Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: FBI Probes Dark-Web Sale of 153M+ Driver's Licenses — IDScan.net Breach Suspected (20260907)

KrebsOnSecurity reports a dark-web service named Nexus is selling 153M+ U.S. and Canadian driver's licenses among 170M+ identity documents, with an FBI assistant director and security researchers among identified victims and the trail leading to ID-verification vendor IDScan.net (Target, FedEx, Motorola Solutions among clients). Also: N-able ships its fourth N-central hotfix in five weeks for CVE-2026-86218 (CVSS 10.0, unauthenticated RCE); Datadog finds AWS root-user password spraying aimed at 150+ organizations; Citrix NetScaler CVE-2026-19490 draws post-PoC exploit attempts from 8 IPs across 5 countries; Check Point Research unpacks JSCeal, whose stolen-cookie session replay bypasses Google authentication; a public Telerik UI padding-oracle RCE exploit chain is released; GPUThor row-hammer research defeats Nvidia GPU ECC; ~5,000 Dropbox accounts fall through a legacy Lenovo ID integration; Taiwan's NCSIST traces its procurement-site attack to a hidden vendor interface.

Data-Breach IDScan.net Driver-Licenses Dark-Web KrebsOnSecurity Identity-Verification N-able CVE-2026-86218 RMM Citrix NetScaler CVE-2026-19490 AWS Datadog JSCeal CheckPoint GPUThor Nvidia ScreenConnect Huntress Telerik CVE-2026-13181 Dropbox Lenovo NCSIST CISO-Digest

FBI Probes Dark-Web Sale of 153M+ North American Driver’s Licenses — IDScan.net Breach Suspected

A dark-web seller is advertising one of the largest troves of North American identity documents ever seen, and the evidence trail points to a single U.S. identity-verification platform. KrebsOnSecurity reported that on August 31, a service calling itself Nexus posted an ad on a Russian underground forum claiming to hold 170M+ identity documents for North Americans: more than 153M U.S. and Canadian driver’s licenses, 10M ID-card images, 3M+ travel documents and other international IDs, and 579,000 medical documents such as health-insurance cards. Free samples included editor Brian Krebs’s own Virginia license — six images each of front, back, infrared, and ultraviolet captures with date-and-time stamps — evidence the imagery originated from document-scanning hardware.

Researchers who searched the Nexus storefront found victims far beyond journalists: an FBI assistant director and researchers from two security firms were among the U.S. licenses identified, and both victims had presented ID at a Hertz rental counter and a licensed cannabis retailer — merchants that rely on IDScan.net, a U.S. online identity-verification provider whose customers include Target, FedEx, Motorola Solutions, financial firm Jack Henry, and Caesars Entertainment. The pattern led researchers to infer a backend breach of IDScan.net, which would widen the exposure to every business using the platform. The site held roughly 1.1M Canadian licenses and was adding ~400,000 new license images every 24 hours — an active pipeline, not a one-time dump. The FBI’s New Orleans field office opened an investigation last week; Caesars said it stopped using IDScan.net in early 2025; Nexus took its storefront offline after press coverage; IDScan.net has not commented publicly.

Why This Reshapes Identity-Verification Governance

  • Vendor concentration at the identity chokepoint: front/back color plus infrared and ultraviolet document imagery — the exact material used to defeat weak liveness checks — now appears tied to one platform processing IDs at rental, retail, casino, and financial touchpoints. One backend compromise yields reusable identity kits for fraud at scale.
  • The ~400,000-images-per-day growth rate indicates ongoing exfiltration rather than a single archived dump, meaning the exposure window may still be open and the final victim count unknowable.
  • Silent-victim vendor risk: businesses that outsource ID checks cannot yet confirm whether their provider was the source — IDScan.net has not disclosed a breach — while Caesars’ “stopped using it in early 2025” timeline shows how long data can keep circulating after a vendor relationship ends. The FBI probe will settle attribution, not exposure.

