Saturday, September 5, 2026

Saturday Security: 153 Million Driver's Licenses on the Dark Web

 


This week's Saturday Security Story is one of the most personally alarming stories of the year — because unlike a password, you can't change your driver's license. A dark web service called Nexus reportedly offered scans of more than 153 million U.S. and Canadian driver's licenses alongside millions of other identity documents. Investigative reporter Brian Krebs uncovered evidence linking the data to ID Scan Net — an identity verification provider serving thousands of businesses across North America. What makes this story especially disturbing is the detail level. This wasn't just names and numbers. Records reportedly include: Front and back scans of licenses Infrared and ultraviolet images Photos of the license holder Timestamps matching real-world events — including a mother and son whose licenses appeared in the data just seconds apart after renting a car That timestamp detail is chilling. It means the data wasn't just stolen in bulk — it was captured at the moment people handed over their IDs in everyday transactions. The FBI is now investigating the suspected ID Scan Net breach. Nexus has already disappeared from the dark web — which typically means either law enforcement action or the operators went underground. This week's big takeaway: Identity data is an attack surface — and the most dangerous kind. You can reset a compromised password in seconds. You cannot change your face, your fingerprints, or your driver's license number. Once physical identity data is out there, it's out there permanently. https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/ 🗓️ Week ending September 5th, 2026 👤 Hosted by Peter 00:00:00 - Intro: Your Driver's License Is Your New Password 00:00:34 - The Timestamp Detail That Changes Everything 00:01:09 - FBI Investigation & Nexus Disappears 00:01:21 - Takeaway: You Can't Change Your Face 00:01:39 - Sign-Off & Stay Secure

Saturday, August 29, 2026

Saturday Security: 700 AI Agents Working Together to Coordinate a Cyberattack

 


This week's Saturday Security Story takes us somewhere new — and it's worth paying close attention. Details are emerging from an attack on Hugging Face — one of the world's most important AI platforms — in which roughly 700 AI agents reportedly collaborated during the breach. These agents were sharing information, discovering vulnerabilities, escalating access, and collectively accomplishing things that individual agents likely could not have done alone. Before the doom headlines take over — let's get some perspective. What's possible isn't always probable. We've heard predictions for years that AI would trigger an explosion in breaches and zero-day exploits — and so far those trends haven't dramatically shifted. The sky has not fallen. But here's what is genuinely new about this incident: AI agents coordinating, dividing tasks, and amplifying each other's capabilities. That's a meaningful evolution from a single powerful model acting alone. This is less about one superintelligent attacker and more about a team of machines working together — like a well-organized threat group, but operating at machine speed and scale. This week's big takeaway: Don't panic — but don't ignore it either. AI in cybersecurity may be shifting from individual powerful models toward entire coordinated teams of agents operating on both the offensive and defensive sides. The arms race just got more interesting. https://www.darkreading.com/cyberattacks-data-breaches/hundreds-openai-agents-invaded-hugging-face-servers https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/#cryptographically-signing-messages 🗓️ Week ending August 29th, 2026 👤 Hosted by Peter 00:00:00 - Intro: 700 AI Agents Coordinated an Attack on Hugging Face 00:00:32 - Perspective — Possible vs Probable 00:01:01 - The Real Takeaway — AI Teams Not Just AI Models 00:01:24 - Sign-Off & Stay Secure

Saturday, August 22, 2026

Saturday Security: Cl0p Ransomware Hits 40+ Companies Through One Vulnerability

 


Your Software Is Your Attack Surface!

This week's Saturday Security Story highlights a growing supply-chain risk: the software your organization relies on can become an attacker’s pathway to your most valuable data.

The Cl0p ransomware group claims to have targeted more than 40 organizations by exploiting CVE-2026-12569, a critical vulnerability in PTC Windchill and FlexPLM product lifecycle management platforms.

The vulnerability reportedly allowed unauthenticated remote code execution and access to sensitive engineering data, with alleged victims including Shell, Philips, GE and Fiserv.

The bigger lesson? Attackers don't necessarily need to breach dozens of companies individually. One vulnerability in widely deployed enterprise software can potentially provide access to many organizations at once.

Third-party software isn't just vendor risk. It's part of your attack surface.

