Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a major cyberattack that exposed data belonging to over 1.2 million citizens and 200,000 entities. The breach, which involved payment receipt data dating back to 2008, has led to calls for resignations from senior officials, including the CSDD chief. The incident has raised national security concerns and prompted investigations by cybersecurity authorities and state police.

Latvia's Road Traffic Safety Directorate (CSDD), the state agency responsible for vehicle registration and driver's licenses, has confirmed a significant data breach impacting approximately 1.2 million individuals and 200,000 businesses. This figure represents about two-thirds of Latvia's total population of 1.8 million. The breach led to the exposure of data from payment receipts dating back to 2008.
Information compromised in the attack includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, and addresses listed on vehicle registration certificates. The CSDD stated that customer phone numbers, email addresses, usernames, and passwords were not affected, and that address information was incomplete in some records. Despite the breach, the agency's day-to-day operations, including online and in-person services, remained uninterrupted.
Latvia's computer emergency response team (CERT.LV) cautioned that the stolen information could be leveraged by criminals for social engineering and fraud schemes. The CSDD has since restricted access to a public service that allowed users to look up vehicle information using a license plate number. The agency also reported successfully blocking a subsequent cyberattack attempt over the weekend, attributing the defense to security enhancements implemented after the initial breach.
The CSDD initially disclosed the incident last week, characterizing it as a "complex" cyberattack where unauthorized third parties gained partial access to systems containing historical payment receipt data. CERT.LV indicated that the attackers exploited a vulnerability in a CSDD system exposed to the internet, and that several mandatory cybersecurity requirements had not been met. The nature and methods employed in the attack suggest a high level of technical competence and prior preparation by the attackers.
The incident has escalated into a political controversy, prompting calls for accountability. Latvian President Edgars Rinkevics stated that the attack posed "a significant threat to national security" and called for the CSDD's leadership to resign, citing a loss of public trust. Member of Parliament Andris Kulbergs echoed these sentiments. Following this, the CSDD's supervisory board submitted its resignation. CSDD chief Aivars Aksenoks also announced his intention to resign after assisting with the ongoing investigation and addressing the consequences of the attack.
Aksenoks suggested that responsibility for the breach might extend beyond the CSDD, pointing to Tet, a Latvian telecom and technology company that provides some of the agency's IT infrastructure and security monitoring services under a five-year contract. He claimed that Tet, which is responsible for certain firewall and incident-monitoring functions, failed to detect the intrusion or alert the agency, with CSDD employees discovering and stopping the attack themselves within hours.
Tet's chairman, Uldis Tatarcuks, has pushed back against premature blame, emphasizing the need for investigators to first determine the precise entry points, timing of access, compromised systems, and specific security failures. Tet clarified that its responsibilities cover only specific parts of the CSDD’s IT infrastructure, not the entire network.
Latvian cybersecurity and data protection authorities are continuing their investigation into the incident, and state police have initiated criminal proceedings. This breach follows another significant cyberattack earlier this summer against LVM, a state-owned forestry company, which experienced a ransomware attack in June that disrupted its mapping platform, hunting application, and systems for exchanging information with contractors and customers. Although LVM had worked on Latvia’s electronic voter registration system, officials confirmed that the election system was unaffected as it was developed separately and its source code was not stored on LVM’s network.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed