Top story
Identity-verification firm IDScan confirmed hackers spent roughly a year inside its cloud and stole driver's license records — full names, license numbers and other government ID numbers — covering more than 150 million US and Canada residents, including license photos and records of high-profile individuals (IDScan confirms theft of over 150 million driver's license records). The data is being sold via the Russia-linked Nexus dark-web marketplace; IDScan published its notice on September 4 after learning of the access around September 1 (breach notice and Nexus link). This is exactly the data used for identity verification, and license numbers can't be quickly reissued — durable fuel for identity fraud.
Exploitation & threats
- Cisco FMC breached by state and ransomware actors. Talos identified three clusters (UAT-12197, UAT-11823, UAT-11988) exploiting CVE-2026-20079 (CVSS 10.0 unauthenticated auth bypass → root execution) and CVE-2026-20316 (hard-coded credentials): one dropped a JSP web shell and credential harvester, the Sandworm-assessed cluster deployed a Cyclops Blink backdoor, and Qilin affiliates deployed Qilin ransomware (Cisco Talos intrusion clusters).
- KEV additions with a hard deadline. On September 9 CISA added four actively exploited flaws — Cisco FMC CVE-2026-20079, Citrix NetScaler CVE-2026-19490, Fortinet CVE-2025-25249, and Chrome V8 CVE-2026-87491 — ordering federal agencies to patch by September 12, 2026 (KEV additions).
- China-linked espionage shares the BlueMoon kit. Proofpoint and Volexity tie JungleBamboo (APT31), UTA0560 and UNK_LateNight to spearphishing (since August 28) chaining Chrome V8 zero-days CVE-2026-85046/CVE-2026-87491 with Windows ALPC LPE CVE-2026-85880; fixes are upstream but not yet in Chrome stable (BlueMoon exploit kit).
- AI agents ran an exploitation campaign. GreyNoise tracked a likely Russian-speaking actor using hundreds of AI agents (OpenAI Codex + DeepSeek) to exploit PaperCut CVE-2026-81578/CVE-2026-82078 (emergency-patched August 28), compromising 440+ instances at 395 organizations in 48 countries since August 31, education-heavy (AI-driven PaperCut campaign).
- JFrog Artifactory exploited in the wild. Wiz confirmed chaining of CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329 between August 15 and September 8 to obtain admin tokens, deploy Groovy plugins and install Rust backdoors (Wiz on Artifactory exploitation).
- Fortinet attacks with a RAT. SOCRadar tracked CVE-2025-25249 attacks scanning 30,000+ IPs, infecting 178 devices with PivotC2 RAT and exfiltrating data, mostly from US targets (Fortinet PivotC2 campaign).
Patch priorities
- Cisco FMC: hotfixes for CVE-2026-20079/CVE-2026-20316 are available now; patch before the September 12 federal deadline (hotfix details).
- Citrix: apply the August 19 fixes for CVE-2026-19490 on gateway/AAA configurations; honeypots logged 56 attack attempts September 3–8 after a public PoC (NetScaler KEV entry).
- Check Point: September 9 emergency hotfixes for the CVSS 9.8 pair CVE-2026-85102/CVE-2026-85103, unauthenticated RCE on VPN-enabled gateways (emergency fixes).
- Palo Alto: CVE-2026-0310 (CVSS 9.2) allows