Cracking Legacy ZIP Encryption: The Known-Plaintext Attack and Why It Still Sometimes Works 🔒
When someone hands you a password-protected ZIP archive, one’s immediate thought is:
For most modern archives, that is exactly the case, and the password is the whole game. But there is a family of ZIP archives where the password does not matter at all. It can be four characters or forty, random or memorable, if the archive uses the legacy ZIP encryption, the whole thing can be unlocked in minutes without ever guessing the password.
This is one of the oldest tricks in our line of work, and it is worth telling the story properly, because it is equal parts computer history and practical forensics🔑
A word of caution before we start. The attack we are about to describe applies to the classic ZIP 2.0 encryption, the scheme Phil Katz built into PKZIP in the late eighties. Almost nobody should be creating archives with it today. Modern archivers default to AES, which is a completely different situation.
So treat most of this article as a fascinating piece of history, with a long and narrow tail of cases where it still bites in real life.
More information at the link📎
When someone hands you a password-protected ZIP archive, one’s immediate thought is:
“I need to break the password”.
For most modern archives, that is exactly the case, and the password is the whole game. But there is a family of ZIP archives where the password does not matter at all. It can be four characters or forty, random or memorable, if the archive uses the legacy ZIP encryption, the whole thing can be unlocked in minutes without ever guessing the password.
This is one of the oldest tricks in our line of work, and it is worth telling the story properly, because it is equal parts computer history and practical forensics
A word of caution before we start. The attack we are about to describe applies to the classic ZIP 2.0 encryption, the scheme Phil Katz built into PKZIP in the late eighties. Almost nobody should be creating archives with it today. Modern archivers default to AES, which is a completely different situation.
So treat most of this article as a fascinating piece of history, with a long and narrow tail of cases where it still bites in real life.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
Digital Triage and the Rules of Evidence: What Holds Up, and Where👆
The scene is familiar. A couple of desktops, a laptop, two or three phones, maybe a NAS or a bunch of external drives, and a limited amount of time before you decide what you do on the spot and what can wait till the lab.
You cannot image everything on the spot, and even if you could, the lab queue would swallow it for weeks. So you triage: you look at what is in front of you and decide what matters, what is urgent, and what can wait.
The catch is that the decisions made in that first hour cast a long shadow. They determine not only what you find, but whether what you find can be used later, in a courtroom.
❤️ This article is about that connection. How triage actually works, what principles govern the handling of digital evidence everywhere – not just the US, and why the very same misstep can be fatal in one country and a minor footnote in another.
Reminder: this is exactly what Elcomsoft Quick Triage is built to do on Windows systems. It captures the volatile side of a live session fast, memory, browser and account credentials, communications and user activity, along with the system artifacts that reconstruct who did what and when, and it stores everything in a single open container that keeps each artifact tied to its source.
More information at the link📎
#EQT
The scene is familiar. A couple of desktops, a laptop, two or three phones, maybe a NAS or a bunch of external drives, and a limited amount of time before you decide what you do on the spot and what can wait till the lab.
You cannot image everything on the spot, and even if you could, the lab queue would swallow it for weeks. So you triage: you look at what is in front of you and decide what matters, what is urgent, and what can wait.
The catch is that the decisions made in that first hour cast a long shadow. They determine not only what you find, but whether what you find can be used later, in a courtroom.
Reminder: this is exactly what Elcomsoft Quick Triage is built to do on Windows systems. It captures the volatile side of a live session fast, memory, browser and account credentials, communications and user activity, along with the system artifacts that reconstruct who did what and when, and it stores everything in a single open container that keeps each artifact tied to its source.
More information at the link
#EQT
Please open Telegram to view this post
VIEW IN TELEGRAM
An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs 👩💻
On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure.
The company was clear about what it did not know: which model was driving the agent, or who was operating it.
Five days later, OpenAI answered both questions. The agent was its own, running an internal benchmark with its cyber safety refusals deliberately switched off, and it had gone looking for the answers to a test.
This is a good story on its own. It becomes a better one when you line it up against what people were saying about model governance in the same week.
More information at the link📎
On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure.
The company was clear about what it did not know: which model was driving the agent, or who was operating it.
Five days later, OpenAI answered both questions. The agent was its own, running an internal benchmark with its cyber safety refusals deliberately switched off, and it had gone looking for the answers to a test.
This is a good story on its own. It becomes a better one when you line it up against what people were saying about model governance in the same week.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2👍1
Why Digital Forensic Reports Don’t Survive Cross-Examination❓
A forensic report is not a summary of finished work. It’s a claim that has to survive someone trying to take it apart, and most reports aren’t built for that.
A lot of what gets filed today is automated tool output with a cover letter attached: the examiner runs a parser, exports a spreadsheet, writes three sentences of narrative, and calls it analysis. That holds up fine until an opposing expert asks how the software actually reached its conclusion.
🔉 Three real cases show what happens when nobody asks that question early enough.
More information at the link📎
A forensic report is not a summary of finished work. It’s a claim that has to survive someone trying to take it apart, and most reports aren’t built for that.
A lot of what gets filed today is automated tool output with a cover letter attached: the examiner runs a parser, exports a spreadsheet, writes three sentences of narrative, and calls it analysis. That holds up fine until an opposing expert asks how the software actually reached its conclusion.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥2
How to recover deleted data from your iPhone 👤
You accidentally deleted an important file from your iPhone, panicked, and hit the web looking for a way to get it back...
Instantly, you’re hit with a barrage of search results pushing “iPhone data recovery” software. If you look closely, you’ll notice almost all of these apps are low-quality rebrands or slightly tweaked forks of just a handful of identical tools.
