← All issues
cybersecurityCyberBubbleidentity-theft

153 Million Driver's Licenses For Sale, Chrome Zero-Day Hits, WordPress Under Fire

🌐  World Intel
USA: 153 Million Driver's Licenses Leaked from Identity Firm Breach

A new dark web service called "Nexus" is selling digital scans of over 153 million US and Canadian driver's licenses. The images appear to come from an ongoing breach at a major identity verification company — one whose customers include Fortune 500 companies. The FBI's New Orleans field office has opened an investigation, and the stolen data is still growing by hundreds of thousands of records per day.

↗ Krebs on Security
France: Hospital Fined €500,000 for Exposing 727,000 Patients' Data

France's data protection authority hit Hôpital privé de la Loire with a €500,000 ($580,000) fine after a breach exposed the personal data of 727,000 patients and their relatives. The hospital failed to put adequate security protections in place, regulators said. It's a reminder that healthcare providers hold some of the most sensitive data imaginable — and are being held financially accountable when they don't protect it.

↗ BleepingComputer
Global: OpenAI Launches GPT-6 Astra — Scores 100% on Hacking Benchmark

OpenAI officially released GPT-6 Astra this week, calling it its "most intelligent and aligned model." The model hit a perfect 100% score on ExploitBench, a test that measures an AI's ability to find and exploit software vulnerabilities. OpenAI has blocked the model from generating working exploit code on demand, but the result still signals that AI systems are fast approaching a level where they could assist in serious cyberattacks.

↗ The Hacker News
⚔️  Active Attacks
WordPress Sites Under Siege: 440,000+ Exploit Attempts Targeting Popular Plugins

Attackers are hammering WordPress websites using two critical flaws in the Super Forms and Elementor Pro plugins. Both bugs let anyone — no login required — upload malicious files to a website and take full control of it. So far, security researchers at Wordfence have counted over 440,000 attack attempts. Once inside, attackers can create fake admin accounts, steal data, or do whatever they want with the site.

🛡 What to do: If you run a WordPress site, log into your dashboard right now and update Super Forms to version 6.3.314 or later, and Elementor Pro to version 4.2.2 or later. Do it before the weekend.
Chrome Zero-Day Being Exploited Right Now — Update Your Browser Today

Google confirmed that a high-severity zero-day vulnerability in Chrome is actively being used in real attacks. The bug lives in V8, Chrome's JavaScript engine. A hacker can trick you into visiting a specially crafted webpage, then run malicious code inside your browser. No extra clicks needed beyond loading the page.

🛡 What to do: Open Chrome, click the three dots in the top-right corner, go to Help → About Google Chrome, and let it update to version 152.0.7977.82 or newer. Then restart the browser.
🔓  New Vulnerabilities
CVE-2026-14894 Super Forms (WordPress Plugin) CRITICAL 9.8

This flaw lets anyone — no account needed — upload any file type to a WordPress site using the Super Forms plugin, including files that can run code on the server. Attackers are already using this to plant web shells and seize full control of websites.

Status: Patch available — update to Super Forms version 6.3.314 immediately.

CVE-2026-32475 Elementor Pro (WordPress Plugin) CRITICAL 9.8

The same class of flaw as above — an unauthenticated attacker can upload dangerous executable files through Elementor Pro and run arbitrary commands on the web server. This plugin is installed on millions of websites, making this one of the wider-reaching WordPress bugs in recent memory.

Status: Patch available — update to Elementor Pro version 4.2.2 immediately.

CVE-2026-85046 Google Chrome (V8 Engine) HIGH 8.8

A type confusion bug in Chrome's V8 engine lets a remote attacker run malicious code inside your browser just by getting you to load a crafted webpage. It's being actively exploited in the wild right now. Discovered by researcher Salvatore Gulizia and reported to Google on August 4.

Status: Patch available — update Chrome to version 152.0.7977.82 or later.

FalconFlank (0-day) CrowdStrike Falcon (Windows) CRITICAL

An anonymous researcher released a working zero-day exploit called "FalconFlank" targeting CrowdStrike's Falcon security software. The exploit allows an attacker who already has limited access to a Windows PC to elevate their privileges to SYSTEM — the highest level of control on a Windows machine. This is especially ironic since Falcon is endpoint security software meant to stop exactly this kind of attack.

Status: No patch confirmed yet — watch for a CrowdStrike update. Monitor your systems for unusual privilege escalation activity.

Plex — Multiple CVEs Plex Media Server & Desktop HIGH (unscored)

Plex has patched multiple undisclosed security flaws in both Plex Media Server (version 1.43.3) and Plex Desktop (version 1.115.0). The company hasn't said what the bugs are, but it's asking all users to update immediately. If you run Plex on a NAS device, you may need to install the update manually since it might not appear in the device's package manager yet.

Status: Patch available — update to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 now.

🛠  New Tech
Passkeys Aren't a Silver Bullet: Researchers Document 39 Ways to Break Them

Passkeys have been widely praised as a replacement for passwords — and they are more secure in most ways. But security firm Token has published research documenting 39 methods attackers can use to compromise passkey-based authentication without ever breaking the underlying cryptography. The attacks target weaker points in the system: how passkeys sync across devices, how accounts recover after a lost device, and how apps prompt users to approve sign-ins. The research isn't a reason to avoid passkeys — they're still far better than passwords — but it's a useful reminder that no single technology solves security on its own.

Coder's Dev Tool Registry Hijacked to Distribute Credential-Stealing Code

Attackers compromised Coder's Cloudflare infrastructure and injected unauthorized servers into the company's Terraform module registry. Developers who downloaded modules from the compromised registry unknowingly received code that steals credentials from their systems. This is a supply chain attack — instead of hacking end users directly, attackers go after the tools developers trust and use every day.

💡  Deep Dive
Your Driver's License Is For Sale Online — And It May Have Come From a Car Rental Counter

Imagine waking up to find your driver's license — front, back, infrared scan, and all — listed for sale on a criminal website, timestamped to the exact day you rented a car last summer. That's the situation facing potentially 153 million Americans and Canadians right now, thanks to a massive breach that security journalist Brian Krebs uncovered this week.

The service, called "Nexus," appeared on a Russian cybercrime forum at the end of August. It offers searchable access to digital scans of driver's licenses, ID cards, government access cards, and even medical cards. Krebs tested it himself — his own license was offered as a free sample. He then asked friends and family to check if their licenses were in there. Nine out of twelve were. Every single one of those nine people confirmed they had used their driver's license at or around the exact date stamped on their stolen image. The pattern pointed away from airports — passports weren't in the data, and some people had never flown recently at all. What they had in common: renting a car from Hertz. The breach appears to trace back to an identity verification company based in Louisiana whose services Hertz and other major businesses use to scan and verify IDs. The company has not been publicly named yet, but the FBI is now investigating.

For regular people, this is deeply unsettling. Driver's licenses contain your photo, address, date of birth, and ID number — everything an identity thief needs. The Nexus service even includes infrared and ultraviolet scans of licenses, the kind of images normally used to verify documents are genuine. Criminals could use these to open financial accounts, apply for loans, or impersonate you in any situation that asks for ID. High-ranking US government officials — including Cabinet-level names — also appeared in the database, raising serious national security concerns beyond everyday identity theft.

There's no fix you can apply to protect yourself retroactively. But you should monitor your credit reports for unusual activity, consider placing a free credit freeze with the three major bureaus (Equifax, Experian, TransUnion), and watch for suspicious mail or communications referencing your address. If your state offers it, check whether your driver's license number can be changed after an identity theft incident. This story is still developing — Krebs says the stolen record count is growing by nearly 400,000 per day.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →