← All issues
cybersecurityCyberBubbledata-breach

153 Million Driver's Licenses Are for Sale — and the Breach Is Still Active

🌐  World Intel
Serbia: Pegasus Spyware Hits Student Protest Movement

A Serbian student activist's iPhone was secretly infected with Pegasus spyware using a zero-click exploit targeting Apple's iMessage, according to researchers at Citizen Lab and the SHARE Foundation. The infection dates to December 2025–January 2026, right as the student movement was gaining momentum. Apple patched the specific flaw used in this attack back in iOS 18.4.1 — if your iPhone isn't updated, now is the time.

↗ The Hacker News
North America: 153 Million Driver's Licenses for Sale on the Dark Web

A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, offering dark web buyers access to scans of over 153 million U.S. and Canadian driver's licenses — including full front-and-back images and infrared scans. Investigative journalist Brian Krebs confirmed his own license is in the database, and traced the breach to an identity verification company likely used by car rental firms including Hertz. The FBI's New Orleans field office has opened an inquiry.

↗ Krebs on Security
United States: Court Software Breach Exposes SSNs Across 11 States

Thomson Reuters disclosed that hackers broke into C-Track, a court case management platform used across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, stealing files that may include Social Security numbers, driver's license numbers, dates of birth, and medical information. The breach happened in March 2026 but wasn't discovered until June 30. If you've had any court involvement in an affected state, you may qualify for 12 months of free Experian credit monitoring — call 1-833-918-5294 with engagement number B171847.

↗ The Hacker News
⚔️  Active Attacks
46-Country Phishing Campaign Uses Tax Forms, Shipping Notices to Push Remote Access Software

A large phishing campaign spanning 46 countries — with the United States as the top target at 45% of attacks — is tricking victims into installing legitimate remote monitoring and management (RMM) software. Attackers send convincing fake documents: tax notices, UPS shipping updates, Social Security Administration letters, and Adobe PDF prompts. Once installed, the RMM software gives attackers full remote control of the victim's computer. The campaign uses disposable, rapidly rotated web infrastructure to stay hard to track, and researchers have linked at least 601 confirmed cases to the operation so far.

🛡 What to do: Never install software prompted by an unexpected email or document — even if the document looks official. Contact the supposed sender directly through a number you look up yourself before acting.
Pegasus Alert: Apple Sends Spyware Warnings to Users in 110 Countries

Apple has sent a fresh round of threat notifications to an unspecified number of users across 110 countries, warning them they may have been targeted by mercenary spyware. The Serbian student case confirmed above is one direct result. Pegasus can read your messages, turn on your microphone and camera, and track your location — all without you knowing. Anyone who receives an Apple threat notification should take it seriously and contact digital security organizations like Access Now for help.

🛡 What to do: Update your iPhone to the latest iOS version immediately. If you receive an Apple threat notification email or alert, do not ignore it — follow Apple's guidance at apple.com/support/threat-notifications.
🔓  New Vulnerabilities
CVE-2026-82329 JFrog Artifactory CRITICAL

A critical flaw in JFrog Artifactory — a popular tool companies use to store and manage software packages — lets attackers bypass login entirely and create administrator-level access tokens for themselves. With those tokens, an attacker gets full control over the platform, meaning they could tamper with software packages that developers download and use in their own products. Active exploitation has already been confirmed in the wild.

Status: Patch available — update JFrog Artifactory immediately.

CVE-2026-9586 Sangoma Switchvox VoIP CRITICAL

Attackers are actively exploiting a flaw in Sangoma Switchvox, a VoIP phone platform used by many businesses. The bug is an SQL injection vulnerability that requires no login — anyone on the internet can exploit it to run their own code on the server. Reverse shell access has already been deployed in observed attacks, giving hackers a live connection into victims' systems.

Status: Patch available — apply the Sangoma update immediately if your business uses Switchvox.

CVE-TBA All-in-One WP Migration & Backup (WordPress) HIGH

A serious SQL injection flaw in the widely installed All-in-One WP Migration and Backup plugin for WordPress could let an unauthenticated attacker — someone with no account at all — run code on your website and take full control of it. Millions of WordPress sites use this plugin for backups, making the potential blast radius very large.

Status: Patch available — update the plugin to the latest version immediately from your WordPress dashboard.

🛠  New Tech
Android 17 Adds ECH to Make Your Browsing Much Harder to Snoop On

Google's upcoming Android 17 will support Encrypted Client Hello (ECH), a privacy upgrade that hides which websites you're visiting from your internet provider, network administrator, or anyone else monitoring your connection. Right now, even on HTTPS sites, the name of the site you're connecting to leaks in plain text during the handshake — ECH closes that gap. This is a meaningful win for everyday privacy, particularly for people in countries where internet traffic is monitored. No action needed from users; it will work automatically once Android 17 rolls out.

💡  Deep Dive
153 Million Driver's Licenses Are for Sale Online. Yours Might Be One of Them.

Imagine walking into an airport, handing your ID to a car rental agent, and never thinking about it again. Now imagine that scan of your license — front, back, even an infrared image — is sitting in a criminal's database, available for anyone with a few dollars in cryptocurrency to browse. That's the reality for potentially over 153 million Americans and Canadians right now.

A new dark web service called Nexus launched this week on a Russian cybercrime forum, selling high-quality scans of driver's licenses. Investigative reporter Brian Krebs confirmed his own license was in the database and spent days figuring out where the images came from. The breakthrough came when he noticed timestamps on his license scan matched the exact date he took a flight — and then realized the source wasn't airports at all. Friends who hadn't flown but had rented cars from Hertz around those dates were also in the database. The working theory: a major identity verification company — used by car rental firms and other businesses to verify your identity — has been continuously breached for over a year, with fresh data still being uploaded. The number of records grew by nearly 400,000 in a single day. The FBI is now investigating.

This matters because a driver's license scan is a goldmine for identity theft. Unlike a leaked password, you can't change your face, your date of birth, or your license number. These images could be used to open bank accounts, take out loans, pass identity checks at financial institutions, or even create fake IDs. The records also include marijuana dispensary cards and possibly government Common Access Cards — meaning the exposure goes well beyond ordinary consumers.

Watch for official notifications from identity verification services or Hertz in the coming weeks. In the meantime, place a free credit freeze with all three major credit bureaus — Equifax, Experian, and TransUnion — at no cost. A freeze is the single most effective thing you can do to stop someone from opening new accounts in your name, even if they have a copy of your ID.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →