this week in security — september 6 2026 edition
THIS WEEK, TL;DR
FBI investigating dark web site selling 150+ million driver's licenses
Krebs on Security: *pinches bridge of nose* ...Add this story to the annual jealousy list, for this was one hell of a scoop. A crime site advertised on the dark web allowed anyone to search over 150 million driver's licenses. @briankrebs confirmed the leak because his license was leaked, along with Secretary of Defense Pete Hegseth and most of the adult population of North America… great. The data leak was traced to a company that performs ID checks in the real-world for a range of things, like going to weed dispensaries, attending entertainment venues, and renting cars. All signs point to a "hellacious ongoing real-time breach of their data," per @thezedwards, who helped Krebs find the source of the spill. The vendor isn't 100% confirmed yet because the company isn't commenting. The FBI said it's investigating and the Pentagon told me it's "aware" and "evaluating" the reports. The crime site vanished after Krebs' report, but this breach could be major and long-lasting for a lot of people across the U.S. and Canada.
More: Techdirt | TechCrunch ($) | The Hill | American Banker | Ars Technica | Biometric Update | @briankrebs | @thezedwards

Thomson Reuters confirms hack affecting U.S. and Canadian courts
The Record: Media and data conglomerate Thomson Reuters disclosed a data breach in its C-Track case management platform, which a dozen U.S. states and some Canadian courts use for tracking legal cases. Per a public notification, the platform breach affected sealed and other confidential filings, but the media and data broker giant says it's still unclear what data might've been compromised. The Record has the best account of what we know, which is mostly a list of what we don't know, thanks to Thomson Reuters' scant notification. There have been so many court filing system hacks over the years, it's hard to keep count — and some have been far more damaging than others. This points to a wider underlying rot across the gov-tech sector, whose software has always been crap.
More: CTrack Notification | Court News Ohio | Ontario Courts | Reuters ($) | DataBreaches.net | Tech Times
Hackers accessed thousands of Dropbox accounts after exploiting Lenovo login bug
Bloomberg ($): Hackers compromised around 5,000 Dropbox accounts and 1,500 accounts had data downloaded following a broad scale breach caused by a bug involving Lenovo… You're thinking, wait, what? How, even?! Turns out that Dropbox users can access their accounts using verified Lenovo IDs, an account that allows users to access products and services made by Lenovo, even if users hadn't set up a Lenovo ID before. Due to a flaw in an integration set up between Dropbox and Lenovo, the hackers could access the Dropbox accounts simply by knowing the person's email address and creating a new Lenovo ID with it. Dropbox cut the access and disclosed the breach to customers.
More: 9to5Mac | Reuters ($) | The Register | IT Pro | Hacker News
Vandals are destroying Flock cameras as backlash intensifies and states seek bans
this week in security: Vigilantism and vandalism are causing damage to Flock cameras across America in an unprecedented wave of anger against the mass surveillance company. I spent some time writing about why people are cutting down and destroying Flock cameras, and why this phenomenon is far more tangible and real for people to feel and experience than previous surveillance scandals. This anti-Flock sentiment isn't going away any time soon, and it's picking up steam in political circles, with Republican-led states getting ready to ban Flock. All eyes are on where the privacy fight goes next, which leads us to this very relevant Inspirational Skeletor.
More: The Verge ($) | BBC News ($) | TechCrunch ($) | @onekade | @hypervisible
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
You can also submit a one-time tip to show your support, or consider gifting a paid subscription.
Recent blogs include: Vigilantism comes for Flock | How residential proxy networks are hiding hackers in your home | This quick question can still expose North Korean spies in an instant | The top highlights from Black Hat, Def Con, and BSides Las Vegas 2026, if you couldn't make it | Dozens of America's largest companies have no simple way to report security flaws
~ ~
THE STUFF YOU MIGHT'VE MISSED
AI burnout is hitting bank and hospital defenders
Bloomberg ($): Security researchers working to defend high-risk organizations like hospitals and banks are burning out at a record pace, thanks in part due to executives pushing the use of AI. Half of surveyed hacker hunters say the stress is causing them to reconsider their jobs. Defenders don't need AI; they need better salaries, better working conditions, and job stability.
Anthropic warns some users have been infected with infostealers
Bleeping Computer: AI giant Anthropic emailed a bunch of users warning that they've been compromised by infostealing malware (think: all your saved passwords and logged-in sessions have been stolen), and the company knows this because the attackers have been using that access to churn through Claude credits. Frankly, an infostealer infection is a much bigger issue than just stolen tokens.
Papercut issues emergency patches after bugs exploited to hack customers
Cybersecurity Dive: If you've got a Papercut installation on your network, take action ASAP, as hackers are actively exploiting two bugs that when chained together allows a full "point and shoot" compromise of their network, per @_JohnHammond. The software is widely used across the higher-ed sector. Papercut has released patches.
A growing list of end-of-life routers you should probably unplug
End of Life: Do you have a networking device on your network that you might not realize no longer gets security bug fixes and software patches? This new End of Life tracker lets you see which devices that U.S. cyber agency CISA told other federal agencies to ditch from their networks as they will never see another update. Unplug today!
OpenAI's agents targeted a German wiki in latest revealed incident
Reuters ($): There's been yet another incident involving an AI model hacking escaping containment to hack into something else. Reuters reported that one of OpenAI's models bypassed its sandbox restrictions and then targeted a German wiki to use as its own bulletin board for scribbling thousands of notes for its later reference. The incident happened in May, but OpenAI executives reportedly kept the incident under wraps. More from The Verge ($) and Ars Technica.
Thousands of Microsoft Exchange email servers are vulnerable to hijack attacks
Bleeping Computer: Around 22,000 servers running Microsoft Exchange's email software can be hijacked with relative ease, thanks to a bug whose details are now online. Most of the buggy servers are located in the U.S. or Germany. The bug, fixed in August, allows a hacker to remotely hijack entire mailboxes on a server without credentials. Meanwhile: Microsoft had a sizable Outlook outage this week lasting at least two days, in case you couldn't access your email more than usual.
~ ~
OTHER NEWSY NUGGETS
Health breaches o' plenty: Bad news if you have ever needed, uh, healthcare, after at least three major health giants disclosed hacks this week. Some 9.5 million people had their medical data stolen in a breach affecting Aesto Health, while Nutex Health disclosed a data breach in an 8-K filing, including patient and employee data. And, oncology care company NovoCure also filed an 8-K saying hackers stole over 1,400 U.S. patient records. The hackers behind the attacks are not yet known. (via HIPAA Journal, MassDevice, Fierce Biotech)
Troops' tricks counter-snoops: A newly published letter from U.S. military leaders confirmed the Pentagon has disabled advertising IDs on its troops' devices to make it more difficult for adversaries to buy commercially available location data derived from their phones to attack bases. Wyden notes that there is still a backdoor left open as servicemembers' personal devices, which are also brought onto bases, are not covered by the Pentagon's phone policy change. (via Reuters ($), Ron Wyden)
Pegasus pilfers parliamentarian's phone: Security researchers have identified a fresh Pegasus spyware infection targeting the phones of Serbia's student protest movement, as well as a Serbian opposition member of parliament. The infections were identified in January running on iPhones with software predating iOS 18.4.1, which fixed the flaw abused by Pegasus. The phone hack was one of the "largest documented wave" of spyware attacks in the country, and the recency of the attack shows Pegasus is still very much actively in use. (via Citizen Lab, SHARE, Cyberscoop, The Guardian, @billmarczak)

Sality sails into cyber sunset: The U.S. Justice Department and CrowdStrike teamed up to take down the Sality botnet, some 23 years since it first debuted on the cybercrime scene. Sality had been used to plant malware and steal cryptocurrency. CrowdStrike said the botnet had over 33,000 infected machines on its network. (via Coindesk, HelpNetSecurity)
Norway's no to pervert glasses: Norway is set to say nei to camera-enabled smart glasses (aka "pervert glasses") after the digital minister said the glasses, made by Meta and Snap, could be banned over privacy fears. (via All About Cookies, TechCrunch ($), Firstpost)
~ ~
THE HAPPY CORNER
Welcome to this week's happy corner, where we like to chill out, take it easy, and focus on the brighter things in the cyber world.
Speaking of being really chill… the Canadians have really put up with a lot of our (*coughs loudly with American awkwardness*) nonsense of late, especially with the recent silly renaming of Lake Ontario, which saw Apple and Google both capitulate and change their maps to Lake America. But not trusty ol' MapQuest, which stood its ground and refused to budge. As such, MapQuest was rewarded by being blasted to the top of the app store charts. In case you haven't heard of MapQuest before, congrats on being under the age of 30. Before smartphones were a thing, printing out driving directions was pretty much the only way to get somewhere without getting lost.

Using an ad-blocker is always good advice. Here are some more suggestions if your browser doesn't support uBlock anymore:

If you hate surveillance as much as I do, then you're probably going to love this new digital camouflage shirt that confuses AI-powered cameras capable of detecting people, as covered by 404 Media ($). Also: Not to be outdone, as promised from Def Con, a custom-made adversarial pattern blocked a Flock camera from being able to detect an entire car. Great stuff here!
And this week's caption contest. Tell me what is going on in the photo below? (Me: "If it's Clooney or the cat, I'm choosing the cat.") I'll put the best replies in next week's edition.

Have good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
Meet Maya, this week's cyber cat, who is doing an absolutely brilliant job of trying to brute force her human's login. (The real password is "chin_Scritches_01.") Thanks so much to Robin L. for sending in!

🐈 Please send in your cyber cats! 🐈⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter!
~ ~
SUGGESTION BOX
And that's it for another busy week in the world of cyber, thanks so much for reading and subscribing! I won't keep you another minute, I've already taken up enough of your day. I hope you have a great rest of your week (and Labor Day if you're here in the U.S.!). I'm back next Sunday with everything you need to know about cyber, privacy, national security, bugs, flaws, breaches, and more!
If you liked this newsletter, please share it. And if you haven't checked out my articles in a few, I'd love to know if there's anything you are particularly interested in and would like for me to explore or write up. The blog is for you! Reach out to me with your suggestions; if you're interested in something, you bet someone else is, too.
And as always, if you have anything for next week's edition, please send me a note — it's great to hear from you. Tell me your success stories! If you have something you're proud of and want to share, I'd love to know more. Email me any time.
Jetpacking outta here,
@zackwhittaker