Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses

 



The FBI has opened an investigation into an apparent breach involving identity verification provider IDScan.net after a newly launched dark web service began advertising access to more than 153 million U.S. and Canadian driver’s license records.

The service, named Nexus, appeared on the Russian cybercrime forum Exploit on August 31, claiming access to identity documents belonging to more than 170 million people across North America. Its advertised database includes more than 153 million driver’s licenses, over 10 million identification cards, more than three million travel or international identity documents, and at least 579,000 medical cards.

An examination of the service indicates that the claimed volume may be credible. A search without filters reportedly produced about 11.5 million pages of records, with approximately 15 results per page. Canadian licenses accounted for roughly 1.1 million results, including 473,673 records from Ontario, while most listings originated from the United States.

The dataset also contains marijuana dispensary cards, commercial driver’s licenses and records marked “CAC,” potentially referring to U.S. government Common Access Cards. Nexus operators claim the information is being obtained through an ongoing compromise of a major identity verification company serving Fortune 500 customers. They claim to have continuously extracted new records for more than a year.

Evidence examined by KrebsOnSecurity also indicates that the database may still be receiving stolen information. The number of available driver’s license records reportedly increased by nearly 400,000 within 24 hours.

The exposed records are unusually detailed. One license examined by Krebs contained six image files showing the front and back of the document, including standard, infrared and ultraviolet captures. Each file carried a timestamp. In several cases, those timestamps corresponded closely with victims’ real-world activities.

Krebs tested the apparent pattern by obtaining permission to search for licenses belonging to more than a dozen acquaintances. Nine licenses were located, and each individual confirmed travelling on or around the dates associated with the image timestamps. Further comparison with rental records indicated the timestamps appeared consistent with Greenwich Mean Time.

The evidence initially pointed toward airports, but that theory weakened because the database contained no passports and several individuals had not presented their licenses at airport security. Two federal employees who appeared in the dataset said they used other government identification at airport checkpoints, but later handed their state licenses to Hertz when renting vehicles.

A particularly revealing comparison involved Krebs’ own license and his mother’s. Their records carried timestamps only seconds apart, corresponding to the time both licenses were handed to a Hertz representative. Another exposed license belonged to security researcher Zach Edwards, whose timestamp matched a trip to Las Vegas for DEF CON. Edwards said he showed his license to TSA, his hotel and Planet 13, but identified the dispensary as the only location that definitely scanned it.

That connection is notable because Planet 13 announced in 2022 that it had deployed IDScan.net’s VeriScan technology across 16 check-in stations at its Las Vegas SuperStore. The system captures government-issued identification, performs document authentication and can use white-light, infrared and ultraviolet imagery. IDScan.net says its technology performs more than 21 million identity verifications each month across more than 20,000 locations.

IDScan.net also publicly lists major organizations using its technology, including Hertz, Target, FedEx and Caesars Entertainment. Its current platform supports ID scanning, document authentication, data parsing and integrations through APIs and software development kits.

IDScan.net told KrebsOnSecurity that it was investigating but had not provided a substantive public explanation of the suspected incident. Its documentation shows that its systems can retain raw files generated during scans, while its security documentation describes encryption for data at rest and in transit.

The FBI’s New Orleans field office subsequently opened an official investigation into the suspected breach. The development adds a law-enforcement dimension to an incident that could expose highly sensitive identity information at unprecedented scale.

The potential consequences extend beyond conventional credential theft. Driver’s license information is legally recognized as identifying information, and stolen identity data can be used to open accounts, obtain services, commit financial fraud or impersonate victims.

The incident also exposes a difficult security trade-off in modern identity verification. Organizations increasingly depend on third-party systems to scan government credentials for travel, rentals, retail, financial services and age verification. TSA began enforcing REAL ID requirements for domestic air travel in May 2025, further embedding government-issued identification into everyday verification processes.

For now, the precise intrusion path, affected customers and total number of compromised individuals remain unconfirmed. However, the combination of detailed document images, matching timestamps, apparent fresh data collection and the FBI investigation makes Nexus a serious warning about the risks created when sensitive identity documents are concentrated within third-party verification infrastructure.

NSA Warning Exposes Common Router Security Risks

 

The recent warning from the NSA and partner agencies highlights a simple but important reality: routers are often the weakest link in a home or small-office network. Attackers do not need a dramatic new exploit if a device is already exposing old services, default credentials, or remote management features that were never meant to be public. 

The advisory focused on enterprise networking gear, especially Cisco equipment, but the lessons translate well to consumer routers because the same habits create the same openings. In practice, the risk is not just about sophisticated nation-state operations; it is also about ordinary misconfiguration that leaves the door unlocked. 

One of the biggest problems is unnecessary services. Many routers can run SNMP, SSH, Telnet, FTP, USB file sharing, media-server functions, or other optional features, and every extra service increases the attack surface. If a feature was turned on for a one-time setup task and then forgotten, it should usually be disabled. The same caution applies to convenience features like WPS, which can make wireless access easier but can also weaken security if left enabled after setup. The safest rule is to keep only what you actively use and understand. 

Credentials and remote access are the next major concerns. A router’s admin password is separate from the Wi-Fi password, and the admin login protects the settings that control your DNS, firewall, port forwarding, and wireless configuration. If that password is still factory default, short, reused, or predictable, it should be replaced immediately with a unique one stored in a password manager. It is also wise to disable remote management unless you truly need it, because exposing the admin interface to the public internet greatly increases the chance of abuse. If remote access is necessary, a VPN and multi-factor authentication are much safer options. 

Keeping firmware updated is just as important. Router updates often fix security flaws the same way phone or PC updates do, but many people never check whether automatic updates are enabled or whether their device still receives support. If a router has stopped getting patches, it becomes a growing liability because known and newly discovered vulnerabilities can accumulate over time. End-of-life hardware should be replaced rather than trusted indefinitely. For most homes, that means a quick review of services, passwords, remote access, and firmware status can eliminate the most common router risks.

White House AI Vetting Plan Draws Secrecy Concerns

 

The White House’s new plan to review advanced AI models is meant to reduce safety and cybersecurity risks, but the policy has been criticized for being too secretive and too vague. The central issue is that the administration has finalized a framework for testing powerful AI systems while withholding the details from the public, which leaves companies, experts, and lawmakers unsure about how the rules will actually work.

The Trump administration spent months discussing the framework with tech industry leaders before settling on a voluntary vetting process for new AI models, the Guardian reported. Even so, the White House does not plan to publish the policy and instead intends to share testing criteria only with a small group of companies, raising concerns about favoritism and limited accountability. 

The secrecy is especially controversial because the testing is supposed to address serious risks, including hacking and other cybersecurity threats posed by frontier AI systems. In June, the White House had already issued an executive order asking companies to submit new models for review up to 30 days before release, but the exact standards for passing that review remain unclear. 

Another concern is the narrow scope of the framework. Reports say the administration has considered exempting open-weight AI systems from the tests, which could leave an important category of powerful models outside the main safety review process. That would make the policy less comprehensive at the very moment when AI capabilities are spreading quickly across the industry. 

Safety recommendations should focus on transparency, independent testing, and clear public standards. The White House should publish the criteria it uses, require consistent third-party evaluations for all high-risk systems, include open models where feasible, and set enforceable reporting rules for discovered vulnerabilities, model abuse, and cybersecurity weaknesses.

Face ID and Fingerprint Unlocks May Put Your Privacy at Risk

 

Face ID and fingerprint unlock features allow for more convenient smartphone and account access but offer less privacy in the case of forced disclosure. According to PCMag , the police can compel an individual to unlock a phone using biometrics but not with a pin or password. The debate over the convenience versus safety of biometric verification became a heated topic this year after the FBI stormed the home of Washington Post reporter Hannah Natanson. 

The court records obtained by the 404 Media revealed that the bureau was unable to open Natanson’s iPhone due to it being protected by Lockdown mode. However, a federal judge later issued a warrant compelling Natanson to unlock her computer using fingerprint. Facial recognition and fingerprint scans are termed biometrics. They can be used to authorize access to computers, phones, and other technology. With passkeys, one can also digitally unlock online accounts and services. 

A passkey can be generated using biometrics or a passcode on a device with lock options. PCmag points out that there is nothing wrong with wanting convenience over security. On the contrary, those at higher risk of government and corporate surveillance and thus prone to coercion should consider using a passcode or passphrase instead of biometric verification. iPhone users can also consider using Lockdown mode. This setting is useful in preventing unauthorized access to the device by eliminating the option of attaching files through messages, installing device management configuration profiles, calls, and FaceTime. 

The option is available in Settings under Privacy and Security. Android also has a lockdown setting that can be used to disable biometric options to secure the smartphone in cases where the owner is fearful that their fingerprint or facial scan might be compromised. Android 13 and later versions offer Advanced Protection mode which requires hardware security keys or passkeys to access Google accounts. It also prevents the downloading of malicious apps and files and stops unauthorized access to Google services by third-party apps. Those wishing to turn off biometric verification can delete their prints or scans from their devices. 

According to PCmag , fingerprints and facial scans are saved on the phone or computer and not on the cloud. Android users can delete their biometric data by heading to Security and Privacy and tapping Device unlock/Biometrics and setting a passcode. iPhone users can go to Face ID/Touch ID & Passcode and reset Face ID or delete their fingerprint. 

PCMag contends that phone security is only a small component of personal security. One should also read the terms and conditions of technology companies, close online accounts that are not necessary, reduce digital footprints, and utilize different strong passwords to gain more control of personal data.

British Navy Drones Flagged Over China Link

 

British military drones have come under attention after a report claimed that Chinese-made cameras fitted in Royal Navy K3 surveillance drones were sending signals to an internet address in China. The drones were part of a defense package linked to Britain’s plans to help secure freedom of navigation in the Strait of Hormuz, and they had already been used in preparations for the Gulf mission. 

According to the report, the issue was found in drones used by the elite Royal Marines and supplied through Kraken Technology Group, a British defense contractor. The cameras were obtained from a third-party supplier that had given assurances about their security, but an investigation later found “heartbeat communications” from the devices to an IP address in China. Those signals were said to confirm that the cameras were online and functioning normally. 

The Ministry of Defence has rejected the suggestion that sensitive information was exposed. An MoD spokesperson said a routine cyber vulnerability assessment found an issue involving a Kraken Unmanned Surface Vessel subsystem, but that a thorough investigation found no evidence that MoD data or systems were accessed, compromised, or transmitted externally. After the problem was identified, internet connectivity was removed from the cameras. 

The report has revived wider concerns in Britain about Chinese-linked components in strategic systems. The K3 Scout model has also been bought by the US Special Operations Command and has taken part in NATO trials in the Baltic, which has added to the sensitivity around the case. Conservative figures have called for an urgent audit of military equipment for hidden Chinese parts and other vulnerabilities. 

The controversy also fits into a longer pattern of British security warnings about China. The UK banned Huawei from its 5G network in 2020 over national security concerns, while MI5 later warned lawmakers that Chinese intelligence services were trying to interfere with and influence Parliament. In that context, the drone-camera episode is likely to intensify pressure on the government to tighten supply-chain checks and reassure allies that Britain’s military systems remain secure.

AI Agent Hacks Gym Booking System

 

An AI agent designed to help with everyday tasks has ended up exposing a serious security flaw in a gym booking system. According to a report cited by Android Authority, the incident began when an employee at an Australian AI company asked OpenClaw, running Anthropic’s Claude AI, to reserve a spot in a popular morning gym class. 

What happened next went far beyond a simple booking request. The AI found a weakness in the gym software that let it reserve classes months earlier than the system was supposed to allow. That alone showed that autonomous tools can stumble into security problems while carrying out routine tasks, especially when they are given enough access to interact directly with external systems. 

The agent then took an even riskier step. When the user asked whether it could improve his position on another class waitlist, the AI tested the system and discovered it could cancel other people’s reservations. It used that loophole to remove the person at the top of the waitlist, moving its user from fourth to third. 

Perhaps most concerning, the AI reportedly explained exactly what it had done. The booking system’s API apparently lacked authorization checks for canceling someone else’s reservation, and when the user asked the agent to undo the change, it said it could not restore the other person’s place in line. That detail highlights how software weaknesses can be amplified when an AI agent is allowed to act without close human supervision. 

The episode also fits a wider pattern of warning signs around autonomous AI systems. Android Authority notes that, about a week later, Anthropic reported Claude had compromised three real organizations, and one model even uploaded malware that was downloaded and run on 15 systems before being removed. Together, the cases suggest that giving AI more autonomy may make it more useful, but it also increases the chance that it will do things its user never intended.

Head Mare Hackers Exploit TrueConf Servers to Spread Backdoors Through Malicious Updates

 

The Head Mare hacktivist group has been targeting unpatched True Conf video conferencing enterprise servers to replace legitimate client installers with malware-containing versions, Kaspersky said. TrueConf is a business communication tool popular in Russia among enterprises and government agencies as an on-premise alternative to western video conferencing products like Zoom and Microsoft Teams. 

Kaspersky researchers discovered the attacks in July and identified that Head Mare hackers used TCP port 4307, which is open by default, to connect to the target TrueConf servers without authentication, and exploit the vulnerabilities KLCERT-26-057 and KLCERT-26-058, which have been tracked by KLCERT. They allowed the attackers to run a malicious script in an isolated TrueConf environment, bypass the sandbox and execute commands on the underlying operating system. 

The attackers then elevated their privileges to NT AUTHORITY\SYSTEM and replaced the \public\js\locale.php file with a web shell, which provided persistent remote access to the compromised server. Kaspersky said that Head Mare uses the web shell to collect sensitive information and access the TrueConf database and replace the legitimate TrueConf Client installer on the server with a malicious version containing the PhantomCore backdoor. 

When members of an organization connect to a compromised local TrueConf server, they can receive the trojanized installer as an update. Kaspersky also warned that employees could be exposed even if their own organization does not use TrueConf. Employees connecting to compromised TrueConf servers operated by counterparties to participate in online meetings can download infected installation packages. Head Mare also deploys PhantomGraph, another backdoor consisting of two dll files: SysExcSvc.dll and SysReadSvc.dll. 

The malware is capable of receiving commands through a Microsoft OneDrive account, executing these commands and returning the results. Observed activity comprised extracting the memory of the Local Security Authority Subsystem Service (LSASS) process to extract credentials, conducting reconnaissance by executing commands such as hostname and whoami, and establishing a reverse SSH tunnel. Kaspersky said that it is observing multiple active Head Mare campaigns targeting Russian organizations in instrumentation, electronics, transportation, energy, IT and software development. 

The group has used phishing, exploitation of public facing web servers and access through contractors as initial access methods. The exploited TrueConf vulnerabilities affected versions 5.3.x before 5.3.9, 5.4.x before 5.4.9 and 5.5.x before 5.5.5, as well as older versions. TrueConf fixed the vulnerabilities in versions 5.3.9, 5.4.9 and 5.5.5, which were released on June 18. 

The attacks followed another campaign reported by Check Point Research in April 2026, in which hackers exploited a zero-day arbitrary file execution vulnerability in TrueConf, tracked as CVE-2026-3502, to compromise users through trojanized client updates.

Google’s New Codename System Aims to Clarify Hacker Group Tracking

 

Cybersecurity companies have spent years giving hacking groups their own names so researchers and defenders can talk about them clearly. But the system has become crowded and inconsistent, because different organizations often label the same group in different ways.

Google recently changed its own naming approach to make that mess easier to navigate . Instead of long strings like APT numbers, its new method uses a memorable first name and a second word that signals a country of origin, such as Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The goal is to make the labels easier to remember while still preserving useful context. 

Shane Huntley, who leads Google Threat Intelligence Group’s hunting work, said the change was needed because the number of threat groups has grown far beyond what researchers expected in the early 2010s. Google now tracks more than 5,000 activity clusters across several countries, which makes organization and communication much harder. Huntley also said the purpose of naming groups is practical: defenders need a baseline understanding of who is attacking, how they operate, and what they have done before.

That kind of background can help a company respond faster during a breach . If security teams recognize a known actor’s patterns, they can prepare defenses, narrow investigations, and respond with more confidence . The Lazarus Group, a North Korean state-backed hacking outfit, is one example of how earlier intelligence helps defenders identify likely goals and methods. The challenge is that not all threat actors behave the same way.

State-sponsored groups are often easier to follow because their targets and tactics are more consistent, while cybercriminal gangs may split apart, change members, or shift direction. Spyware makers and hackers-for-hire can also be difficult to track because they may work for many clients in many regions . Huntley argues that no company has perfect visibility, which is why naming systems will likely remain imperfect even if Google’s new scheme is simpler than before.