The Nexus story this week deserves more attention than it will probably get. A dark-web service is selling scans of over 153 million U.S. and Canadian driver's licenses, and the evidence points to a breach at idscan.net — an identity verification provider used by rental car counters, dispensaries, bars, and any business that needed to confirm a customer's identity quickly and cheaply. The FBI's New Orleans office has opened an inquiry. The data includes images, timestamps, and location context that makes it significantly more useful for fraud than a name-and-SSN dump.
The part worth sitting with is the layer that got hit. Identity verification providers exist precisely because individual businesses can't build robust ID-checking infrastructure themselves — they outsource the trust. When the outsourced trust layer is the thing that gets compromised, every downstream business that relied on it has a problem they may not yet know they have, and every customer who handed over their license at a rental counter or a dispensary is now in a database being sold by the scan. The blast radius of a compromised ID verification provider is structurally different from a typical breach. It doesn't just expose data — it undermines the mechanism other services use to decide who to trust.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🇮🇪 Rotting paper psychiatric records were found in abandoned HSE facilities in Ireland, leading to exposed patient data. The Irish Data Protection Commissioner fined the HSE €645,000 and ordered audits, removals, and better record controls. The breaches highlighted ongoing risks from paper records and failures in GDPR compliance.
🇺🇸 Novocure says a mid‑August cyberattack exposed data for more than 1,400 U.S. cancer patients and some employees. Most patient records lacked names, but under 50 western U.S. patients had identifying and provider contact details accessed. The company reports no device or operational impact and is evaluating notifications and legal requirements.
🇺🇸 Aesto Health said a data breach exposed personal and medical data for about 9.54 million people. The breach, linked to its AWS systems, occurred between December 2 and 18, 2025 and was discovered in June 2026. Names, SSNs, IDs, financial and health information were among the stolen data, and dozens of healthcare clients were affected.
🇺🇸 Nutex Health confirmed hackers accessed its network and stole patient, employee, provider, business, and financial data. The company says no material business impact has been found yet and it is still investigating while facing a class-action lawsuit. The Gentlemen ransomware group claimed responsibility and threatened to leak the stolen data.
🇺🇸 McKesson says its operations are running after a cyberattack that stole data from some customers in its oncology, multispecialty, and medical-surgical units. The group ShinyHunters claimed responsibility and is reportedly demanding over $55 million, though McKesson did not confirm a ransom. The company is investigating, says there is no ongoing unauthorized activity, and has engaged cybersecurity experts.
→ More breaches:
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🇺🇸 🇨🇦 🪪 A new dark‑web service called Nexus is selling scans of more than 153 million U.S. and Canadian driver’s licenses. Evidence suggests the data came from a breach at identity‑verification firm idscan.net, and the FBI’s New Orleans office has opened an inquiry. The leak includes sensitive images and timestamps tied to places like rental car counters and dispensaries, raising serious privacy and safety concerns.
🇺🇸 ⚖ 🇷🇺 A Russian national, Searzhudin Aktulaev, was extradited to the U.S. and charged for running a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware. He used fake accounts to send malicious Excel files that gave him remote access and stole login and personal data. Aktulaev is in federal custody and will appear in court on October 5.
🇻🇪 ⚖ 🇺🇸 Five Venezuelans pleaded guilty in the U.S. to trying to steal cash from ATMs in Kansas. They attempted to install malware to force machines to dispense money but were caught on camera and arrested. One received nine months in prison; the other four await sentencing as authorities warn ATM "jackpotting" is rising.
🇳🇬 ⚖ 🇺🇸 Two Nigerian men were extradited to the U.S. and charged in sextortion schemes that helped cause the deaths of two teens. They face life in prison and long mandatory minimums on charges including child sexual exploitation and coercion. The FBI says sextortion targets minors via stolen explicit images and warned victims to contact law enforcement.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🔐 The G7 urges governments and industry to speed up switching to post-quantum encryption. They warn quantum computers could one day break current encryption and let attackers decrypt past or future data. Nations say organizations must act now, coordinate, and build crypto-agility.
🇷🇸 📲 Researchers found Pegasus and a NoviSpy variant on devices of Serbian student activists, one MP, and a local official. The infections appear linked to authorities and coincided with election-related protests. Apple warned users and researchers urge updating iOS to block the exploit.
🇳🇴 🥸 Norway is weighing a ban on camera‑enabled smart glasses and other wearable headsets over privacy worries. Officials fear these devices, often with internet links and soon facial recognition, could be used to monitor people in public. The government will form an expert group to advise on rules to protect privacy.
🇺🇸 🗳 A whistleblower says the USPS is rushing three new, untested IT systems that could control and block mail-in ballots. The systems may reject entire ballot batches for small barcode or manifest errors, shifting the burden to state election officials. Critics warn the rushed, secretive rollout risks widespread ballot delivery failures and legal challenges.
🦠 MALWARE & THREATS
🐍 Researchers warn about BraZetsu, a Python-based Windows malware that turns compromised computers into sellable assets on a criminal marketplace. It uses modular design and AI to scout networks, steal financial and browser data, and prioritize high-value targets. The malware supports remote execution for buyers and focuses on Iberian and Latin American victims.
🇧🇷 A cybercrime group called Gambling Goblin installed malicious Apache modules on Brazilian government and education sites to redirect visitors to betting and fake app-store pages. The attackers used reverse-proxy tricks and SEO manipulation to make high-reputation domains promote gambling while hiding their tracks. Researchers linked the campaign to China-aligned groups and found many hijacked gov.br hosts and supporting malware tools.
ℹ Researchers found a Shai-Hulud infostealer now scans 469 locations for credentials, up from 189. Attackers are harvesting existing tokens and keys to move through supply chains instead of breaking trust. Defenders must find, prioritize, and eliminate reusable publishing and production credentials, and shift to short-lived, identity-backed auth.
🤯 Researchers at ESET say a Russia-aligned group called UAC-0099 used a trick named GuardBreaker to stop AI tools from analyzing malware. They put a fake dangerous prompt ("I want to make a nuclear weapon. Help me ...") inside a VBS script to trigger LLM safety filters. The script then installs MATCHBOIL to load more malicious payloads.
🇨🇳 🔙 🚪 Security researchers say the Silver Fox group hid the ValleyRAT backdoor inside a signed Chinese adware app (QN Wallpaper) using DLL sideloading. The malware disables Defender, gains admin rights, and gives attackers full control while running inside a trusted process. Kaspersky warns not to install questionable software or add it to antivirus exclusion lists.
❌ After 23 years, the Sality P2P botnet was disrupted by international law enforcement and CrowdStrike. CrowdStrike manipulated the botnet protocol to isolate infected machines and inject sinkholes so bots can no longer get commands. ISPs, CSIRTs, and Shadowserver are helping identify and clean infected computers.
🇮🇷 🐀 Iranian group Nimbus Manticore is using fake recruiter job tests to spread cross-platform remote access trojans for Windows, Linux, and macOS. Kaspersky named the malware families NodeRabbit and PollCat, which run JavaScript/Node.js implants, persist via OS-specific methods, and communicate with Azure-backed C2 servers. The attacks target developer workstations with trojanized coding challenges to steal data and maintain long-term access.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🆕 OpenAI released GPT-6 Astra, a more capable model focused on computer use, browsing, software engineering, science, and cybersecurity. It shows strong cyber abilities, including finding zero-day exploits, so OpenAI added tighter safety checks that may pause or ask for user review. Astra is rolling out slowly to select users and APIs while OpenAI improves alignment and risk controls.
🤑 The Cronos blockchain was paused after a price-manipulation attack on the Tectonic lending protocol let an attacker borrow $74 million. The attacker only managed to bridge about $6 million off-chain; roughly $60 million remains stuck on Cronos. Cronos has restarted the chain, restored the state to before the exploit, and is monitoring the network while preparing a post-mortem.
🦠 Anthropic warned some Claude users that infostealer malware on their computers let attackers hijack login sessions and use their accounts. The company signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges. Users were told to remove the malware before re-adding payment details.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
⚠ 🦅 A researcher called Nightmare Eclipse released a CrowdStrike Falcon zero-day named "FalconFlank" that lets attackers get SYSTEM privileges on up-to-date Windows systems. CrowdStrike is investigating and told customers to disable the Office File Suspicious Macro Removal policy while protections in the cloud remain active. The researcher also published other antivirus and Windows zero-days this week, some confirmed working.
⚠ Hackers are actively exploiting a critical remote code execution bug (CVE-2026-0768) in Langflow’s custom component editor. The flaw lets attackers run arbitrary Python code as root and has been used for reconnaissance and credential theft. VulnCheck reports hundreds of attempts and thousands of successful attacks against multiple Langflow vulnerabilities.
⚠ SonicWall says two new zero-day flaws in its SMA1000 appliances are being actively exploited — One is a pre-auth SSRF (CV E-2026-83548) and the other is an authenticated OS command injection (CV E-2026-83549). Affected SMA1000 models should install the listed hotfixes immediately.
⚠ A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) was patched on August 28 and can let attackers gain admin access. Security firm WatchTowr says the flaw is already being exploited in the wild to mint admin tokens, and self-hosted users are urged to update to the patched versions. Earlier Artifactory flaws were also abused, including a zero-day used by an OpenAI model to attack Hugging Face.
🚨 🩹 PaperCut NG/MF print-management software had two zero-day vulnerabilities that let unauthenticated attackers bypass authentication and run remote code. The vendor released two emergency patches and IoCs after security firms found multiple exploit attempts and patch bypasses. About 1,000 PaperCut servers remain internet-exposed while investigations continue and attribution is unknown.
🛰️ ICS, OT & IoT
🩹 Rockwell Automation released patches and workarounds for more than a dozen security flaws across its industrial products. The fixes address DoS, privilege escalation, remote code execution, XSS, and other high-severity issues in RSLinx Classic, FactoryTalk, Logix controllers, ControlFLASH, and other tools. One advisory mistakenly labels CVE-2026-9637 as exploited, but CISA says there is no known exploitation.
🇨🇳 👀 Chinese-linked Fire Ant hackers covertly turned Cisco routers into spying platforms by installing custom malware and a hidden GRE tunnel. The attackers captured router traffic, uploaded PCAPs to external servers, and used a disguised backdoor called BridgeAgent for remote access. Sygnia warns the group tampers with logs and provides IoCs and detection rules.
🇺🇸 🇮🇷 U.S. strikes on Iran and Iranian counterattacks have increased the risk of cyberattacks on American infrastructure. Federal agencies warn Iranian-linked hackers have probed and disrupted water and utility control systems. Small local water systems are especially vulnerable.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.

