← All issues
cybersecurityCyberBubbleidentity-theft

153M Licenses for Sale, Record Patch Tuesday & AI Assistants Under Attack

🌐  World Intel
USA: 153 Million Driver's License Scans Are Now for Sale on the Dark Web

A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, selling digital scans of over 153 million driver's licenses from Americans and Canadians. Investigative reporter Brian Krebs confirmed the breach by checking his own license — and found it listed with a timestamp matching a real trip he took in 2025. The images appear to be coming from an ongoing breach at a major identity verification company whose clients include multiple Fortune 500 businesses. Disturbingly, new records are still being added — nearly 400,000 in a single 24-hour window — suggesting the data is still being actively stolen.

↗ Krebs on Security
Global: Microsoft Issues Its Biggest Patch Day Ever — 974 Fixes in One Go

Microsoft's September Patch Tuesday shattered records: 974 security holes patched in a single update, more than doubling the previous record set just two months ago in July. Two of those flaws are actively being exploited right now — both let an attacker quietly gain higher control over a Windows machine. Microsoft says AI is helping its engineers find bugs faster, but security experts are worried that most organizations simply can't keep up with patching this many issues each month.

↗ Krebs on Security
North America & Europe: N0va Phishing Campaign Hits Government, Healthcare, and Tech

A phishing kit called N0va is actively targeting organizations across North America and Europe, including government agencies, healthcare providers, and tech companies. It impersonates trusted services and tricks people into logging in through what look like legitimate authentication flows. Once someone falls for it, the attackers get access to a real account — no obvious malware needed — which can open the door to sensitive data and broader systems.

↗ The Hacker News
⚔️  Active Attacks
AI Coding Assistant Hijacked, Worm Spreads Across 100 Code Repositories

Security firm Mandiant reported that an attacker took over an active AI coding assistant session at an unnamed software company. The attacker used the hijacked session to get the AI to recommend a poisoned software package — and when a developer accepted it, the attacker slipped in a program that steals passwords and tokens. From there, a self-spreading worm called Shai-Hulud tore through roughly 100 internal code repositories, stealing source code and login secrets. The attacker also poisoned a public software package on PyPI, meaning other companies could have been hit too.

🛡 What to do: If your team uses AI coding assistants, remind developers to verify any package an AI recommends before installing it — treat AI suggestions like advice from a stranger, not a guarantee.
HBO Max Reddit Account Hijacked to Spread Malware via ClickFix Ads

Hackers took over the official HBO Max Reddit account and used it to run ClickFix-style ads that pushed malware to visitors. Because the account was verified and well-known, readers were far more likely to trust the posts. This is a growing tactic: attackers hijack trusted, high-follower social accounts so their malicious links look completely legitimate.

🛡 What to do: Be skeptical of any post — even from a brand you recognise — that asks you to run a command or download a file. Legitimate companies don't ask you to do that through Reddit ads.
🔓  New Vulnerabilities
CVE-2026-81963 & CVE-2026-85880 Microsoft Windows (Two Actively Exploited Zero-Days) CRITICAL

Both flaws let an attacker who already has basic access to a Windows PC quietly upgrade themselves to administrator level — no extra tricks needed. Microsoft confirmed both are being actively exploited in the wild right now, meaning real attackers are already using them. They were patched in this month's record-breaking Patch Tuesday update.

Status: Patch available — install the September 2026 Windows update immediately.

CVE-2026-58704 Google Pixel Cellular Modem HIGH 8.0

A logic error in the cellular modem of Google Pixel phones lets an attacker nearby — think same Wi-Fi network or cellular range — gain elevated control over the device without the owner doing anything. Google confirmed it has seen signs of limited, targeted attacks using this flaw already. The fix is in Google's September 2026 security patch, which addresses 110 vulnerabilities in total.

Status: Patch available — update your Pixel phone to the September 2026 security patch now.

CVE-2026-90894 Parallels Desktop for Mac ("ParaShells") HIGH 7.8

Parallels Desktop — the popular app that lets Mac users run Windows inside a window — has a flaw that lets any normal user account on the Mac silently escalate to root access. The catch: the attack requires code already running locally, so a remote stranger can't exploit it over the internet. The fix exists in Parallels Desktop 27, but Intel-based Macs cannot install that version, leaving a large chunk of users without a patch.

Status: Patch available for Apple Silicon Macs (Parallels Desktop 27). Intel Mac users have no patch yet — consider limiting who has local access to your machine.

🛠  New Tech
Forever Security Demo: One Browser Extension Can Hijack Five AI Assistants at Once

Researchers at Forever Security built a proof-of-concept browser extension that can take control of the AI assistants built into Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and the Claude browser extension — all with a single click. On some products, the rogue extension could drive the AI to act on the attacker's behalf: opening files, switching on the camera and microphone, or browsing the web as you. This isn't an attack seen in the wild — it's a research demonstration — but it exposes a structural problem: all five products share the same underlying browser architecture, so a flaw that works on one tends to work on all. The researchers published their findings to push browser makers and AI developers to build stronger walls between extensions and AI agents.

💡  Deep Dive
153 Million Driver's Licenses for Sale: Is Your Face and ID Already Online?

Imagine a database containing the front and back of your driver's license — plus infrared and ultraviolet scans of it — timestamped to the exact day you last handed it to a stranger. That's what the Nexus identity theft service is selling, and it already has over 153 million records. Your information may be in there without you ever knowing.

The source of the breach appears to be an identity verification company — one of the businesses that many apps and services hire to confirm you're who you say you are. When you photograph your license to rent a car, open a bank account, or board a flight, that image often goes to a third-party verifier. According to the people behind Nexus, they have been quietly draining one such company's database for over a year. Brian Krebs at KrebsOnSecurity confirmed the breach is real by checking his own license and those of friends — each person's timestamp matched a real-world event where they showed their ID. The FBI has opened an investigation.

For regular people, this is more alarming than a typical password breach. A stolen password can be changed. A driver's license — your face, your address, your date of birth, your license number — cannot. With that information, criminals can open credit accounts, commit tax fraud, or impersonate you to pass identity checks at other companies. Some records even include government Common Access Cards, marijuana dispensary cards, and commercial driver's licenses, suggesting the breadth of industries using this compromised verifier is enormous.

Until the source company is publicly named, there's no definitive way to know if your license is in the set. Watch for unusual credit inquiries, new accounts you didn't open, or letters from the IRS about income you didn't earn. Consider placing a free credit freeze with the three major credit bureaus if you haven't already. The FBI investigation is ongoing — this story isn't done yet.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →