DFIR News, 23 Sep 2026

A round-up of today’s digital forensics news and views:


Forensic Focus News

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification.

Read more (forensicfocus.com)


Radim Motycka, Founder, Proofsnap

Why screenshots alone may not be enough: ProofSnap founder Radim Motycka explains how hashes, timestamps, WARC, network artefacts and independent verification can strengthen the preservation of web evidence.


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Read more (forensicfocus.com)


Evidence Locker Adds CTF and Memory Images

The Evidence Locker has added new practice datasets including Josh Brunty CTF images, Hackropole memory and iOS images, EC Cybersecurity Operations Centre sysdiagnose files, OSForensics sample memory images for Volatility Workbench, and sanitized Slack files. File search improvements include hash-based cross-correlation, evidence source filtering, tooltip OS indicators, and pagination upgrades allowing direct page navigation.

Read more (theevidencelocker.github.io)


Threat Intelligence

CERT Polska Dissects MikroTik Auth Bypass Chain

CERT Polska researchers identified a two-CVE chain, dubbed MikroTrick, allowing full administrative access to MikroTik RouterOS devices without credentials. CVE-2026-67279 exploits incorrect SSH rekey handling during authentication, while CVE-2026-86060 abuses argument injection in the login binary. Patches were released across multiple RouterOS branches in September 2026, and specific IoCs including a rogue ops account and failed login for user -2 aid post-compromise detection.

Read more (cert.pl)


Research & Techniques

SEM Recovers Crash Data from Destroyed EDR Modules

Researchers Sergei Skorobogatov and Peter Vertal recovered EDR crash data from a severely damaged SRS/airbag control module using Scanning Electron Microscopy to examine physically destroyed EEPROM memory cells. Recovered data was then processed with CrashScan, demonstrating that visible hardware damage does not necessarily render vehicle crash data unrecoverable. Vehicle forensics examiners are reminded that OBD, bench, ISP, chip-off, and SEM approaches each unlock different data recovery possibilities.

Read more (arxiv.org)


Automating Edge Device Memory Forensics with Volatility

Edge devices remain among the hardest forensic targets despite their growing role in intrusions. A session at Volexity Cyber Sessions in Amsterdam on October 29 will cover an agentic framework that fingerprints unknown networked devices, selects architecture-appropriate acquisition paths, and extends Volatility 3 to support MIPS-based routers natively unsupported by the tool.

Read more (luma.com)


Training & Events

DFIR Summit Showcases Real Case Digital Evidence

Investigators Heather Barnhart and Jason Higley, whose cases featured in Netflix documentaries, will present the actual digital evidence from those investigations at the SANS DFIR Summit on October 15, 16 in Arlington. Attendees will see firsthand what the digital artifacts looked like in real casework, making it a rare methodology-focused session for working investigators.

Read more (sans.org)


In-Depth Review: 13Cubed Windows Memory Course

An independent reviewer has published a detailed assessment of 13Cubed’s Investigating Windows Memory course, covering its content and value for DFIR practitioners. A prior review of the Investigating Windows Endpoints course is also available for those evaluating training options.

Read more (krzysztofkuzin.substack.com)

Leave a Comment