ZeroHour

Source: Krebs on Security

3 stories in the last 30d

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft's September Patch Tuesday fixes a record 974 flaws, including two actively exploited Windows zero-days and critical DNS and Windows Shell bugs.

Microsoft released fixes for 974 vulnerabilities, its largest-ever monthly patch batch, bringing the 2026 total above 2,600. Two zero-day privilege elevation flaws, CVE-2026-81963 and CVE-2026-85880, are being actively exploited. Critical bugs include CVE-2026-69730, an unauthenticated DNS weakness in Windows Server 2012 onward and Windows 10 deemed likely to be exploited, and CVE-2026-69829, a CVSS 9.8 Windows Shell remote code execution flaw requiring no privileges or user interaction. Microsoft and other vendors credit AI-assisted discovery for the growing patch volumes.

FBI Probes Service Selling 153M+ Drivers Licenses

Dark web service Nexus sells scans of 153M+ US and Canadian drivers licenses, apparently siphoned from a breached identity verification company; FBI opened an inquiry.

A new dark web identity theft service called Nexus, advertised on the Exploit forum, offers scans of more than 153 million drivers licenses from the US and Canada, plus over 10 million ID cards and millions of travel and medical documents. The data appears to come from an ongoing breach at a major Louisiana-based identity verification company, with records growing by roughly 400,000 in 24 hours. Records include high-ranking US officials such as Defense Secretary Pete Hegseth, and timestamps suggest data was captured during car rentals and travel. The FBI's New Orleans field office has launched an official inquiry into the source of the images.

Krebs on Security · 14d agoData breach in the wild1

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members, a data extortion group tied to prolonged software supply chain attacks.

The Australian Federal Police arrested two unnamed suspects from Western Australia, aged 21 and 23, believed to be members of TeamPCP. The group is described as a cybercrime and data extortion syndicate blamed for the longest-running spree of software supply chain attacks, allegedly creating malicious open-source software that hit thousands of global businesses. KrebsOnSecurity had identified the 21-year-old suspect in June and had been in contact with him.

Krebs on Security · 20d agoPolicy & legal