Elcomsoft
552 subscribers
570 photos
1 video
1 file
455 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
“Get Verification Code” Is Missing in iOS 18 and iOS 26; Here’s Where It Went🤔

If you have an Apple device running iOS 18 or iOS 26 and gone looking for the old Get Verification Code option under:

Settings → [user name] → Sign-In & Security


..you’ve probably noticed it’s no longer there. A quick search turns up forum threads, support comments, and even GitHub issues all reaching the same conclusion: Apple removed it.
Some posts go further and call it “deprecated” or “Apple’s middle finger to users of older devices.” 

😊That conclusion is wrong. The option still exists in iOS 26. It just doesn’t show up the way it used to.

We tell you how to actually get an offline code in iOS 26 and iOS 18 and why this matters.

More information at the link📎

#Tips
Please open Telegram to view this post
VIEW IN TELEGRAM
🆕Bypassing Stolen Device Protection: Alternative Ways of Installing the Extraction Agent🆕

Stated plainly: iOS Forensic Toolkit can now get past Stolen Device Protection.

There is a catch, and it belongs up front: this is not a magic unlock, and anyone selling it as one is selling something.

🔥What we have built is a way to install the extraction agent without ever pairing the iPhone to the workstation over a USB port.
Because the most disruptive thing SDP does to a forensic workflow is place Face ID or Touch ID in front of that pairing step, bypassing the pairing step bypasses the gate.
You still need:
🟢the device passcode;
🟢a paid Apple Developer account;
🟢a device you are authorized to examine.

With those in hand, SDP is no longer the wall it was a month ago.

This is the solution promised in Forensic Implications of Apple Stolen Device Protection. The how – every command, in order – will appear in a separate technical write-up.

This piece covers what the method does, when you would reach for it, and whether it should concern anyone who is not an examiner.

More information at the link📎

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
4🔥1
Sideloading the extraction agent: a Stolen Device Protection workaround👤

A new update to iOS Forensic Toolkit is out.
The headline feature is an alternative installation method for the extraction agent – that is, deploying it onto an iPhone while bypassing the mandatory pairing requirement.
The agent can now be delivered across the network, which removes a number of limitations that came with the usual cable-based installation. One requirement up front: the device must already be unlocked – in other words, the passcode must be known. This method does not work with a fully locked iPhone.

☺️Why a new installation method was needed?

The reason is a feature called Stolen Device Protection (SDP), which we discussed in the previous article. It is designed for the situation where a phone ends up in someone else’s hands and that person also knows the passcode.
In this mode, certain actions require biometric authentication – the owner’s Face ID or Touch ID — with no option to confirm the operation by entering the passcode. The checks tighten when the device is away from familiar locations such as home or work, and in settings they can be enforced at all times, regardless of location.

❗️Previously this protection could only be enabled optionally, and it was rarely encountered. Starting with iOS 26.4, that has changed: Apple turns Stolen Device Protection on automatically. As a result, examiners increasingly run into devices that simply will not allow a USB connection to a new computer.

😊The alternative agent delivery methods solve this.

More information at the link📎

#EIFT #Tips
Please open Telegram to view this post
VIEW IN TELEGRAM
🆕Two-Factor Authentication and iCloud: A Short History, and What We Fixed in Phone Breaker 11.03🆕

Two-factor authentication is the least glamorous security feature, and probably the most important one.

A password is “something you know”, which really means “something that can be phished, reused, leaked, or guessed”.

The second factor is “something you have”, and, while it can still be phished, it makes stolen passwords much less of a catastrophe they used to be. Everything else in account security is built on top of that. If the second factor is not there, or if it does not cover the data that actually matters, the rest is decoration.


Apple gets this right today. They did not always. The story of how they got here is worth telling, because it explains a lot about how iCloud acquisition works in 2026, and it leads directly to the two 2FA-related fixes in Elcomsoft Phone Breaker 11.03.