🔗 Reference: Coverage from (KrebsOnSecurity, iThome)


Active Threats This Week

📌 N-able ships a fourth N-central hotfix in five weeks for CVE-2026-86218 — CVSS 10.0 unauthenticated RCE N-able released 2026.3 Hotfix 4 in the early hours of September 6 (UTC) for a maximum-severity flaw in its N-central RMM platform: CVE-2026-86218 (CVSS 4.0 score 10.0, CWE-96 static code injection) allows remote code execution on the N-central server without authentication and affects every on-premises build below 2026.3.1.14 — including servers updated to Hotfix 3 (2026.3.1.13) roughly eight hours earlier. Hosted NCOD instances are already patched. Notably, N-able’s own communications disagree on exploitation: its incident notice says the flaw has been exploited in the wild, while the release notes call that unconfirmed; no IoCs, interim mitigations, or detection guidance have been published beyond auditing N-central accounts for unexpected users. Huntress, tracking N-central attacks since August, advises IP-allowlisting or VPN-only access to the console. 🔗 Reference: The Hacker News

📌 Citrix NetScaler CVE-2026-19490 moves from disclosure to active exploitation attempts The authentication-bypass flaw patched by Citrix in late August — CVE-2026-19490, CVSS v4.0 9.3, affecting specific NetScaler Gateway and AAA virtual-server configurations, and covered in our August 21 digest at disclosure — is now drawing real attack traffic. Threat-intel platform Previdian reported on September 4 that after a PoC appeared September 2, it detected exploit attempts starting September 3; by September 7 the source IPs had grown from 3 (Australia, United States, Germany) to 8 IPs across 5 countries, totaling 17 observed exploitation attempts. Whether any NetScaler was successfully compromised remains unknown, but Belgium’s NCC-BE has updated its advisory to echo Previdian’s findings and urge immediate patching. 🔗 Reference: iThome

📌 AWS root-user password spraying targets 150+ organizations Datadog’s security research team disclosed that root users with full account access in more than 150 organizations’ AWS accounts have been targeted by password-spraying attacks. No successful sign-in has been observed, and the attackers’ source for root-user email addresses — either a pre-compiled list or enumeration from a set of account emails — and their end goal remain unknown. AWS has required MFA on root users since 2025, but the researchers argue organizations should reduce reliance on long-lived root credentials rather than treat MFA as sufficient. 🔗 Reference: iThome

📌 Telerik UI padding-oracle chain gets a public unauthenticated RCE exploit Security firm TantoSec released a working exploit chain and a ready-to-run CLI tool (telerik-rau-exploit) with two payloads — one writing a web shell to disk, one running entirely in memory — against Telerik UI for ASP.NET AJAX. The chain turns an AES-CBC padding oracle in the RadAsyncUpload control (versions 2010.1.309 through 2026.2.519) into unauthenticated remote code execution, anchored by CVE-2026-13181 (CVSS 8.1), an unguarded type-resolution flaw. Progress Software patched the bugs on July 8 in version 2026.2.708 (advisory July 22), and exploitation requires a non-default configuration — a page must render RadAsyncUpload — so default installs are not exposed. There are no confirmed in-the-wild attacks, but the disclosure puts a complete attack path in public hands for the first time. 🔗 Reference: The Hacker News

📌 JSCeal: compiled-V8 stealer replays stolen cookies into victims’ Google accounts Check Point Research published a fully static deobfuscation of JSCeal, a compiled V8 JavaScript (JSC) malware family first documented in July 2025 and delivered via fake cryptocurrency-trading sites and bogus TradingView installers reached through Facebook and Google malvertising (overlapping the WEEVILPROXY/MeadowLocust clusters and Confiant’s recently documented SourTrade operation). The malware enumerates installed browsers — Chrome, Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc — and extracts cookies, passwords, and OAuth tokens, then reconstructs browser sessions for active session-replay attacks that bypass authentication, including unauthorized access to victims’ Google accounts. A second module records keystrokes and screenshots, and a local-proxy module installs certificates and injects service-specific traffic modifications with dedicated handlers for Binance, Bybit, and Ledger. Payloads are RC4-protected with control-flow flattening to resist analysis. 🔗 Reference: The Hacker News

📌 Rogue ScreenConnect clients spread a four-stage VBScript chain to newly connected hosts Huntress documented three unrelated August incidents — a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund-form lure — that all ended in rogue ConnectWise ScreenConnect clients repeatedly spawning wscript.exe to execute a staged payload chain (1.vbs → 4.vbs) from temporary directories, with each script profiling the host and launching the next. Observed C2 infrastructure: 45.13.237[.]190 (tele-sync.opik[.]net) hosting a RAR archive of the four VBS files, 131.123.40[.]98:8041, and borertors92.anondns[.]net. The worm-like propagation pattern — infecting newly connected systems once a rogue client is installed — makes containment of the initial access point the critical control. 🔗 Reference: The Hacker News

