ZeroHour

Search: “licensing”

4 stories in the last 24h

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

ShinyHunters published hundreds of thousands of records from Florida's DAVID vehicle database, including SSNs and passports, after an unpaid ransom demand.

The ShinyHunters group published hundreds of thousands of files from Florida's DAVID motor vehicle database on its leak site, saying the victim did not pay a ransom. Stolen records include vehicle ownership certificates with names, addresses, and VINs, plus a smaller number of Social Security numbers, non-US passports, and immigration documents. FLHSMV confirmed the breach, which followed theft of a police officer's credentials stored on a personal device. It comes the same month as the IDScan hack exposing over 150 million driver's license images.

TechCrunch · Security · 12h agoData breach 3 sources

Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

Group-IB attributes large-scale smishing using the JWR real-time phishing kit to the Smishing Triad's Outsider cluster, harvesting card data, OTPs, and bank credentials.

Group-IB attributes a large-scale SMS phishing campaign to Outsider, an operator sub-cluster within the Smishing Triad phishing-as-a-service ecosystem, using a kit dubbed JWR. The Vue 2-based platform maintains real-time WebSocket communication with operators, enabling them to adapt pages live and harvest roughly 70 PII fields, card data, PINs, OTPs, identity document images, and digital wallet credentials via a dedicated PayPal sub-funnel. Unit 42 previously tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024. Defenders can hunt for /api/open/ endpoints, /webSocket/QT/ paths, JWR-prefixed storage artifacts, and a hard-coded WebSocket token.

GBHackersupdated · 16h agofirst · 18h agoPhishing & fraud in the wild 2 sources

CenterPoint Energy confirms data breach following claims on hacking forum

CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records via an unauthenticated API lacking WAF, rate limiting, and token checks.

CenterPoint Energy, a Houston-based utility serving about 7 million customers, confirmed in a September 14 SEC Form 8-K that an unauthorized third party accessed customer data through an external system after a hacker posted a 7.49 million-line dataset online. The exposed fields include names, phone numbers, addresses, account numbers, emails, driver's license numbers, and the last four digits of Social Security numbers. The hacker said the API had no web application firewall, rate limiting, certificate checks, or authentication token, and that a CAPTCHA stopped exfiltration at 7.49 million of a claimed 17.44 million lines. The company faces multiple class action lawsuits and is working with outside experts to determine scope.

Help Net Securityupdated · 15h agofirst · 20h agoData breach in the wild 5 sources

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

Cyber Security News · 22h agoVulnerability in the wildCVE-2026-627211