I'm Peter, and that's your Saturday Security Story. Like, subscribe and stay secure!

https://cybermagazine.com/news/plm-zero-day-flaw-exploited-by-clop-in-massive-data-breach

https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/

Saturday, August 15, 2026

Saturday Security: Evil Twin Attack at 30,000 Feet with Fake Wi-Fi on a Delta Flight

 


This week's Saturday Security Story takes us 30,000 feet in the air — and it's a fascinating one. A fake Wi-Fi network appeared on a Delta flight from Las Vegas to Atlanta — and not just any flight. This was a plane leaving the notorious Black Hat conference and DEF CON — two of the world's biggest cybersecurity events. If you're going to pull a stunt like this, that's quite an audience to pick. A passenger had created a network impersonating Delta's onboard Wi-Fi, prompting the airline to shut down legitimate onboard Wi-Fi for approximately 30 minutes while the situation was addressed. The good news: Delta confirmed no aircraft systems or flight safety systems were affected and there was no actual breach of Delta's own infrastructure. But here's why it matters — this is a classic Evil Twin Attack. A fake access point deliberately named to mimic a trusted network — designed to trick unsuspecting users into connecting and potentially exposing their passwords, browsing data, and personal information to whoever controls the rogue hotspot. This week's big takeaway: Never automatically trust the Wi-Fi name you see. Verify the network before you connect — especially in airports, hotels, conference centers, and yes — at 30,000 feet. https://www.theregister.com/security/2026/08/11/def-con-dingus-suspected-of-trying-to-take-over-delta-in-flight-wi-fi/5286331 🗓️ Week ending August 15th, 2026 👤 Hosted by Peter


Saturday, August 8, 2026

Saturday Security: Brinks Breach May Be Just the Beginning

 


This week's Saturday Security Story is a reminder that sometimes the biggest threat after a breach is the attack that comes next. Brinks — yes, the iconic security company — has confirmed unauthorized access to part of its IT systems, saying it quickly activated its incident response process. The good news: alarm monitoring and security systems continued operating normally throughout the incident. The Shiny Hunters group — covered multiple times on this channel — has claimed responsibility, alleging they stole millions of customer and employee records. Brinks has not yet confirmed exactly what information was taken or who may be affected. That uncertainty is itself part of the problem. Brinks is now warning customers to watch for follow-up phishing emails, texts, and phone calls designed to exploit the breach — using stolen personal information to make fraudulent contact appear legitimate. This week's big takeaway: The breach doesn't end when the attackers leave. Stolen data becomes ammunition for the next attack — and the victims of the initial breach become the targets of everything that follows. Stay vigilant. https://brinkshome.com/cybersecurity-update https://www.safestate.com/post/brinks-home-data-breach-confirmed-as-shinyhunters-threatens-leak 🗓️ Week ending August 8th, 2026 👤 Hosted by Peter

Saturday, August 1, 2026

Saturday Security: FBI & EPA Warn Attackers Targeting US Water Systems

 


This week's Saturday Security Story is a sobering reminder that America's water infrastructure remains a prime cyber target. The FBI and EPA are jointly warning that cyber attacks have now been reported at municipal water systems across at least seven states. Iran-linked hackers are the leading suspects in attacks affecting more than 30 Minnesota utilities — though the investigation remains ongoing. The attack method was straightforward but effective: attackers targeted internet-connected industrial control systems (ICS), changing passwords and locking operators out of remote monitoring. The good news — no evidence of drinking water contamination has been found. The bad news — that almost misses the point entirely. This week's big takeaway: Critical infrastructure doesn't have to be physically destroyed to cause serious disruption. Simply forcing utility operators into manual operations creates real-world consequences — slower response times, increased risk of human error, and cascading operational failures. If your OT (Operational Technology) systems are exposed to the internet right now, securing them cannot wait. https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210 🗓️ Week ending August 1st, 2026 — Welcome to August! 👤 Hosted by Peter 00:00:00 - Intro: America's Water Infrastructure Under Attack 00:00:27 - How the Attack Worked — Locked Out of Remote Monitoring 00:00:45 - No Contamination But Real Disruption 00:01:01 - Takeaway: Secure Your OT Systems Now 00:01:01 - Sign-Off & Welcome to August 2026

Saturday, July 25, 2026

Saturday Security: Hugging Face Breached by Autonomous Agent

 



Hugging Face — the world's largest AI model repository — has disclosed that an autonomous AI agent breached its production environment. The attack unfolded by uploading a malicious dataset that exploited code execution flaws, stole credentials, and then moved laterally through internal systems — performing thousands of automated actions without any human attacker behind the keyboard. The good news: there was no evidence that public AI models were modified — which would have been a catastrophic supply chain scenario affecting potentially millions of downstream users. This week's big takeaway: When your platform is designed to execute user-supplied AI models or datasets, that execution environment becomes your attack surface. Every upload should be treated as potentially hostile. Isolate your credentials. Build your sandboxes like your business depends on them. Because it does. https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html 🗓️ Week ending July 25th, 2026 👤 Hosted by Peter 00:00:00 - Intro: When the Attacker Is Another AI 00:00:27 - How the Autonomous Agent Moved Through Systems 00:00:45 - Takeaway: Every Upload Is Hostile 00:00:59 - Sign-Off