More information at the link📎

#EPB
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1
The Long, Strange History of PDF (In)Security – And the Arrest That Made It Personal👁‍🗨

PDF
has a reputation as the boring, dependable file format – the one you reach for when you need a document to look exactly the same on every computer, forever. What gets forgotten is that PDF’s security model has been shaky since version 1.0, and its history includes an FBI arrest, a federal jury trial that helped define how the DMCA actually works, and – twenty years later – a fake GIF that hid a tiny working computer inside an image compression stream.

This is that story, roughly in order, including the part where we were personally on the receiving end of it.

Where it all started: Adobe’s eBook experiment

Back in 1999–2001, Adobe was chasing the “eBook” market with the Acrobat eBook Reader (originally the GlassBook Reader) and a back-end called the Adobe Content Server. Publishers could lock a book down with any of several plug-in “security handlers” – Adobe’s own PDF Merchant and EBX, plus third-party schemes like FileOpen and SoftLock – restricting printing, copying, lending, or text-to-speech.

All of them shared the same underlying weakness, and it wasn’t really about key length…

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
Cracking Legacy ZIP Encryption: The Known-Plaintext Attack and Why It Still Sometimes Works 🔒

When someone hands you a password-protected ZIP archive, one’s immediate thought is:

“I need to break the password”.


For most modern archives, that is exactly the case, and the password is the whole game. But there is a family of ZIP archives where the password does not matter at all. It can be four characters or forty, random or memorable, if the archive uses the legacy ZIP encryption, the whole thing can be unlocked in minutes without ever guessing the password.

This is one of the oldest tricks in our line of work, and it is worth telling the story properly, because it is equal parts computer history and practical forensics 🔑

A word of caution before we start. The attack we are about to describe applies to the classic ZIP 2.0 encryption, the scheme Phil Katz built into PKZIP in the late eighties. Almost nobody should be creating archives with it today. Modern archivers default to AES, which is a completely different situation.

So treat most of this article as a fascinating piece of history, with a long and narrow tail of cases where it still bites in real life.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
Digital Triage and the Rules of Evidence: What Holds Up, and Where👆

The
scene is familiar. A couple of desktops, a laptop, two or three phones, maybe a NAS or a bunch of external drives, and a limited amount of time before you decide what you do on the spot and what can wait till the lab.

You cannot image everything on the spot, and even if you could, the lab queue would swallow it for weeks. So you triage: you look at what is in front of you and decide what matters, what is urgent, and what can wait.

The catch is that the decisions made in that first hour cast a long shadow. They determine not only what you find, but whether what you find can be used later, in a courtroom.

❤️This article is about that connection. How triage actually works, what principles govern the handling of digital evidence everywhere – not just the US, and why the very same misstep can be fatal in one country and a minor footnote in another.

Reminder: this is exactly what Elcomsoft Quick Triage is built to do on Windows systems. It captures the volatile side of a live session fast, memory, browser and account credentials, communications and user activity, along with the system artifacts that reconstruct who did what and when, and it stores everything in a single open container that keeps each artifact tied to its source.

More information at the link📎

#EQT
Please open Telegram to view this post
VIEW IN TELEGRAM
An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs 👩‍💻

On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure.

The company was clear about what it did not know: which model was driving the agent, or who was operating it.

Five days later, OpenAI answered both questions. The agent was its own, running an internal benchmark with its cyber safety refusals deliberately switched off, and it had gone looking for the answers to a test.

This is a good story on its own. It becomes a better one when you line it up against what people were saying about model governance in the same week.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2👍1
Why Digital Forensic Reports Don’t Survive Cross-Examination

A forensic report
is not a summary of finished work. It’s a claim that has to survive someone trying to take it apart, and most reports aren’t built for that.

A lot of what gets filed today is automated tool output with a cover letter attached: the examiner runs a parser, exports a spreadsheet, writes three sentences of narrative, and calls it analysis. That holds up fine until an opposing expert asks how the software actually reached its conclusion.

