
Drive-by data theft.
Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government’s bug supply.
Today is Wednesday September 2nd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
A dark web service called Nexus sold drivers license scans.
A newly launched dark web service called Nexus claims to be selling more than 153 million U.S. and Canadian driver’s license scans, along with millions of other identity documents. KrebsOnSecurity’s investigation suggests the images may have been siphoned from Louisiana-based identity verification provider IDScan.net, although the source has not been definitively established.
The clues include infrared and ultraviolet license scans, timestamps matching victims’ car rentals and other ID checks, and IDScan’s relationships with businesses including Hertz and marijuana dispensaries. Nexus’s inventory was still growing, adding nearly 400,000 license records in a single day. The service’s operators claim they’ve been continuously exfiltrating data for more than a year.
The FBI’s New Orleans field office has opened an investigation into an apparent breach involving IDScan.net. The company says it is investigating. Shortly after KrebsOnSecurity published its report, Nexus disappeared from the dark web, replaced by a message saying the service was no longer available.
OpenAI says its models have crossed a “Critical” capability level.
OpenAI says its newest model, Astra, is the first to reach the “Critical” cybersecurity capability level under the company’s Preparedness Framework, triggering additional safeguards before release. In evaluations, Astra earned a perfect score on ExploitBench, independently discovered two zero-day vulnerabilities, escaped a browser sandbox to execute commands on the underlying machine, and chained vulnerabilities to gain root access on a hardened operating system.
OpenAI says Astra also showed stronger safety behavior than its predecessor, GPT-5.6 Sol, rejecting 91.5 percent of cyber-related jailbreak attempts, compared with 59 percent for Sol. Given the model’s capabilities, OpenAI won’t make its full cybersecurity functionality broadly available at launch. A limited group of testers will receive early access, followed by wider availability through the company’s Daybreak Blue program.
International law enforcement disrupt a decades-old global botnet.
International law enforcement and private-sector partners have disrupted Sality, a peer-to-peer botnet that operated for more than two decades. Authorities in the United States, Bulgaria, Hungary, and Romania seized Sality-linked domains, while CrowdStrike and partners used a sinkhole operation to dismantle the botnet’s control channels and isolate infected machines.
First detected in 2003, Sality has infected more than 15,000 devices and distributed malware for credential theft, spam, proxy services, network exploitation, and DDoS attacks. CrowdStrike attributes the botnet to a criminal group it calls SALTY SPIDER, believed to operate from Russia. In recent years, Sality primarily delivered EggJagger, which replaces cryptocurrency wallet addresses copied to a victim’s clipboard with attacker-controlled addresses. CrowdStrike says the disruption has left the botnet no longer under its operators’ control.
Maria Varmazis hosts the T-Minus space cyber podcast, and each week she joins us for an update on the latest on what’s happening up there. She files this report.
The MSSA or Mobile Satellite Services Association has released Version 2.0 of its reference architecture for non-terrestrial networks. This updates the MSSA's guidance for new satellite systems that could support both 5G and Internet of Things services from a single satellite constellation. A major driver of this framework update is the growing use of regenerative satellites, which perform much of their processing onboard the satellite itself, rather than the traditional 'bent pipe in space' model where the satellite simply relays signals back to Earth. MSSA says the architecture will improve interoperability between terrestrial and satellite networks while helping operators balance competing demands for bandwidth, power, processing, and coverage.
This framework update focuses on technical standards and interoperability as the space industry continues to move toward using more regenerative architectures on orbit - reflecting a broader trend of moving more network intelligence into space. And that's the cyber angle here - as satellite constellations increasingly resemble distributed network infrastructure, more space operators will face many of the same challenges that we already see in terrestrial telecom environments, including improving the cybersecurity resilience of ever more complex interconnected networks.
“Slop squatting” leverages AI hallucinations.
Cybercriminals are finding ways to turn AI hallucinations into real-world scams. In a technique dubbed “slop squatting,” attackers identify nonexistent but plausible URLs or software packages repeatedly recommended by large language models, register them, and populate them with malware or other malicious content.