📌 ~5,000 Dropbox accounts accessed through a legacy Lenovo ID integration flaw Dropbox confirmed that approximately 5,000 customer accounts were accessed between August 4 and 21 after attackers exploited the email-verification process of the legacy Dropbox ↔ Lenovo ID login integration: an attacker could register a new Lenovo ID using someone else’s email address without proving ownership of that inbox, and the legacy integration then allowed that Lenovo ID to sign straight into the victim’s Dropbox account — no Dropbox password required. Dropbox told affected users that fewer than a third of the accessed accounts had files actually opened, and said the issue was apparently not caught by live monitoring at the time. Lenovo stated its own customers and systems were unaffected and that both companies worked together to mitigate the risk once identified. 🔗 Reference: Bitdefender

📌 GPUThor: row-hammer technique defeats ECC on Nvidia GPUs, reaching for host root University of Toronto researchers demonstrated GPUThor, a new row-hammer-style attack that breaks Nvidia GPU ECC protection on Ampere-architecture cards with GDDR6 memory (RTX A4000, A4500, A5000, and A6000). By using non-uniform memory-access patterns that exploit GPU request coalescing and Target Row Refresh (TRR) behavior, GPUThor flips bits even with ECC enabled — producing double-bit errors ECC detects but cannot correct, and triple-bit errors beyond its correction capacity — enabling data corruption, GPU denial of service, GPU page-table tampering, and privilege escalation of CUDA applications toward host root access. The team reported the issue to Nvidia on April 29; Nvidia responded on August 25 with mitigation guidance (enable SYS-ECC, IOMMU/DMA isolation, and GPU error-telemetry monitoring). No in-the-wild exploitation is reported. 🔗 Reference: iThome

📌 Taiwan’s NCSIST procurement site: hidden vendor interface cracked by overseas IPs Taiwan’s National Chung-Shan Institute of Science and Technology (NCSIST) revised its account of an August 28 incident in which its procurement website mass-mailed outdated tender notices to suppliers. Initial statements blamed the institute’s own AI security survey agent — saying the agent broke API encoding rules during a test and triggered the mailings — but a September 5 follow-up revealed an external attack: the contracted developer had hidden a scheduled-management interface inside the system for maintenance convenience, and that interface was cracked by overseas IP addresses that triggered the resend of inquiry notices. NCSIST acknowledged a governance gap: although it issued an SBOM-based software-development handbook about a year ago, the affected system dates to 2019 and was never backfilled under the policy. It has demanded full SBOM data from the vendor and is reviewing its response procedures. 🔗 Reference: iThome

📌 US and UK formalize joint action against Southeast Asia scam centers The U.S. Scam Center Strike Force — established in November 2025 by the D.C. U.S. Attorney’s Office with the FBI, Secret Service, DOJ Criminal Division, HSI, and IRS-CI — signed a memorandum of understanding with England and Wales’ Crown Prosecution Service and the UK’s National Crime Agency to fight the organized-crime networks behind Southeast Asia scam compounds: shared intelligence, parallel investigations of common targets, and coordinated prosecution jurisdictions. Overlapping cases have already been identified; the next joint action is a London meeting in early October, hosted by the NCA with private-sector participation. The DOJ has not disclosed specific targets. Context for the effort: the FBI estimates crypto-investment scams cost U.S. victims about $7.2 billion in 2025. 🔗 Reference: iThome


How Can OPSWAT Help

Several of today’s threats arrive as files: JSCeal rides bogus TradingView installers and ZIP archives delivered through malvertising, the ScreenConnect campaign chains MSI installers with VBScript payloads, and the Telerik exploit writes web shells to disk. MetaDefender multi-scan layers 30+ anti-malware engines over installers, archives, and executables so trojanized files are blocked before they reach endpoints or servers, while MetaDefender Deep CDR (Content Disarm & Reconstruction) rebuilds scripts, documents, and archives into safe forms — shrinking the blast radius of malvertising lures, rogue installers, and staged script chains like these.