🔉Three real cases show what happens when nobody asks that question early enough.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2
How to recover deleted data from your iPhone 👤

You accidentally deleted an important file from your iPhone, panicked, and hit the web looking for a way to get it back...

Instantly, you’re hit with a barrage of search results pushing “iPhone data recovery” software. If you look closely, you’ll notice almost all of these apps are low-quality rebrands or slightly tweaked forks of just a handful of identical tools.

Before you pull out your credit card, you need to understand what can actually be recovered from an iPhone, and what is gone for good.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
When the iCloud Backup Is the Only Copy Left ☁️

An iCloud backup is often the only surviving copy of data no longer on the device. Two ordinary situations show why, and neither involves anything clever on the suspect’s part.

What could possibly go wrong, and how can you access the data?

Case one: the update that went wrong

Updates fail, usually for a boring reason: not enough free space. iOS downloads the update, starts installing, runs out of room, and the phone reboots into Recovery mode – the cable-and-computer screen, nothing else. Connect it to a Mac or PC and you get two options: Update, which reinstalls the system and keeps data, or Restore, which wipes it.
Major version jumps fail worse. We’ve seen updates leave a device unable to boot at all, with reports of the passcode being rejected afterward, which points at Secure Enclave state rather than the file system.
Either way, the outcome for an examiner is the same. A phone stuck in Recovery mode won’t yield a file system image.

Case two: the data that was deleted

Deleting something on an iPhone takes two taps, and the safety net is thin. Photos, Notes, Voice Memos and iCloud Drive files go to Recently Deleted and stay about 30 days.
This is where synced data and backups diverge. Synced categories propagate a deletion within seconds of the device going online, so the cloud copy usually mirrors the device by the time anyone checks. Back up overnight, delete the file the next morning, and the file is still in last night’s backup. The older of the two stored backups can predate the deletion by weeks.

😀We covered the user-facing side of this recently: How to recover deleted data from your iPhone.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
1
🆕Special macOS Firewall: Safe Sideloading of the EIFT Extraction Agent🆕

Elcomsoft iOS Forensic Toolkit begins low-level extraction by sideloading the extraction agent, and the agent will not run until the phone has completed one or two checks against Apple’s servers.

Network requests, on a phone that is evidence. That single requirement is why we have shipped three different firewalls over the past three years.
💡The newest one, EIFT Firewall, is a free macOS application and a direct replacement for the 2023 script!

Why the phone needs the internet at all?

The phone has to reach a small number of Apple hosts, one of which has a name that resolves to a different address every few minutes, and nothing else. Arranging exactly that is harder than it sounds.

More information at the link📎

#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
The iOS 27 Recovery Menu: What It Means for Forensics 👆

iOS 27
and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.

Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old “connect to computer” recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone 📱

The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.

Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
1
Write Blockers in Forensics: What Controls How You Use Them? 🫆

In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.

Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.

🟡Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter.

The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.

🗣And here comes the question: which laws or standards mandate using a write blocker?

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
The True Meaning of Consent in ‘Consent Extractions’

In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.

❤️Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the “Trust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top.

An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.

🗣This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums

▪️Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installation▪️

Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.

Let's talk about:

🟡what actually this does
🟡background
🟡browser extraction, imaging, checksums, and more
🟡Elcomsoft System Recovery 8.38 release notes

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM
🆕Elcomsoft Quick Triage 2.2: Timeline, file system snapshot, and a plugin engine🆕

Elcomsoft Quick Triage 2.2 adds three things:

🟡a Timeline view that merges events from every timestamped artifact into one chronology
🟡a file system snapshot that copies metadata without file contents
🟡 a plugin architecture for artifact parsers

😀The release also brings MSA password attacks, OpenDocument parsing and recursive archive parsing in full-text search, and a list of fixes, but here we’ll mostly talk about the first three.

More information at the link📎
Please open Telegram to view this post
VIEW IN TELEGRAM