Top stories.
- New darknet marketplace peddles millions of driver's licenses.
- Healthcare companies disclose breaches.
- Law enforcement and industry partners shutter the Sality botnet.
- Nonprofit sues Trump admin for details on AI safety reviews.
- Two Nigerians extradited to US over sextortion schemes.
New darknet marketplace peddles millions of driver's licenses.
The US Federal Bureau of Investigation (FBI) is investigating a newly launched dark web marketplace that claims to be selling more than 153 million driver's licenses belonging to people in the United States and Canada, as well as more than 10 million ID cards, more than three million travel documents and international IDs, and at least 579,000 medical cards, KrebsOnSecurity reports. The driver's licenses appear to have been taken from a Louisiana-based identity verification company called "IDScan.net," although this hasn't been definitively confirmed. Krebs says his own driver's license is being advertised in the free sample offered by the marketplace. The marketplace, called "Nexus," is also selling the driver's licenses of US Defense Secretary Pete Hegseth and the assistant director of the FBI.
Shortly after Krebs published his article about the marketplace on Tuesday, Nexus's website disappeared, and its login page simply states, "This service is no longer available."
Nightmare Eclipse drops a CrowdStrike zero-day.
Security researcher Nightmare Eclipse on Thursday released an exploit for a zero-day flaw in CrowdStrike's Falcon endpoint security platform, the Register reports. The zero-day is a privilege-escalation flaw that affects a feature in Falcon that inspects Microsoft Office documents for malicious macros.
A CrowdStrike spokesperson told The Register, "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal."
Nightmare Eclipse is best known for releasing Windows zero-days in a protest campaign against Microsoft, but this week the researcher began releasing exploits for flaws affecting products from Kaspersky, Gen Digital, and now CrowdStrike. Security expert Kevin Beaumont has confirmed that the exploits are functional.
Healthcare companies disclose breaches.
American pharmaceutical giant McKesson on Saturday disclosed a cyberattack that disrupted some services and led to the theft of data belonging to "a subset of customers within [its] Oncology & Multispecialty and Medical-Surgical business units," the Record reports. The ShinyHunters extortion group claimed responsibility for the breach and is threatening to leak the stolen data unless McKesson pays a ransom.
Separately, medical device manufacturer Boston Scientific is still recovering from a breach it sustained last week, warning that pacemakers and other heart devices implanted after the attack on August 25th cannot be activated and therefore cannot transmit data, the Register reports. The company says the devices can be activated once its IT systems are back up, but did not give a timeline for recovery.
Law enforcement and industry partners shutter the Sality botnet.
An international law enforcement operation dismantled the Sality peer-to-peer botnet, which was active for more than two decades, BleepingComputer reports. US law enforcement worked with counterparts in Bulgaria, Hungary, and Romania, supported by Europol and Eurojust, to seize and sinkhole the botnet's infrastructure, cutting off infected devices from the botnet's operator. CrowdStrike and the Shadowserver Foundation also assisted in the effort.
CrowdStrike attributes the botnet, which has been active since 2003, to a Russia-based criminal threat actor tracked as "SALTY SPIDER."
Nonprofit sues Trump admin for details on AI safety reviews.
The US nonprofit Protect Democracy has sued the Trump administration for details on its framework for conducting safety reviews of frontier AI models prior to release, Ars Technica reports. The nonprofit asserts, "The regulatory process was set up without any legislation or legal authority of any kind, and almost no details have been released to the media, civil society, or the American public. That means the executive branch is now choosing which companies can release their products and which customers get access to a technology that could shape the future of not only American industry and national security, but economies and governments abroad as well."
The lawsuit is seeking "unclassified procedural and contractual architecture: the framework’s text, the terms of participation, the identity of participants, and the process and criteria by which access to frontier models is granted or withheld."
Two Nigerians extradited to US over sextortion schemes.
Two Nigerian nationals have been extradited to the United States for their alleged involvement in sextortion schemes that led to the suicides of two teenagers in Mississippi and North Carolina. The two suspects, 26-year-old Adebola Festus Adekunle and 24-year-old Mudasiru Afeez Olawale, are facing life in prison, with a minimum of 30 years for the sexual exploitation of a minor resulting in death.
The two men were arrested in 2023 as part of the FBI-led Operation Artemis, an international initiative targeting Nigeria-based sextortion rings.