The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

The Federal Bureau of Investigation is reportedly investigating a potential data breach that may have exposed the identity information of up to 170 million North Americans, primarily impacting individuals in the United States and Canada. The incident first came to light through the investigative work of journalist Brian Krebs.
The alleged breach involves a service named "Nexus," which was offered on the Russian cybercrime forum Exploit. Nexus claimed to provide access to digital scans of identity documents, including over 153 million driver's licenses, as well as ID cards, travel documents, and medical cards. The operators of Nexus asserted that this extensive trove of data originated from an active breach at a "major identity verification company."
Although the Nexus service ceased operations shortly after Krebs published his findings, his investigation, which involved tracking activity from his own and other identified victims' movements, linked the data to IDScan.net, an identity verification provider based in New Orleans. IDScan.net has confirmed it is currently investigating the matter.
A compromised driver's license can have significant and lasting repercussions, as it contains sensitive personal details such as date of birth, address, physical descriptors, and a government-issued identification number. This information is often sufficient to bypass identity verification checks used by many financial institutions and government agencies. Unlike passwords, these core identity details cannot be changed, meaning affected individuals could face lifelong exposure to this risk.
Experts suggest that this incident underscores the need for higher standards in identity verification processes. Businesses that rely on third-party identity verification vendors are advised to scrutinize their data retention policies, particularly regarding how long scans are kept after verification is complete. They should also inquire about contractual obligations for data minimization and the possibility of auditing these vendors.
The absence of a mechanism similar to a credit freeze for compromised driver's license numbers highlights a critical gap in current identity protection measures. Organizations that collect and centralize government-issued identity documents are urged to implement security protocols for these data stores that are at least as robust as those applied to payment card data, if not more stringent. While a new credit card number can be obtained relatively quickly, a new face, or the core identity details associated with it, cannot.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.