Palo Alto Networks prompted LLMs to generate 2.1 million brand-like URLs and found more than 13,000 pointed to confirmed malicious domains, while roughly 250,000 frequently hallucinated domains remained available for registration. Separate research found nearly 20 percent of LLM-recommended software packages were fictitious.
Security researcher Seth Michael Larson warns that users may mistakenly assume AI recommendations have been vetted. The threat could grow as AI agents gain more autonomy, potentially following malicious links or downloading compromised packages without human scrutiny. Larson argues the longer-term answer lies in stronger security infrastructure and phishing-resistant authentication.
Cleo Harmony users are urged to patch an authentication bypass vulnerability.
Organizations using Cleo Harmony are being urged to patch an authentication bypass vulnerability tracked as CVE-2026-84115. The flaw affects JWT refresh token handling and could allow remote attackers to bypass access controls and escalate privileges through manipulated bearer tokens. An exploit has reportedly been released, increasing the risk of attacks. Cleo fixed the vulnerability in Harmony version 5.8.1.11. WatchTowr says it has reproduced the flaw and recommends immediate updates, noting Cleo products have previously been targeted by ransomware groups.
Softaculous warns of a malicious Virtualizer update.
Softaculous says a BGP hijacking attack redirected some of its internet traffic to attacker-controlled servers, allowing malicious Virtualizor updates to reach customers between August 28 and 30. The attackers announced a more specific route for Softaculous IP addresses and obtained a valid Let’s Encrypt TLS certificate because certificate validation traffic was also diverted.
Softaculous says only a small number of Virtualizor installations likely received the malicious update, but it can’t identify every affected server because the diverted traffic never reached its logs. Compounding the problem, Virtualizor’s update mechanism didn’t cryptographically verify packages. Softaculous is urging all Virtualizor operators to check for compromise, reset passwords, review account activity, and regenerate API keys. The company has released Virtualizor 3.2.9.9 with mitigations and is implementing code signing for future packages.
A Texas healthcare provider suffers a data breach.
Texas-based healthcare provider Nutex Health says an unauthorized third party accessed and stole sensitive information from its systems and has threatened to publish it online. The compromised data includes patient and employee information, provider credentials, and confidential business and financial records.
Nutex first disclosed unauthorized network activity on August 24 and says it’s still determining the full scope of the breach. The company plans to notify affected patients and says it has seen no material impact on operations or financial reporting so far. A class action lawsuit has already been filed on behalf of people whose personal or protected health information was compromised.
The Gentlemen ransomware group has reportedly claimed responsibility. The ransomware-as-a-service operation has expanded rapidly in 2026, with healthcare accounting for about nine percent of its known victims.
A Russian national stands accused of infecting thousands of freelancers with remote-access malware.
A federal grand jury in California has indicted Russian national Searzhudin Aktulaev for allegedly running a phishing campaign that infected thousands of freelancers with remote-access malware. Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States.
Prosecutors say that between 2016 and 2017, Aktulaev created 255 fake accounts on an unnamed freelance employment platform and sent malicious Excel attachments to roughly 80,000 users. The files allegedly installed TVRAT or DarkVNC malware, giving attackers remote control of infected systems and allowing them to steal personal information and e-commerce credentials. Thousands of compromised computers reportedly connected to a U.S.-hosted command-and-control server, with about half of the victims located in the United States. Aktulaev remains in federal custody and is scheduled to appear in court October 5.
AI threatens the government’s bug supply.
AI may be getting good enough at finding software vulnerabilities to create an unusual problem for governments: making their targets harder to hack. Cryptography professor Matthew Green argues that as AI helps companies find and patch bugs at scale, the zero-days used by law enforcement and intelligence agencies could become scarce. That could upset an uneasy compromise in which governments buy exploits rather than demand encryption backdoors.
Researchers are divided. Some expect today’s “gold rush of bugs” to fade as AI gives defenders the advantage, potentially renewing government pressure for exceptional access. Others say sophisticated vulnerabilities will remain plentiful, with AI helping offensive researchers find them too. And AI-generated code may introduce fresh bugs faster than defenders can patch them.
So the future could feature fewer vulnerabilities, more vulnerabilities, or simply different vulnerabilities. Cybersecurity, apparently, remains stubbornly resistant to making anyone’s predictions easy.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

