← All issues
cybersecurityCyberBubbledata-breach

153 Million Driver's Licenses For Sale — Plus Record 966 Windows Patches

🌐  World Intel
China: Six AI Companies Stole Billions of Tokens From U.S. Models

U.S. cybersecurity and intelligence agencies say six Chinese AI companies ran industrial-scale distillation attacks on American frontier AI models — essentially reverse-engineering them by querying them at enormous volume. The operation has been running since at least late 2024 and extracted billions of tokens' worth of responses. CISA published a detailed advisory on the campaign on September 8.

↗ CISA Advisory AA26-251A
Dark Web: 153 Million U.S. & Canadian Driver's Licenses For Sale

A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, selling digital scans of over 153 million North American driver's licenses. Investigative reporter Brian Krebs traced the images to what appears to be an active breach at a major identity verification company used by Fortune 500 firms — with new records still being uploaded daily. The FBI's New Orleans field office has opened an investigation.

↗ Krebs on Security
Russia-Linked Actor Uses Hundreds of AI Agents to Hit 440+ PaperCut Servers

A suspected Russian-speaking attacker used AI to automatically generate and fire off exploits against PaperCut NG/MF print management software — and compromised more than 440 servers doing it. Security firms Blackpoint Cyber and GreyNoise both traced the activity to the same IP address. The attacker's end goal isn't confirmed yet, but the approach signals a new era of AI-assisted hacking at machine speed.

↗ The Hacker News
⚔️  Active Attacks
Gigabud Banking Trojan Hides Inside Android Work Profiles

The Gigabud banking trojan has a clever new trick. It installs a second app on your Android phone that creates a work profile — a separate, walled-off space Android normally uses for employer apps. Inside that profile, it drops a fake version of your real banking app. When your bank's security software scans for malware, it can't see across the wall into the work profile, so Gigabud stays hidden while quietly processing fraudulent payments. Confirmed infections have been found in Indonesia.

🛡 What to do: If you didn't set up a work profile yourself and one appears on your Android phone, treat it as a red flag. Go to Settings → Accounts (or Digital Wellbeing) to check. Only install banking apps from official sources and keep your phone's OS updated.
BlueMoon Exploit Kit Hit Windows and Chrome With Zero-Days

Multiple cyber-espionage groups used an exploit kit called BlueMoon to attack users through zero-day vulnerabilities in both Microsoft Windows and Google Chrome. Zero-days are the most dangerous kind of flaw because there's no patch when they're first used. The attacks have been attributed to espionage-motivated groups, meaning the targets were likely high-value individuals or organizations.

🛡 What to do: Update Chrome immediately — Google typically patches zero-days within days of disclosure. Also apply this month's Windows updates (see below), which fix two actively exploited flaws.
🔓  New Vulnerabilities
CVE-2026-20079 Cisco Secure Firewall Management Center CRITICAL 10.0

This is as bad as it gets — a perfect 10.0 score. An attacker with no username or password can reach Cisco's Secure Firewall Management Center over the internet, bypass the login screen entirely, and run scripts that give them full root control of the underlying system. Cisco has confirmed this flaw is already being actively exploited in real attacks right now.

Status: Patch available. CISA has ordered federal agencies to apply it by September 12, 2026. If you use Cisco FMC, patch immediately.

CVE-2026-85102 & CVE-2026-85103 Check Point Security Gateway & Management Server CRITICAL 9.8

Check Point disclosed two critical flaws in how its firewall products handle VPN certificates. The first flaw lets an attacker run code on the firewall without logging in, by exploiting faulty certificate trust checks. The second is a heap-based buffer overflow that can also lead to remote code execution. Check Point says it found both itself and has no evidence of exploitation yet — but with a 9.8 score, that window won't stay open long.

Status: Patches delivered by Check Point on September 9, 2026. Apply immediately if you run Check Point Security Gateways.