❓ Before you pull out your credit card, you need to understand what can actually be recovered from an iPhone, and what is gone for good.
More information at the link📎
You accidentally deleted an important file from your iPhone, panicked, and hit the web looking for a way to get it back...
Instantly, you’re hit with a barrage of search results pushing “iPhone data recovery” software. If you look closely, you’ll notice almost all of these apps are low-quality rebrands or slightly tweaked forks of just a handful of identical tools.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
👍1
When the iCloud Backup Is the Only Copy Left ☁️
An iCloud backup is often the only surviving copy of data no longer on the device. Two ordinary situations show why, and neither involves anything clever on the suspect’s part.
What could possibly go wrong, and how can you access the data?
⏺ Case one: the update that went wrong
Updates fail, usually for a boring reason: not enough free space. iOS downloads the update, starts installing, runs out of room, and the phone reboots into Recovery mode – the cable-and-computer screen, nothing else. Connect it to a Mac or PC and you get two options: Update, which reinstalls the system and keeps data, or Restore, which wipes it.
Major version jumps fail worse. We’ve seen updates leave a device unable to boot at all, with reports of the passcode being rejected afterward, which points at Secure Enclave state rather than the file system.
Either way, the outcome for an examiner is the same. A phone stuck in Recovery mode won’t yield a file system image.
⏺ Case two: the data that was deleted
Deleting something on an iPhone takes two taps, and the safety net is thin. Photos, Notes, Voice Memos and iCloud Drive files go to Recently Deleted and stay about 30 days.
This is where synced data and backups diverge. Synced categories propagate a deletion within seconds of the device going online, so the cloud copy usually mirrors the device by the time anyone checks. Back up overnight, delete the file the next morning, and the file is still in last night’s backup. The older of the two stored backups can predate the deletion by weeks.
😀 We covered the user-facing side of this recently: How to recover deleted data from your iPhone.
More information at the link📎
An iCloud backup is often the only surviving copy of data no longer on the device. Two ordinary situations show why, and neither involves anything clever on the suspect’s part.
What could possibly go wrong, and how can you access the data?
Updates fail, usually for a boring reason: not enough free space. iOS downloads the update, starts installing, runs out of room, and the phone reboots into Recovery mode – the cable-and-computer screen, nothing else. Connect it to a Mac or PC and you get two options: Update, which reinstalls the system and keeps data, or Restore, which wipes it.
Major version jumps fail worse. We’ve seen updates leave a device unable to boot at all, with reports of the passcode being rejected afterward, which points at Secure Enclave state rather than the file system.
Either way, the outcome for an examiner is the same. A phone stuck in Recovery mode won’t yield a file system image.
Deleting something on an iPhone takes two taps, and the safety net is thin. Photos, Notes, Voice Memos and iCloud Drive files go to Recently Deleted and stay about 30 days.
This is where synced data and backups diverge. Synced categories propagate a deletion within seconds of the device going online, so the cloud copy usually mirrors the device by the time anyone checks. Back up overnight, delete the file the next morning, and the file is still in last night’s backup. The older of the two stored backups can predate the deletion by weeks.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
Elcomsoft iOS Forensic Toolkit begins low-level extraction by sideloading the extraction agent, and the agent will not run until the phone has completed one or two checks against Apple’s servers.
Network requests, on a phone that is evidence. That single requirement is why we have shipped three different firewalls over the past three years.
Why the phone needs the internet at all?
The phone has to reach a small number of Apple hosts, one of which has a name that resolves to a different address every few minutes, and nothing else. Arranging exactly that is harder than it sounds.
More information at the link
#EIFT
Please open Telegram to view this post
VIEW IN TELEGRAM
The iOS 27 Recovery Menu: What It Means for Forensics 👆
iOS 27 and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.
Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old “connect to computer” recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone📱
The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.
Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.
More information at the link📎
iOS 27 and iPadOS 27, currently in beta, add a bootable recovery menu to the iPhone and iPad.
Hold the power button while the device starts up and you land in a small pre-boot environment with six options, one of which is the old “connect to computer” recovery mode. This is the same idea Apple silicon Macs have had for years, and it is overdue on the phone
The feature is aimed at owners whose device hangs at the Apple logo or loops after a failed update.
Our interest is different: this is new code that runs on a locked device before the data volume is unlocked, it talks to the network, and it can erase the device. All three matter to us.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
Write Blockers in Forensics: What Controls How You Use Them?
In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.
Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.
🟡 Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter.
The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.
🗣 And here comes the question: which laws or standards mandate using a write blocker?
More information at the link📎
In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit.
Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable.
The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
The True Meaning of Consent in ‘Consent Extractions’ ✅
In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.
❤️ Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the “Trust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top.
An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.
🗣 This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.
More information at the link📎
In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key.
An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft System Recovery 8.38: Built-In BitLocker TPM Exploit Library, Browser Artefact Extraction, and Imaging Checksums
▪️ Elcomsoft System Recovery, a bootable digital triage tool, now offers to build you a second USB flash drive for a BitLocker exploit during installation▪️
Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.
Let's talk about:
🟡 what actually this does
🟡 background
🟡 browser extraction, imaging, checksums, and more
🟡 Elcomsoft System Recovery 8.38 release notes
More information at the link📎
Version 8.38 supports two exploits this way: YellowKey and GreatXML.
The release also adds checksum logging for disk images and updates the imaging library.
Let's talk about:
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM
Elcomsoft Quick Triage 2.2 adds three things:
More information at the link
Please open Telegram to view this post
VIEW IN TELEGRAM