153M Licenses for Sale, Record Patch Tuesday & AI Assistants Under Attack
Wednesday, September 16, 2026 · 5-minute read
A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, selling digital scans of over 153 million driver's licenses from Americans and Canadians. Investigative reporter Brian Krebs confirmed the breach by checking his own license — and found it listed with a timestamp matching a real trip he took in 2025. The images appear to be coming from an ongoing breach at a major identity verification company whose clients include multiple Fortune 500 businesses. Disturbingly, new records are still being added — nearly 400,000 in a single 24-hour window — suggesting the data is still being actively stolen.
↗ Krebs on SecurityMicrosoft's September Patch Tuesday shattered records: 974 security holes patched in a single update, more than doubling the previous record set just two months ago in July. Two of those flaws are actively being exploited right now — both let an attacker quietly gain higher control over a Windows machine. Microsoft says AI is helping its engineers find bugs faster, but security experts are worried that most organizations simply can't keep up with patching this many issues each month.
↗ Krebs on SecurityA phishing kit called N0va is actively targeting organizations across North America and Europe, including government agencies, healthcare providers, and tech companies. It impersonates trusted services and tricks people into logging in through what look like legitimate authentication flows. Once someone falls for it, the attackers get access to a real account — no obvious malware needed — which can open the door to sensitive data and broader systems.
↗ The Hacker NewsSecurity firm Mandiant reported that an attacker took over an active AI coding assistant session at an unnamed software company. The attacker used the hijacked session to get the AI to recommend a poisoned software package — and when a developer accepted it, the attacker slipped in a program that steals passwords and tokens. From there, a self-spreading worm called Shai-Hulud tore through roughly 100 internal code repositories, stealing source code and login secrets. The attacker also poisoned a public software package on PyPI, meaning other companies could have been hit too.
Hackers took over the official HBO Max Reddit account and used it to run ClickFix-style ads that pushed malware to visitors. Because the account was verified and well-known, readers were far more likely to trust the posts. This is a growing tactic: attackers hijack trusted, high-follower social accounts so their malicious links look completely legitimate.
Both flaws let an attacker who already has basic access to a Windows PC quietly upgrade themselves to administrator level — no extra tricks needed. Microsoft confirmed both are being actively exploited in the wild right now, meaning real attackers are already using them. They were patched in this month's record-breaking Patch Tuesday update.
Status: Patch available — install the September 2026 Windows update immediately.
A logic error in the cellular modem of Google Pixel phones lets an attacker nearby — think same Wi-Fi network or cellular range — gain elevated control over the device without the owner doing anything. Google confirmed it has seen signs of limited, targeted attacks using this flaw already. The fix is in Google's September 2026 security patch, which addresses 110 vulnerabilities in total.
Status: Patch available — update your Pixel phone to the September 2026 security patch now.
Parallels Desktop — the popular app that lets Mac users run Windows inside a window — has a flaw that lets any normal user account on the Mac silently escalate to root access. The catch: the attack requires code already running locally, so a remote stranger can't exploit it over the internet. The fix exists in Parallels Desktop 27, but Intel-based Macs cannot install that version, leaving a large chunk of users without a patch.
Status: Patch available for Apple Silicon Macs (Parallels Desktop 27). Intel Mac users have no patch yet — consider limiting who has local access to your machine.
Researchers at Forever Security built a proof-of-concept browser extension that can take control of the AI assistants built into Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and the Claude browser extension — all with a single click. On some products, the rogue extension could drive the AI to act on the attacker's behalf: opening files, switching on the camera and microphone, or browsing the web as you. This isn't an attack seen in the wild — it's a research demonstration — but it exposes a structural problem: all five products share the same underlying browser architecture, so a flaw that works on one tends to work on all. The researchers published their findings to push browser makers and AI developers to build stronger walls between extensions and AI agents.
Imagine a database containing the front and back of your driver's license — plus infrared and ultraviolet scans of it — timestamped to the exact day you last handed it to a stranger. That's what the Nexus identity theft service is selling, and it already has over 153 million records. Your information may be in there without you ever knowing.
The source of the breach appears to be an identity verification company — one of the businesses that many apps and services hire to confirm you're who you say you are. When you photograph your license to rent a car, open a bank account, or board a flight, that image often goes to a third-party verifier. According to the people behind Nexus, they have been quietly draining one such company's database for over a year. Brian Krebs at KrebsOnSecurity confirmed the breach is real by checking his own license and those of friends — each person's timestamp matched a real-world event where they showed their ID. The FBI has opened an investigation.
For regular people, this is more alarming than a typical password breach. A stolen password can be changed. A driver's license — your face, your address, your date of birth, your license number — cannot. With that information, criminals can open credit accounts, commit tax fraud, or impersonate you to pass identity checks at other companies. Some records even include government Common Access Cards, marijuana dispensary cards, and commercial driver's licenses, suggesting the breadth of industries using this compromised verifier is enormous.
Until the source company is publicly named, there's no definitive way to know if your license is in the set. Watch for unusual credit inquiries, new accounts you didn't open, or letters from the IRS about income you didn't earn. Consider placing a free credit freeze with the three major credit bureaus if you haven't already. The FBI investigation is ongoing — this story isn't done yet.