CVE-2026-19490 Citrix NetScaler ADC & NetScaler Gateway CRITICAL 9.3

Citrix's NetScaler products — used by thousands of organizations for remote access and VPN access — have an authentication bypass flaw when configured as a gateway or authentication server. An attacker can skip the login entirely and get in. CISA has added it to its Known Exploited Vulnerabilities list, which means it's being used in real attacks.

Status: Patch available. Federal agencies must apply it by September 12, 2026. All Citrix NetScaler customers should treat this as urgent.

CVE-2026-81963 & CVE-2026-85880 Microsoft Windows (Patch Tuesday — September 2026) CRITICAL

Microsoft's September 2026 Patch Tuesday is the single largest patch release in the company's history — 966 fixes in one drop, obliterating the previous record of 570 set just in July. Two of those fixes are for zero-days being actively exploited right now: both let an attacker who's already on your system gain full administrator-level control. In total, 113 bugs in this batch earned Microsoft's "Critical" rating, meaning attackers could take over a machine with no help from the user.

Status: Patches available now via Windows Update. Run updates today — both zero-days are confirmed active in the wild.

🛠  New Tech
Microsoft Defender "ShieldCrash" Zero-Day: Researcher Discloses SYSTEM-Level Flaw

A newly disclosed zero-day in Microsoft Defender — the built-in antivirus that ships with every copy of Windows — lets an attacker elevate their access to SYSTEM level, the most powerful account on a Windows machine. The flaw has been dubbed "ShieldCrash" by the researcher who found it. It's notable because Defender is the last line of defense for millions of home and business users, and a flaw in the very tool protecting you is especially tricky to guard against. Watch for a patch from Microsoft's out-of-band update channel — this one likely won't wait until next month's Patch Tuesday.

Google Play "Early Access" Abused to Push Fake Casino and Reward Apps

Bad actors found a loophole in Google Play's Early Access program — a feature meant to let developers gather feedback on apps before launch. Because Early Access apps can't receive public reviews or star ratings, scammers are flooding the program with fake casino games, phony reward apps, and apps that copy the names and branding of popular titles like Grand Theft Auto. One spotted fake, "Vice Streets: Open World," already has over a million installs. Google has not yet described what steps it's taking to close the loophole, making user vigilance especially important right now.

💡  Deep Dive
153 Million Driver's Licenses Are For Sale Online — And They Might Be Coming From the App That Checked Your ID

Imagine handing your driver's license to a bouncer, a car rental desk, or a boarding gate scanner — and finding out a year later that a photo of both sides of that license, along with an infrared and ultraviolet scan, is now for sale on a Russian cybercrime forum for a few dollars. That's the situation facing potentially 153 million Americans and Canadians right now.

The service, called Nexus, appeared this week on the forum Exploit. It's not just a static data dump — records are still being added at a rate of roughly 400,000 per day, which means whatever breach is feeding it is still open. Krebs on Security investigated by asking friends and family to let him look up their licenses. Nine out of nine matched. And here's the disturbing detail: the timestamps on the image files corresponded almost exactly to dates when those people had traveled — rented a car, boarded a flight, or checked into a hotel. That points squarely at identity verification companies — businesses that scan your ID on behalf of airlines, rental agencies, banks, and others to confirm you are who you say you are. One such company, based in Louisiana, appears to be the likely source, though it hasn't been publicly confirmed.

For regular people, this is the kind of breach that stings in slow motion. Your driver's license number, photo, and date of birth are enough to open lines of credit, file fraudulent tax returns, or pass identity checks at other services. Unlike a leaked password, you can't change your face or your license number overnight. The records also include some Common Access Cards — government ID used to enter secure federal buildings — which adds a national security dimension to an already serious story.

The FBI has opened an investigation. Watch for news about which identity verification company is at the center of this — and if you've rented a car, taken a flight, or used an ID verification service in the past year or two, consider placing a credit freeze with the three major credit bureaus. It's free, it takes about ten minutes, and it stops most new credit from being opened in your name without your direct involvement.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →