153 Million Driver's Licenses for Sale, Passkey Phishing Hits Microsoft 365
Sunday, September 13, 2026 · 5-minute read
CISA published a formal advisory warning that China-based AI companies are running coordinated campaigns to steal data and models from American AI companies at industrial scale. The technique, called distillation, lets attackers clone expensive AI systems cheaply. This is the government putting a name to something the industry has suspected for months.
↗ CISA Advisory AA26-251AThe Dutch national cybersecurity agency is sounding the alarm about two critical bugs in Check Point's VPN products, tracked as CVE-2026-85102 and CVE-2026-85103. Hackers haven't hit them widely yet, but the agency says exploitation is imminent. If your organisation uses Check Point VPN, patch now — don't wait for the weekend to be over.
↗ BleepingComputerA new dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian driver's licenses, and the FBI has opened an investigation. The images appear to come from a breach at an identity verification company used by car rental firms and other businesses — meaning the photos were captured when people showed their IDs at the counter. Journalist Brian Krebs confirmed his own license was in the database, timestamped to a trip he made last year.
↗ Krebs on SecurityGangs including ShinyHunters are sending fake login pages that look like Microsoft's new passkey and single sign-on prompts. Employees click the link, type in their credentials or approve the fake prompt, and the attackers immediately walk into their Microsoft 365 account and start pulling out data. These attacks are also pairing with AI-generated emails pretending to be the company's CEO, asking the finance team to approve wire transfers worth thousands of dollars — a classic business email compromise play, now supercharged with AI.
Attackers connected to a Chinese espionage group are using a critical bug (CVE-2026-51990) in Tencent's Sogou Input Method — a popular Chinese-language keyboard app for Windows — to install a piece of malware called GrayRabbit. A backdoor like GrayRabbit lets criminals return to a compromised machine whenever they like, without needing to break in again. If anyone in your organisation uses Sogou Input Method, update it immediately.
This is the worst possible severity score: a perfect 10. The bug is a path traversal flaw in GitLab's code repository API. An attacker who isn't even logged in can read any file stored on a GitLab server — think private code, configuration files, passwords, and API keys. Security researchers spotted active probing of this vulnerability within hours of it being made public on September 11.
Status: Patch available. GitLab has released fixed versions (19.1.8, 19.2.6, and 19.3.2). Update immediately — this is being actively scanned for in the wild.
ConnectWise ScreenConnect is remote-access software used by IT support teams to connect to and fix employees' computers. This near-perfect severity flaw lets an outside attacker misuse broken permission controls to do things only administrators should be able to do — potentially taking over the machines of everyone the IT team can reach. CISA has added this to its list of known exploited vulnerabilities, meaning real attackers are already using it.
Status: Patch available. If your IT support provider uses ScreenConnect, ask them to confirm they've updated.
JFrog Artifactory is a system that companies use to store and manage software packages — the building blocks developers use to create apps. This bug lets attackers exploit a flaw in how the software checks login tokens, potentially jumping from a regular user account to an administrator account. Researchers have seen this chained together with a second Artifactory bug to install a hidden Rust backdoor on unpatched servers.
Status: Patch available. JFrog has released fixes. Development and DevOps teams should prioritise this immediately.
Microsoft just dropped its biggest patch batch ever — 974 security fixes in a single update, smashing its previous record of 570 set just two months ago. Two of these bugs are being actively exploited right now: CVE-2026-81963 and CVE-2026-85880 both let an attacker quietly escalate privileges on a Windows machine. Microsoft says AI is helping it find more bugs faster — which explains the surge in patch volume. A note of caution: this month's Windows Server update is also breaking Remote Desktop Services for some users, so test before rolling out widely.
Status: Patches available via Windows Update. Install them — but IT teams should test on a small group first given the reported Remote Desktop issues.
Microsoft says it's now using AI to find security bugs in its own software faster than ever before. The result: September's Patch Tuesday hit 974 fixes — more than double the previous annual record, and we're still three months from year-end. On one hand, finding and fixing bugs faster is genuinely good. On the other, security teams at companies large and small are already struggling to test and deploy updates quickly enough. When the pace of patching outstrips the capacity to patch safely, organisations are forced to make difficult choices about which fixes to apply first — and that gap is exactly where attackers wait. This acceleration, driven by AI agents doing security research at machine speed, is likely the new normal.
Imagine handing your ID to a car rental agent at an airport counter. You get your keys, you drive away, and you forget it ever happened. Now imagine that same ID scan — front, back, infrared, ultraviolet — sitting in a searchable database on a Russian cybercrime forum, available to anyone willing to pay. That's the situation facing more than 153 million Americans and Canadians right now, after a dark web service called Nexus went live this week.
The data appears to come from a breach at a major identity verification company — the kind of business that sits invisibly behind the scenes when you rent a car, check into a hotel, or prove your age to access a service. Investigative journalist Brian Krebs confirmed his own license was in the database, with a timestamp matching a trip he took last year. He then asked a dozen friends to check — nine of them found their licenses, all timestamped to real events. The images aren't just flat photos either. They include infrared and ultraviolet scans, the kind used to verify document security features. This is highly detailed personally identifiable information, not just a name and email address.
For regular people, the risk is identity theft on a scale that's hard to overstate. A driver's license scan is enough to open bank accounts, apply for loans, pass verification checks, or impersonate someone to a government agency. With 153 million records and the count still climbing by hundreds of thousands per day, this breach affects roughly one in every two American adults. The FBI has opened an investigation, but the data is already out there.
Watch for two things in the coming weeks. First, whether the identity verification company at the centre of this gets named — FLHSMV, the Florida DMV, separately confirmed its own database was breached via a stolen police account, suggesting government databases are also in scope. Second, watch for a wave of targeted spear-phishing attacks using this data. Criminals who know your full name, date of birth, address, and what you look like can craft very convincing impersonation attempts. Be extra sceptical of any unexpected contact from banks, government agencies, or service providers over the next few months — even if they seem to know a lot about you.