and daily practice – both mental and practical – that go into building a body of work. It also makes one feel old all of a sudden, but “old(er)” doesn’t have to equal bad, as I’ve come to learn.
January 12, 2025 Effective Advanced Communication in DF/IR “Nothing important comes into being overnight; even grapes or figs need time to ripen.” -Epictetus As my bio and LinkedIn page relay, I teach a lot. One of those teaching roles is as an Adjunct Professor in the Department of Forensic Science teaching an Intro to Digital Forensics course at Virginia Commonwealth University, which also happens to be my Alma Mater. I teach one semester per year, which, when combined with a list of other responsibilities, is quite enough. For those of you who teach, you know that most semesters start off with excitement and energy and by the time the 15 or 16-week course starts to wind down, it can be a bit of a grind. Even teaching once a week for 3 hours is grueling at times, especially with regard to assignments, grading, testing, etc… Oh, and FT work too!
A New Memory Forensics Challenge Source
A Linux Memory Forensics Challenge by 13Cubed Source
My humble opinion about the Memory Forensics Section of CCD Source