153 Million Driver's Licenses for Sale — Plus Microsoft's Biggest Patch Day Ever
Tuesday, September 15, 2026 · 5-minute read
Japan's Digital Agency confirmed a data breach tied to a vulnerability in a VPN system used by government staff. Around 246,000 rows of personal information belonging to government employees may have been exposed. The agency is still investigating the full scope of the incident.
↗ BleepingComputerFive alleged leaders of the Black Axe cybercrime syndicate have been extradited to the United States. The group is accused of running global financial fraud schemes involving wire fraud and money laundering. If convicted, they face serious federal prison time.
↗ BleepingComputerMicrosoft released patches for a staggering 974 security vulnerabilities today — by far its largest single update in company history, blowing past July's previous record of 570. Two of those bugs are zero-days being actively exploited right now, both allowing attackers to gain elevated control over Windows machines. Security experts are sounding the alarm: the sheer volume of patches is making it harder for IT teams to keep up.
↗ Krebs on SecurityCISA is warning that ransomware groups have joined active attacks against a critical flaw in VMware vCenter — software that many companies use to manage large numbers of servers from one place. The vulnerability was patched back in July, but organizations that haven't updated yet are now being hit by multiple criminal groups. If attackers get in, they can take full control of an organization's server infrastructure, which is a fast path to a crippling ransomware attack.
Hackers broke into HBO Max's official Reddit account and used it to run fake ads pushing a scheme called ClickFix. The ads directed users to a page that asked them to paste a command into their computer to "fix" a problem — but running that command actually installed information-stealing malware on Windows and macOS devices. Because the ads came from a verified, well-known brand account, many people had no reason to be suspicious.
Vite is a popular tool developers use to build websites. This flaw lets an outsider bypass the file restrictions Vite is supposed to enforce, and grab sensitive files — like cloud credentials stored in .env files — just by tweaking the URL in a web request. Attackers have already been running automated scans across the internet looking for exposed Vite servers to steal AWS and Azure cloud credentials from.
Status: Patch available. Update Vite immediately and avoid exposing dev servers to the public internet.
Both of these flaws let an attacker who already has basic access to a Windows machine quietly upgrade their own permissions to administrator level — a move called privilege escalation. That makes it far easier to install malware, steal data, or lock down the whole machine. Microsoft confirmed both are being actively exploited in the wild right now.
Status: Patches released today as part of September's Patch Tuesday. Apply Windows updates as soon as possible.
On a shared hosting server, dozens or hundreds of different websites coexist on one machine. This flaw in LiteSpeed Web Server Enterprise lets a single low-privilege customer account break out of its sandbox and gain root-level control of the entire server — meaning one bad tenant could access every other website on the machine. The hosting control panel company cPanel flagged this as urgent.
Status: Fixed in LiteSpeed Enterprise version 6.3.7, released September 11. Hosting administrators should update immediately.
Homebrew, the beloved free tool that Mac users use to install developer software, dropped version 7.0.0 today with a batch of meaningful security upgrades. It now ships with a built-in vulnerability scanner that checks your installed packages for known security flaws — something you previously needed a separate tool for. The update also brings stronger controls over what software can be installed and officially launches BrewUI, a graphical point-and-click interface so you no longer have to use the command line at all. For non-technical Mac users who've inherited a Homebrew setup, this is a big quality-of-life improvement that also happens to make things safer.
↗ BleepingComputerImagine your driver's license — front and back, in full color, with an infrared scan and a timestamp — sitting in a searchable database that anyone with cryptocurrency can browse. That's what a new service called Nexus, discovered this week on Russian cybercrime forums, is offering. And it has over 153 million records.
Security journalist Brian Krebs broke the story after a source tipped him off to the service. To verify it, Krebs searched for himself and over a dozen friends and family members. Nine of them were in the database. Every single one confirmed they had traveled on or very near the date stamped on their license image. The timestamps pointed to a pattern: the data appears to be coming from a company that scans ID documents as part of identity verification — think car rentals, airport check-ins, or age verification. The working theory is that a Louisiana-based identity verification company has been silently breached for over a year, with fresh records still being uploaded to Nexus as recently as this week. The FBI's New Orleans field office has opened a formal investigation.
This matters for ordinary people in a big way. A driver's license scan contains almost everything a criminal needs to open accounts, take out loans, or pass identity checks in your name. The records reportedly include not just everyday citizens but also high-ranking US government officials, including Defense Secretary Pete Hegseth. Some entries even include Common Access Cards used to enter secure government buildings. The scale — 153 million and actively growing — puts this among the largest identity document breaches ever recorded.
The unsettling part is that you may have no idea whether your license is in there, and there's nothing you can do to take it back. Watch for signs of identity theft — unexpected credit inquiries, new accounts you didn't open, or strange mail. Consider placing a free credit freeze with the three major bureaus (Equifax, Experian, TransUnion) to block anyone from opening new credit in your name. The FBI investigation is ongoing, and the source company has not yet been publicly named.