LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
breach

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.

zeroday.news ·

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach, attributing it to credentials stolen from a Plant City Police Department officer's personal electronic device. The department initiated an investigation on September 4 after discovering the incident.

The cybercriminal group ShinyHunters claimed responsibility for the breach on Monday, stating they had accessed FLHSMV data. As evidence, the group reportedly shared images of a Department of Motor Vehicles record associated with financier Jeffery Epstein.

FLHSMV officials confirmed the breach on Thursday, stating that a "criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device." Plant City is a suburb of Tampa. The department is collaborating with the Florida Digital Service and has informed other Florida government offices about the incident.

Initially, some cybersecurity experts speculated that this breach might be connected to a recently confirmed leak of 153 million driver’s licenses from the identity verification firm IDScan. ShinyHunters had previously sought to acquire the ID database from the perpetrators of the IDScan breach.

ShinyHunters has been linked to several high-profile attacks this year. In May, the group targeted an educational software suite, impacting over four million individuals. In April, they attacked a major medical device company. Other reported victims include bank IT provider Jack Henry, pharmaceutical and healthcare technology company McKesson (from which data from oncology and surgical units was reportedly stolen), Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.

Recent reports from artificial intelligence company Anthropic and incident responders at Google indicate that suspected affiliates of ShinyHunters are employing AI tools in their operations. These tools are reportedly used to scan for credentials, map unfamiliar systems, and exfiltrate data for extortion purposes. In one instance, an operator allegedly escalated from a stolen developer token to full administrative access within a victim's cloud environment in approximately three hours.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.