← All issues
cybersecurityCyberBubbleidentity-theft

153 Million Driver's Licenses for Sale, Passkey Phishing Hits Microsoft 365

🌐  World Intel
China: AI Companies Running Industrial-Scale Data Theft Against U.S. AI Firms

CISA published a formal advisory warning that China-based AI companies are running coordinated campaigns to steal data and models from American AI companies at industrial scale. The technique, called distillation, lets attackers clone expensive AI systems cheaply. This is the government putting a name to something the industry has suspected for months.

↗ CISA Advisory AA26-251A
Netherlands: Critical Check Point VPN Flaws Under Imminent Threat

The Dutch national cybersecurity agency is sounding the alarm about two critical bugs in Check Point's VPN products, tracked as CVE-2026-85102 and CVE-2026-85103. Hackers haven't hit them widely yet, but the agency says exploitation is imminent. If your organisation uses Check Point VPN, patch now — don't wait for the weekend to be over.

↗ BleepingComputer
USA: 153 Million Driver's License Scans Sold on the Dark Web

A new dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian driver's licenses, and the FBI has opened an investigation. The images appear to come from a breach at an identity verification company used by car rental firms and other businesses — meaning the photos were captured when people showed their IDs at the counter. Journalist Brian Krebs confirmed his own license was in the database, timestamped to a trip he made last year.

↗ Krebs on Security
⚔️  Active Attacks
Passkey Phishing: Criminals Tricking Workers Into Handing Over Microsoft 365 Accounts

Gangs including ShinyHunters are sending fake login pages that look like Microsoft's new passkey and single sign-on prompts. Employees click the link, type in their credentials or approve the fake prompt, and the attackers immediately walk into their Microsoft 365 account and start pulling out data. These attacks are also pairing with AI-generated emails pretending to be the company's CEO, asking the finance team to approve wire transfers worth thousands of dollars — a classic business email compromise play, now supercharged with AI.

🛡 What to do: Always verify any urgent financial request from a "CEO" via a phone call to a known number — never reply to the email itself. For IT teams, enable Microsoft's Conditional Access policies to flag logins from unexpected locations.
China-Linked Hackers Exploit Tencent App to Drop GrayRabbit Backdoor

Attackers connected to a Chinese espionage group are using a critical bug (CVE-2026-51990) in Tencent's Sogou Input Method — a popular Chinese-language keyboard app for Windows — to install a piece of malware called GrayRabbit. A backdoor like GrayRabbit lets criminals return to a compromised machine whenever they like, without needing to break in again. If anyone in your organisation uses Sogou Input Method, update it immediately.

🛡 What to do: Update Sogou Input Method to the latest version right away. If you don't need it, uninstall it — reducing the number of apps on a machine reduces the number of ways attackers can get in.
🔓  New Vulnerabilities
CVE-2026-85706 GitLab (CE & EE) CRITICAL 10.0

This is the worst possible severity score: a perfect 10. The bug is a path traversal flaw in GitLab's code repository API. An attacker who isn't even logged in can read any file stored on a GitLab server — think private code, configuration files, passwords, and API keys. Security researchers spotted active probing of this vulnerability within hours of it being made public on September 11.

Status: Patch available. GitLab has released fixed versions (19.1.8, 19.2.6, and 19.3.2). Update immediately — this is being actively scanned for in the wild.

CVE-2026-84869 ConnectWise ScreenConnect CRITICAL 9.9

ConnectWise ScreenConnect is remote-access software used by IT support teams to connect to and fix employees' computers. This near-perfect severity flaw lets an outside attacker misuse broken permission controls to do things only administrators should be able to do — potentially taking over the machines of everyone the IT team can reach. CISA has added this to its list of known exploited vulnerabilities, meaning real attackers are already using it.

Status: Patch available. If your IT support provider uses ScreenConnect, ask them to confirm they've updated.

CVE-2026-42016 JFrog Artifactory HIGH 8.1

JFrog Artifactory is a system that companies use to store and manage software packages — the building blocks developers use to create apps. This bug lets attackers exploit a flaw in how the software checks login tokens, potentially jumping from a regular user account to an administrator account. Researchers have seen this chained together with a second Artifactory bug to install a hidden Rust backdoor on unpatched servers.

Status: Patch available. JFrog has released fixes. Development and DevOps teams should prioritise this immediately.

Multiple CVEs Microsoft Windows (Patch Tuesday — September 2026) CRITICAL — 974 fixes

Microsoft just dropped its biggest patch batch ever — 974 security fixes in a single update, smashing its previous record of 570 set just two months ago. Two of these bugs are being actively exploited right now: CVE-2026-81963 and CVE-2026-85880 both let an attacker quietly escalate privileges on a Windows machine. Microsoft says AI is helping it find more bugs faster — which explains the surge in patch volume. A note of caution: this month's Windows Server update is also breaking Remote Desktop Services for some users, so test before rolling out widely.

Status: Patches available via Windows Update. Install them — but IT teams should test on a small group first given the reported Remote Desktop issues.

🛠  New Tech
AI-Powered Vulnerability Discovery Is Reshaping Patch Tuesday — For Better and Worse

Microsoft says it's now using AI to find security bugs in its own software faster than ever before. The result: September's Patch Tuesday hit 974 fixes — more than double the previous annual record, and we're still three months from year-end. On one hand, finding and fixing bugs faster is genuinely good. On the other, security teams at companies large and small are already struggling to test and deploy updates quickly enough. When the pace of patching outstrips the capacity to patch safely, organisations are forced to make difficult choices about which fixes to apply first — and that gap is exactly where attackers wait. This acceleration, driven by AI agents doing security research at machine speed, is likely the new normal.

💡  Deep Dive
Your Driver's License Is Probably for Sale Online — Here's How 153 Million Got There

Imagine handing your ID to a car rental agent at an airport counter. You get your keys, you drive away, and you forget it ever happened. Now imagine that same ID scan — front, back, infrared, ultraviolet — sitting in a searchable database on a Russian cybercrime forum, available to anyone willing to pay. That's the situation facing more than 153 million Americans and Canadians right now, after a dark web service called Nexus went live this week.

The data appears to come from a breach at a major identity verification company — the kind of business that sits invisibly behind the scenes when you rent a car, check into a hotel, or prove your age to access a service. Investigative journalist Brian Krebs confirmed his own license was in the database, with a timestamp matching a trip he took last year. He then asked a dozen friends to check — nine of them found their licenses, all timestamped to real events. The images aren't just flat photos either. They include infrared and ultraviolet scans, the kind used to verify document security features. This is highly detailed personally identifiable information, not just a name and email address.

For regular people, the risk is identity theft on a scale that's hard to overstate. A driver's license scan is enough to open bank accounts, apply for loans, pass verification checks, or impersonate someone to a government agency. With 153 million records and the count still climbing by hundreds of thousands per day, this breach affects roughly one in every two American adults. The FBI has opened an investigation, but the data is already out there.

Watch for two things in the coming weeks. First, whether the identity verification company at the centre of this gets named — FLHSMV, the Florida DMV, separately confirmed its own database was breached via a stolen police account, suggesting government databases are also in scope. Second, watch for a wave of targeted spear-phishing attacks using this data. Criminals who know your full name, date of birth, address, and what you look like can craft very convincing impersonation attempts. Be extra sceptical of any unexpected contact from banks, government agencies, or service providers over the next few months — even if they seem to know a lot about you.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →