DFIR News, 24 Sep 2026

A round-up of today’s digital forensics news and views:


Forensic Focus News

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

Investigative capability shouldn’t be split across licences, modules and bolt-ons – S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform.

Read more (forensicfocus.com)


Industry News


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Oxygen Forensics CEO Arrested Over Russian Ownership Fraud

Lee Reiber, CEO of Oxygen Forensics, and Russian co-founder Oleg Davydov have been arrested and charged with conspiracy to commit wire fraud after allegedly concealing the company’s Russian ownership and software development from US federal customers including the Secret Service, DHS, and IRS. Prosecutors say the pair moved build infrastructure to US cloud servers while continuing to develop the software in Russia, then falsely certified to agencies that no foreign persons controlled the firm. Oxygen Forensics holds contracts across multiple federal law enforcement bodies and sells tools used to extract data from mobile devices, computers, and drones.

Read more (zetter-zeroday.com)


SANS FOR500 Case Targets North Korean IT Workers

A new SANS FOR500 Windows Forensic Analysis case, Operation Crimson Ledger, places examiners on the laptop of a remote engineer who evaded hiring checks for months. Artifacts include two remote-access tools, a consumer VPN, files staged to Google Drive, an exported mailbox, and a wiper run seven times in the two minutes surrounding an upload. Least privilege is framed as a core control, with access recommended to grow with tenure rather than granted on day one.

Read more (securityweek.com)


Threat Intelligence fits Case Studies

Honeynet Captures Full EtherHiding Intrusion Chain

A 12-day honeynet operation recorded a complete KongTuke ClickFix intrusion, from initial access through credential theft, lateral movement, and 5 GB of staged exfiltration. The Node.js backdoor resolved its C2 via EtherHiding, polling public Ethereum RPC providers to retrieve a rotating command-and-control URL, making traditional takedown ineffective. Defenders recovered packet-level evidence of LSASS dumping, SAM hive theft, Mimikatz, SystemBC persistence, and Cloudflare Tunnel exfiltration, with full IOCs and Emerging Threats signatures documented.

Read more (blog.deception.pro)


Tools & Software

New iOS Geolocation Artifact Found in Apple Intelligence

A newly identified iOS geolocation artifact, introduced with iOS 17 and linked to Apple Intelligence, is now documented and supported in iLEAPP. The artifact is accessible via After First Unlock (AFU) acquisition, making it recoverable in live device examinations. Support has been added to iLEAPP’s codebase and will ship in the next formal release.

Read more (leapps.org)

Leave a Comment