153 Million Driver's Licenses for Sale — Plus AI Tools Under Attack
Wednesday, September 2, 2026 · 5-minute read
A Chinese-speaking cybercrime group called Gambling Goblin has been quietly planting malicious code inside web servers run by Brazilian government agencies and universities since mid-2025. Visitors to those trusted sites are silently redirected to fake pages that mimic the Google Play and Microsoft stores — but push online gambling apps instead. The real goal appears to be SEO manipulation: by chaining together hundreds of high-reputation government domains, the attackers inflate search rankings for their gambling sites.
↗ The Hacker NewsA new identity theft service called Nexus appeared on a Russian cybercrime forum this week, offering scans of over 153 million US and Canadian driver's licenses — complete with front, back, infrared, and ultraviolet photos. Investigative journalist Brian Krebs traced the timestamps on stolen records and found they consistently match dates when people rented cars from Hertz, pointing to a likely breach at a major identity verification company. The FBI's New Orleans field office has opened a formal investigation.
↗ Krebs on SecurityLaw enforcement agencies and private security firms from multiple countries have seized the infrastructure behind the long-running Sality botnet. Sality has been active for years, spreading through infected files and using peer-to-peer connections to stay alive even when some servers are taken down. The coordinated seizure is designed to permanently cut off the criminal operators' ability to control infected machines.
↗ BleepingComputerAttackers pulled off a sophisticated supply chain attack against Virtualizor, a popular tool used by web hosting companies to manage virtual servers. They used a technique called BGP hijacking to intercept Virtualizor's software update traffic between August 28 and August 30. Anyone who updated Virtualizor during that window may have installed a malicious version that gives attackers root-level — meaning total — control of the server. One hosting company confirmed five of its 34 servers were fully compromised. Virtualizor has released a scanner tool (Patch 9) so operators can check if they were hit, but the company still doesn't have a complete list of affected installations.
A new Android banking trojan called StreamRat was advertised to Spanish-speaking users through paid Meta ads that promised free TV streaming. The ads reached an estimated 570,000 accounts in the EU. When victims downloaded the fake app — a process called sideloading — it asked for a chain of sensitive system permissions completely unrelated to watching TV. Once granted, attackers could take near-total control of the device, including accessing banking apps.
Langflow is an open-source tool that developers use to build AI-powered applications. A critical flaw allows anyone on the internet — no login required — to run their own code on a Langflow server. Attackers are already exploiting this in the wild to steal API keys for services like OpenAI and Amazon Web Services. Once stolen, those keys can rack up huge bills or be used to abuse those services.
Status: Being actively exploited. Update Langflow immediately if you run it.
SonicWall has warned that hackers are actively chaining two new zero-day flaws in its SMA1000 remote access appliances. SMA1000 devices are used by companies to let employees securely connect to corporate networks from home. By combining both bugs, attackers can run their own code on the device — potentially getting inside a company's entire network. SonicWall confirmed active exploitation is underway.
Status: No complete patch yet. SonicWall is urging customers to apply all available mitigations immediately and monitor for suspicious activity.
Nearly 22,000 Microsoft Exchange email servers exposed to the internet are still unpatched against a known authentication bypass vulnerability. An attacker who exploits it can take over every mailbox on the server — reading, deleting, or sending emails as any user in the organization. The patch has been available for some time, but tens of thousands of servers haven't applied it.
Status: Patch available. If your organization runs Exchange on-premises, check with your IT team today.
Google's upcoming Android 17 will support a new privacy feature called Encrypted Client Hello (ECH). Right now, even when you visit an HTTPS website, the very first part of the connection — where your device announces which site it wants to reach — is sent in plain text. That means your internet provider (or anyone on the same network) can see every site you visit, even if the content itself is encrypted. ECH fixes that by encrypting that initial handshake too. Android 17 will be the first major mobile OS to enable this by default across all apps using its built-in network stack, closing one of the last easy ways to track your browsing at the network level.
Imagine handing your driver's license to a hotel clerk, a car rental agent, or an airport security officer — and that scan ending up for sale on a Russian cybercrime forum less than a year later. That's exactly what appears to be happening to millions of Americans and Canadians right now, according to a bombshell investigation published this week by Brian Krebs.
A service called Nexus launched on the criminal forum Exploit this week, advertising over 153 million driver's license scans. Each record includes multiple high-resolution photos of the license — standard, infrared, and ultraviolet — the kind of multi-image capture that professional identity verification equipment produces. Krebs verified the service by searching for his own license and those of friends and family. Every person whose license appeared in the database confirmed they had recently rented a car, and the timestamps matched their rental dates almost exactly. Multiple people identified the rental company as Hertz. That points strongly toward a breach at a company that handles identity verification on behalf of car rental firms and other businesses — not a government agency or airline. The data appears to still be flowing in: the record count grew by nearly 400,000 in a single 24-hour period, suggesting an active, ongoing breach rather than a one-time theft.
For regular people, this is unsettling because a driver's license scan is more valuable than most stolen data. It's a high-quality photo ID that criminals can use to open bank accounts, take out loans, apply for credit cards, or bypass identity checks at financial institutions — all in your name. Unlike a stolen password, you can't change your face or your license number easily. The FBI has opened an investigation out of its New Orleans field office, which suggests investigators may already have a lead on the identity verification company at the center of this.
Watch for news about which identity verification company is named in the FBI investigation — that will tell you whether your license is likely in this database. In the meantime, consider placing a credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion). It's free, it takes about ten minutes, and it's the single most effective thing you can do to stop someone from opening fraudulent accounts with your identity.