← All issues
cybersecurityCyberBubbleidentity-theft

153 Million Licenses, 966 Patches, and AI Accounts Getting Hijacked

🌐  World Intel
USA vs. China: Your AI Assistant Is Being Reverse-Engineered at Industrial Scale

The NSA, CISA, and FBI released a joint advisory accusing Chinese AI companies of systematically copying the capabilities of American AI models — tools like Claude, GPT, Gemini, and Grok — through a technique called distillation. The agencies say this isn't occasional research borrowing — it's the core of China's AI development strategy, done at massive scale. This matters to regular people because the AI tools you pay for may be funding an arms race that's already being undercut abroad.

↗ The Hacker News / CISA Advisory AA26-251A
153 Million Driver's Licenses on Sale — Stolen From an ID Verification Company

A new dark web service called "Nexus" is selling digital scans of over 153 million U.S. and Canadian driver's licenses, apparently siphoned from a major identity verification company based in Louisiana. Journalist Brian Krebs confirmed his own license was in the database, timestamped to a trip he took in June 2025. The FBI has opened an investigation, and the stolen data appears to still be actively growing — nearly 400,000 new records appeared in just 24 hours.

↗ Krebs on Security
Florida DMV Database Breached — 200,000+ Driver Records Stolen

The hacking group ShinyHunters claims it broke into "DAVID," an online platform used by the Florida Department of Motor Vehicles, and lifted more than 200,000 records on state drivers. ShinyHunters is the same crew behind several massive breaches in recent years. If confirmed, this is another blow to anyone who has interacted with Florida's DMV — names, addresses, and license details could all be exposed.

↗ BleepingComputer
⚔️  Active Attacks
Criminals Are Hijacking Your AI Accounts — Even If You Have MFA Turned On

Hackers are using a type of malware called an infostealer to grab session tokens and API keys from infected computers. Once they have these, they can log straight into your AI accounts — on services like Google AI or Anthropic's Claude — without needing your password or your MFA code. The stolen keys are then bought and sold on criminal forums. Security experts at Okta confirmed that replaying these tokens bypasses login checks entirely — the service just thinks it's you.

🛡 What to do: Log out of your AI service accounts on any device you don't actively use, and revoke unused API keys from your account settings — this forces new logins and kills any stolen tokens criminals might be holding.
119,000 Fake Online Shops Are Stealing Your Payment Card Details Right Now

A fraud operation called "DoppelCart" is running more than 119,000 fake e-commerce websites designed to look like real stores. When you enter your card details to "buy" something, they're captured and sold. The scale is staggering — this isn't a handful of scam sites, it's an automated factory of fake shops. If a deal online looks unusually good and the site feels slightly off, trust that instinct.

🛡 What to do: Before entering card details on an unfamiliar site, search the store name plus "scam" or "reviews" — and consider using a virtual card number (offered by many banks) that limits exposure if the site turns out to be fake.
🔓  New Vulnerabilities
CVE-2026-82533 DeepSeek Harness (AI Coding Agent Tool) CRITICAL 9.4

DeepSeek's tool for running AI coding agents had a flaw that let the AI effectively unlock its own cage. The tool is supposed to keep AI agents contained in a sandbox so they can't touch files outside their workspace. But a single command — triggered by malicious text the agent read — could disable that sandbox entirely, giving the agent free run of the machine. No approval prompt. No warning. Researchers rated this nearly the worst possible severity.

Status: Patched. DeepSeek fixed this on August 27. If you use DeepSeek Harness, make sure you've updated since then.

CVE-2026-81963 & CVE-2026-85880 Microsoft Windows (Zero-Days) CRITICAL — Actively Exploited

Two zero-day flaws in Windows are being actively used by attackers right now. Both allow an attacker who already has limited access to a Windows machine to quietly upgrade themselves to full administrator control — a move called privilege escalation. These arrived as part of this month's Patch Tuesday, which fixed a record-breaking 966 flaws total — more than Microsoft has ever released in a single month.

Status: Patched. Install the September 2026 Windows updates immediately — these two are being exploited in the wild right now.

Alby Hub (no CVE published yet) Alby Hub — Bitcoin Lightning Wallet CRITICAL — Wallet Takeover

If you run your own Lightning wallet using Alby Hub and you made it accessible from the internet, there was a flaw that could let an attacker take it over and send all your bitcoin elsewhere. Versions before v1.19.0 — anything released before August 2025 — are vulnerable. At least one user has already been affected. Alby is holding back the technical details for now, which is standard practice to give people time to patch.

Status: Patched. Update to Alby Hub v1.24.0 immediately. As a first step, disable any external internet access to your Hub's management interface.

ShieldCrash (no CVE yet) Microsoft Defender — "ShieldCrash" Zero-Day CRITICAL — SYSTEM Access

Just hours after Microsoft's September patch updates dropped, an anonymous researcher published a working exploit called "ShieldCrash" targeting Microsoft Defender — the built-in antivirus on Windows. It grants full SYSTEM-level control of the machine, meaning an attacker gets the highest possible permissions. The timing is particularly bad: this landed the same day as a massive patch release, when IT teams are already scrambling.

Status: No patch yet as of publication. Watch for an out-of-band Microsoft update and apply it as soon as it arrives.

🛠  New Tech
Microsoft Adds Age-Awareness to Windows 11 — Without Sharing Your Birthdate

Microsoft is rolling out new APIs in Windows 11 that let apps find out whether a user is a child, teenager, or adult — without ever seeing their actual date of birth. The idea is that apps can apply age-appropriate settings or content filters without collecting sensitive personal information. It's a rare example of a privacy-preserving design choice: the app gets the answer it needs (child vs. adult) but not the underlying data. This could matter for gaming platforms, social apps, and parental control tools built on Windows.

💡  Deep Dive
153 Million Driver's Licenses for Sale: How a Breach at One Company Exposed Half of America

Imagine handing your driver's license to a bouncer at a bar — and later finding out that bouncer had been secretly photographing every ID that came through for over a year, selling the images to strangers on the internet. That's essentially what appears to have happened with a major identity verification company, and the consequences are enormous.

Investigative journalist Brian Krebs first spotted "Nexus," a new service on Russian cybercrime forums, advertising scans of driver's licenses for more than 153 million Americans and Canadians. When Krebs searched for his own license, he found it — complete with front and back scans and a timestamp that matched a trip he took in June 2025. He then asked over a dozen friends and family members to check. Nine of them found their licenses in the database. Every single one confirmed that the timestamp matched a real trip or event in their lives. The data isn't old or vague — it's precise, recent, and still growing. Nearly 400,000 new records appeared in just one day while Krebs was investigating.

The records appear to come from a identity verification company based in Louisiana whose clients include major Fortune 500 companies. These are the services that ask you to hold up your license on camera when you're opening a bank account, renting a car, or boarding a flight. The breach isn't just historic in size — it's active. The hackers claim they've been quietly pulling data for over a year, and new records keep appearing. Some files even include infrared and ultraviolet scans of licenses, the kind used by sophisticated ID-checking systems. For regular people, this means your license image — the document you use to prove you are who you say you are — may already be in criminal hands. That creates real risk: identity theft, fraudulent account openings, and impersonation attacks that are much harder to pull off with just a name and address, but trivial with a high-resolution license scan.

The FBI has opened an investigation through its New Orleans field office. The identity verification company hasn't been named publicly yet — Krebs is still investigating. Watch for updates on which company is at the center of this, and whether the companies that used their service (and therefore exposed your data) are required to notify you. In the meantime: check whether your state offers a free credit freeze, which makes it much harder for anyone to open new accounts in your name even if they have your ID.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →