← All issues
cybersecurityCyberBubbledata-breach

153 Million Driver's Licenses for Sale — Plus Microsoft's Biggest Patch Day Ever

🌐  World Intel
Japan: Government VPN flaw exposed 246,000 employee records

Japan's Digital Agency confirmed a data breach tied to a vulnerability in a VPN system used by government staff. Around 246,000 rows of personal information belonging to government employees may have been exposed. The agency is still investigating the full scope of the incident.

↗ BleepingComputer
USA: Black Axe cybercrime leaders extradited to face wire fraud charges

Five alleged leaders of the Black Axe cybercrime syndicate have been extradited to the United States. The group is accused of running global financial fraud schemes involving wire fraud and money laundering. If convicted, they face serious federal prison time.

↗ BleepingComputer
USA: Microsoft's biggest-ever Patch Tuesday drops 974 fixes

Microsoft released patches for a staggering 974 security vulnerabilities today — by far its largest single update in company history, blowing past July's previous record of 570. Two of those bugs are zero-days being actively exploited right now, both allowing attackers to gain elevated control over Windows machines. Security experts are sounding the alarm: the sheer volume of patches is making it harder for IT teams to keep up.

↗ Krebs on Security
⚔️  Active Attacks
Ransomware gangs now exploiting critical VMware vCenter flaw

CISA is warning that ransomware groups have joined active attacks against a critical flaw in VMware vCenter — software that many companies use to manage large numbers of servers from one place. The vulnerability was patched back in July, but organizations that haven't updated yet are now being hit by multiple criminal groups. If attackers get in, they can take full control of an organization's server infrastructure, which is a fast path to a crippling ransomware attack.

🛡 What to do: If your organization uses VMware vCenter, check with your IT team today to confirm the July patch has been applied. This one is being actively weaponized and waiting is not an option.
HBO Max's Reddit account hijacked to spread ClickFix malware

Hackers broke into HBO Max's official Reddit account and used it to run fake ads pushing a scheme called ClickFix. The ads directed users to a page that asked them to paste a command into their computer to "fix" a problem — but running that command actually installed information-stealing malware on Windows and macOS devices. Because the ads came from a verified, well-known brand account, many people had no reason to be suspicious.

🛡 What to do: Never paste commands into your computer at a website's request, even if the source looks official. No legitimate service will ever ask you to do this to fix a problem.
🔓  New Vulnerabilities
CVE-2026-39364 Vite Development Server HIGH 8.2

Vite is a popular tool developers use to build websites. This flaw lets an outsider bypass the file restrictions Vite is supposed to enforce, and grab sensitive files — like cloud credentials stored in .env files — just by tweaking the URL in a web request. Attackers have already been running automated scans across the internet looking for exposed Vite servers to steal AWS and Azure cloud credentials from.

Status: Patch available. Update Vite immediately and avoid exposing dev servers to the public internet.

CVE-2026-81963 & CVE-2026-85880 Microsoft Windows CRITICAL — Actively Exploited

Both of these flaws let an attacker who already has basic access to a Windows machine quietly upgrade their own permissions to administrator level — a move called privilege escalation. That makes it far easier to install malware, steal data, or lock down the whole machine. Microsoft confirmed both are being actively exploited in the wild right now.

Status: Patches released today as part of September's Patch Tuesday. Apply Windows updates as soon as possible.

No CVE assigned yet LiteSpeed Web Server Enterprise (before 6.3.7) CRITICAL

On a shared hosting server, dozens or hundreds of different websites coexist on one machine. This flaw in LiteSpeed Web Server Enterprise lets a single low-privilege customer account break out of its sandbox and gain root-level control of the entire server — meaning one bad tenant could access every other website on the machine. The hosting control panel company cPanel flagged this as urgent.

Status: Fixed in LiteSpeed Enterprise version 6.3.7, released September 11. Hosting administrators should update immediately.

🛠  New Tech
Homebrew 7.0.0 — the Mac package manager gets a security glow-up

Homebrew, the beloved free tool that Mac users use to install developer software, dropped version 7.0.0 today with a batch of meaningful security upgrades. It now ships with a built-in vulnerability scanner that checks your installed packages for known security flaws — something you previously needed a separate tool for. The update also brings stronger controls over what software can be installed and officially launches BrewUI, a graphical point-and-click interface so you no longer have to use the command line at all. For non-technical Mac users who've inherited a Homebrew setup, this is a big quality-of-life improvement that also happens to make things safer.

↗ BleepingComputer
💡  Deep Dive
153 Million Driver's Licenses Are for Sale on the Dark Web — And They're Coming From a Live Breach

Imagine your driver's license — front and back, in full color, with an infrared scan and a timestamp — sitting in a searchable database that anyone with cryptocurrency can browse. That's what a new service called Nexus, discovered this week on Russian cybercrime forums, is offering. And it has over 153 million records.

Security journalist Brian Krebs broke the story after a source tipped him off to the service. To verify it, Krebs searched for himself and over a dozen friends and family members. Nine of them were in the database. Every single one confirmed they had traveled on or very near the date stamped on their license image. The timestamps pointed to a pattern: the data appears to be coming from a company that scans ID documents as part of identity verification — think car rentals, airport check-ins, or age verification. The working theory is that a Louisiana-based identity verification company has been silently breached for over a year, with fresh records still being uploaded to Nexus as recently as this week. The FBI's New Orleans field office has opened a formal investigation.

This matters for ordinary people in a big way. A driver's license scan contains almost everything a criminal needs to open accounts, take out loans, or pass identity checks in your name. The records reportedly include not just everyday citizens but also high-ranking US government officials, including Defense Secretary Pete Hegseth. Some entries even include Common Access Cards used to enter secure government buildings. The scale — 153 million and actively growing — puts this among the largest identity document breaches ever recorded.

The unsettling part is that you may have no idea whether your license is in there, and there's nothing you can do to take it back. Watch for signs of identity theft — unexpected credit inquiries, new accounts you didn't open, or strange mail. Consider placing a free credit freeze with the three major bureaus (Equifax, Experian, TransUnion) to block anyone from opening new credit in your name. The FBI investigation is ongoing, and the source company has not yet been publicly named.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →