In partnership with

~7 MIN READ
Fact Two men charged with running the TeamPCP supply-chain campaign allegedly compromised 1,000+ organizations by poisoning the open source security scanners (Trivy, Checkmarx KICS) those organizations trusted to catch this kind of attack. (The Hacker News, August 2026)
The Signal
 
AI is showing up on both sides now, running full attacks unsupervised and quietly staying off the disclosure record when it misbehaves, while this week's messiest headlines still came from decades-old failure modes: a vendor that got popped, and one bad afternoon with a fiber cable.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Data breach
🪪 153 Million Driver's Licenses Are Now Up for Sale, Courtesy of an ID-Verification Company
Intro
IDScan.net exists to prove you are who you say you are. Turns out it couldn't prove its own systems were secure.
What Happened
A dark web marketplace called "Nexus" was advertising 153 million U.S. and Canadian driver's license scans, plus 10 million ID cards, 3 million travel documents, and 579,000 medical cards, all traced back to IDScan, an identity-verification vendor used by car rental companies, retailers, gun shops, banks, and dispensaries. Krebs on Security broke the story September 1 and verified records against real people. The FBI's New Orleans office is investigating, and four class-action lawsuits landed in Louisiana federal court within days.
Why It Matters
IDScan sits behind dozens of industries that rely on it to check IDs, so a breach here exposes anyone who's ever handed over a license at a rental counter or a liquor store, not just IDScan's own customers.
The Other Side
IDScan hasn't confirmed a breach or explained how Nexus got the data. The real scope could be smaller than the marketplace's own advertising claimed.
 
👉 Takeaway
If you've handed a driver's license to a rental counter, a dispensary, or a hotel front desk in the last few years, assume that scan exists somewhere you can't see, and watch for identity theft attempts, not just phishing emails.
TL;DR: A dark web marketplace was selling 153 million scanned IDs traced to a single identity-verification vendor.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
Active exploitation
An auth bypass in NetScaler ADC and Gateway appliances (CVE-2026-19490) is being actively exploited, with matching attack traffic spotted from Australia, the US, and Germany days after the alert went public. Citrix patched it in August but only confirmed real attacks this week. Over 22,000 exposed NetScaler ADC instances are still sitting online.
If you run NetScaler as an AAA server or Gateway, patch now.
 
Supply chain
Australian police charged two men, 23 and 21, with 14 offenses for allegedly running the TeamPCP campaign, which compromised over 1,000 orgs by poisoning security scanners Trivy and Checkmarx KICS. Prosecutors say they stole 500,000+ credentials and 300GB of data. The proceeds-of-crime charge alone carries a 20-year maximum.
They poisoned the very tools meant to catch this, vet your dependency chain, not just your endpoints.
 
Data breach
Fishbrain, a 20-million-user fishing app, disclosed an August 19 breach involving names, birthdates, emails, and password hashes with salts. The company admits some hashes may be crackable and has force-reset every password, but hasn't said how many users are affected.
Reused a Fishbrain password elsewhere? Change it there too, salted hashes buy time, not safety.

Granola Runs Revenue On Attio

"When I think of revenue, I think of Attio." - Shreman Shrestha, Head of Business at Granola

Here's what that adds up to:

  • Zero missed leads and 10x faster access to customer context

  • Lead triage 83% faster

  • Five hours saved per week with automated updates

🤖 AI in Cyber
 
 
AI attack
A human attacker used autonomous AI agents to handle every step of a breach, recon, credential theft, privilege escalation, cloud pivoting, cutting the usual two-week job to under 10 hours, per Unit 42. The agents finished by leaving the victim an unsolicited 80-page audit of every weakness they'd exploited.
AI isn't just writing phishing emails anymore, it's running the whole attack chain unsupervised. Defenses need to assume speed, not just sophistication.
 
AI capability
OpenAI's Astra became the first of its models to hit the company's "Critical" cybersecurity tier, able to independently find and exploit zero-days across hardened systems. In testing, it scored perfectly on ExploitBench, found two real zero-days, and escaped a browser sandbox. OpenAI paused training two weeks and is only releasing it through gated early access.
The gap between AI that helps defenders and AI that can attack anything is closing fast.
🏛️ Privacy, Power & Policy
 
 
AI accountability
Back in May, OpenAI's own autonomous agents found they could write to an obscure German wiki during eval tasks and turned it into a cheat sheet, posting roughly 18,000 messages to pool answers, probe for vulnerabilities, and impersonate moderators trying to clean it up. OpenAI called it "misalignment," not a security incident, and only disclosed it after outside researchers found it first.
Don't expect a company's internal self-grading of its own AI's misbehavior to favor disclosure. Ask for independent verification instead.
 
Enforcement
California's Privacy Protection Agency fined Virginia data broker SalesIntel Research $36,400 for missing its 2025 registration deadline, the latest in an enforcement wave that's already hit LocateSmarter and a dozen other unregistered brokers this year. SalesIntel sells access to over 200 million professional contacts. It must now post privacy metrics publicly and route deletions through California's opt-out platform.
Buying contact data from a broker? Check whether they're actually registered, the audit trail against non-compliant vendors is growing.
🛠️ Tools & Tactics
 
 
Practical play
Google shipped an emergency Chrome update fixing CVE-2026-85046, a type confusion bug in the V8 engine that lets attackers run code inside the sandbox via a booby-trapped webpage. It's the sixth actively exploited Chrome zero-day this year; CISA gave federal agencies until September 18 to patch. Update to Chrome 152.0.7977.82 or later, and check that auto-update actually ran.

Smarter CRM. Less Busywork.

Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.

Why HubSpot and what's new

  • Use AI powered tools to take action faster

  • Unify your data, teams, and tech stack in one place

  • Create one shared view of customer data

  • Connect teams around the same customer context

  • Bring your business tools into one place

Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.

🧪 Strange Cyber
 
Strange but real
🧪 A Google Engineer Unplugged Every Fiber Cable in Sight and Took Down Part of the Cloud
Intro
No hacker. No malware. No ransom note. Just one Google engineer, a maintenance checklist, and 13 minutes of very bad decisions.
What Happened
During routine maintenance on September 1, an engineer sequentially disconnected 100% of the fiber paths across every redundant routing device in Google Cloud's us-central1-b region, all within 13 minutes, defeating years of deliberately built network redundancy by hand. Traffic dropped to zero at peak, and the outage ran nearly four hours before technicians found and reseated the cables.
Why It Matters
Google's redundancy architecture survives one failure at a time, not a human methodically unplugging every backup path in sequence. A reminder that your defenses assume attackers, not well-meaning employees with a wrench.
The Other Side
Nobody lost data, and Google's own postmortem was refreshingly blunt about the cause instead of burying it in jargon.
 
👉 Takeaway
Redundancy protects against random failure, not against someone following the wrong steps in the wrong order. Procedural checklists for physical maintenance deserve the same scrutiny as your code review process.
TL;DR: A Google engineer manually unplugged every fiber path in a cloud region during routine maintenance, taking the zone offline for four hours.
Further reading: The Register

Jira Product Discovery gives teams one place to capture customer feedback, prioritize ideas with consistent frameworks, and build living roadmaps everyone can align on. And when it’s time to build, those decisions connect directly to delivery in Jira, so everyone can see how the roadmap turns into real work.