UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan.net confirms a breach after a marketplace advertised over 153 million US and Canadian driver's licenses, possibly exfiltrated continuously for over a year.
The Louisiana identity-verification firm detected unauthorized access on or around September 1, 2026, after the 'Nexus' identity theft service on the Exploit forum began advertising 170M+ people's records, including 153M+ driver's licenses, 10M+ ID cards, 3M+ travel documents, and 579,000 medical cards. Canadian records exceed 1.1 million, and the trove includes commercial licenses, Common Access Cards, and dispensary IDs, with a record for US Defense Secretary Pete Hegseth reportedly included. Nexus operators claim continuous exfiltration for over a year, with the license count growing by nearly 400,000 in 24 hours, suggesting the intrusion may be active. The FBI's New Orleans field office has opened a formal inquiry, and IDScan.net is offering free credit monitoring.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Attackers abused Brevo's SAML SSO to access 138 accounts, sending phishing emails to 347,000 Trezor customers and exfiltrating contacts from 43 accounts.
Trezor said 347,000 of its customers received phishing emails with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' after the attacker compromised the Brevo marketing platform. Brevo said the intruder created an account, enabled SAML SSO, and used its own identity provider to access 138 accounts, exfiltrating contacts from 43 of them. Trezor reported 2,500 users clicked the malicious link before the site was taken offline 20 minutes after detection; potential fund losses are unknown. Swiss wallet maker BitBox and crypto tax calculator CoinTracking also appear affected, and Trezor separately disclosed a ShipMonk breach now affecting roughly 81,000 people.
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
Boston Scientific says a cyberattack has caused global disruption to its operations, with no confirmation yet on device impact or data exfiltration.
Boston Scientific, a major medical device manufacturer, disclosed that a cyberattack is causing global disruption to its operations. The company has not confirmed whether medical devices are affected or whether any customer data was exfiltrated. The investigation appears to be ongoing, and healthcare-sector exposure raises patient-safety and supply-chain concerns.
Terabytes of credentials leaked in massive supply-chain attack
Compromise of an AI software package led to scraping and exfiltration of terabytes of credentials from about 2,500 users.
A supply-chain attack involving a compromised AI software package resulted in data being scraped and exfiltrated. Roughly 2,500 users were affected, with terabytes of credentials leaked. The article provides limited technical detail on the package or attackers involved.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Malicious LiteLLM 1.82.7/1.82.8 PyPI releases tied to the Trivy TeamPCP campaign harvested cloud, SSH, and database credentials, potentially exposing 2,500+ organizations.
CloudSEK reported that two malicious LiteLLM releases on PyPI (versions 1.82.7 and 1.82.8, live about 40 minutes on March 24) harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords, with captured loot files mapping potential exposure to more than 2,500 organizations including NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. The campaign is part of TeamPCP (tracked by Google as UNC6780), linked to the Aqua Security Trivy scanner compromise tracked as CVE-2026-33634 and added to CISA's Known Exploited Vulnerabilities catalog on March 26. The payload used a litellm_init.pth file executed at Python interpreter startup and exfiltrated secrets to models.litellm[.]cloud; the FBI's FLASH-20260702-01 advisory urged rotation of CI/CD, publishing, and cloud credentials.