Skip to content

Confidential ยท 07 Sep 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-09-07 (Monday)

Window: last 24โ€“48h (Sep 6โ€“7). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level GUARDEDVictims L30D 85Top actor QilinM&A L30D $94.5M

Number of the day153 million โ€” US and Canadian driver's license scans (front and back, plus infrared and UV images) now on the dark web, traced by Brian Krebs to New Orleans-based identity-verification provider IDScan.net; the FBI has opened an investigation; the breach is the largest documented identity-document exposure in US history and provides attackers with biometric-quality imagery for a substantial fraction of the US driving population. Krebs on Security ยท SecurityWeek

๐Ÿ’ผ M&A ACTIVITY

No new September cybersecurity M&A deals confirmed in the Sep 6โ€“7 windowMediumCybersecuritypost-Labor Day quiet; no announcements tracked via SecurityWeek or Return on Security. The SecurityWeek August roundup is expected this week and may surface additional late-August deals. mWISE (Sep 15โ€“17, Atlanta) remains the next likely announcement cluster.
L30D summary (Aug 7 โ€“ Sep 7): 15 deals tracked in August 2026, including three added today. Disclosed-value highlights: Visa โ†’ BioCatch $2.4B (behavioural biometrics); Munich Re โ†’ At-Bay $575M (cyber insurtech / SME MDR); Zenity $125M Series C (AI agent governance); Obsidian Security $100M+ Series D (SSPM/identity); CyberCatch $94.5M all-cash (compliance AI); Oligo Security $60M Series C (AI application security). Consolidation themes: cyber insurance (Munich Re/At-Bay; AXA XL โ†’ S-RM); AI security platform (Fortinet โ†’ Virtue AI). No confirmed September deals yet. SecurityWeek M&A Tracker ยท Pinpoint Search Group August Brief

โš ๏ธ CRITICAL BREACHES & INCIDENTS

IDScan.net / Unknown โ€” 153M+ driver's license scans (US/Canada) on dark web; FBI investigation opened; Nexus marketplace went dark after Krebs reportCriticalTechnology & SoftwareA dark web marketplace called Nexus offered front-and-back scans, infrared, and ultraviolet imagery of 153M+ US and Canadian driver's licenses, timestamps aligned with travel and car-rental activity for the images' subjects. Brian Krebs traced the data to IDScan.net, a New Orleans-based identity-verification provider whose clients include Hertz, Target, FedEx, Motorola Solutions, and Caesars Entertainment. The seller claimed ongoing breach access for over a year, meaning new scans may still be added. The FBI's New Orleans field office opened an investigation; the Nexus site vanished hours after Krebs published. Class action filings are already being filed. Krebs on Security ยท SecurityWeek ยท Malwarebytes
Berlin Senate / Rhysida โ€” 5.8 TB / 1.44M government files published Sep 4; critical infrastructure blueprints, police data, and federal defense plans now on the dark web; Sep 20 state election 13 days outCriticalGovernment & Public SectorRhysida's 7-day auction countdown ended ~15:35 local time Sep 4 after the Berlin Senate refused its 30 BTC (~EUR 2M) demand. The published dataset includes blueprints for Berlin's water and power grid infrastructure, police and LKA files, Bundeswehr documents, CBRN threat assessments, federal communication plans for a state of defense, and 12,000+ personnel records. Researchers confirmed critical infrastructure plans are in the dump. Berlin's interior administration has maintained that election-infrastructure systems are unaffected. ๐ŸŸฉ Data dump confirmed by independent researchers; the files are circulating on dark web mirrors. Cybernews ยท BankInfoSecurity
McKesson / ShinyHunters โ€” Sep 9 publication deadline 2 days out; no resolution signal; 284M-record publication would be the largest US healthcare breach notification event of 2026HighHealthcare & Life SciencesAs of Sep 7, McKesson has made no public statement on payment or resolution. ShinyHunters' Sep 9 data-publication deadline is the operative threshold. The Sep 1 contact deadline passed without McKesson public engagement. ๐ŸŸฅ The 284M-record count is ShinyHunters' own characterisation; unique-individual figure unverified. A publication triggers OCR breach investigation, state AG enforcement, class actions across multiple jurisdictions, and Senate Commerce Committee scrutiny. SecurityWeek ยท CyberScoop
Boston Scientific โ€” Day 13 of recovery; no new adverse network activity; Cork manufacturing remains at reduced capacityMediumHealthcare & Life SciencesIndustrials & ManufacturingNo material change since Sep 6. Distribution shipping restored at major global centres; Cork site partially restored. CrowdStrike and third-party experts leading investigation confirm no new intrusion activity since Aug 25. Piper Sandler mid-September full-restoration estimate unchanged. ๐ŸŸฅ Threat actor and attack vector not publicly disclosed. Boston Scientific ยท SecurityWeek

๐Ÿ”“ CRITICAL VULNERABILITIES

MikroTrik CVE-2026-67276 (CVSS 9.2) + CVE-2026-86060 โ€” SSH auth bypass to full admin control; active exploitation since Sep 2; 4 days since patches shippedHighTechnology & SoftwareCERT Polska confirmed exploitation by at least one threat actor (originating IP 82.192.72.4) as early as Sep 2, creating rogue SSH user accounts ("ops", "0") on reachable devices. The chain: CVE-2026-67276 (RouterOS does not compare the full RSA public key modulus โ€” an attacker who knows a valid username can craft a synthetic public key and authenticate without the private key); CVE-2026-86060 then escalates to full administrative privileges. Patches shipped Sep 3 across all RouterOS release channels โ€” 6.49.21 (long-term), 7.23.4 (long-term), 7.24.2 (stable), 7.25 beta3. CISA has not yet added CVE-2026-67276 to KEV as of Sep 7. All MikroTik devices with SSH exposed to the internet should be treated as potentially compromised โ€” check for unexpected user accounts before applying patches. CERT Polska ยท MikroTik Advisory ยท SecurityAffairs
Chrome CVE-2026-85046 (CVSS 8.8) โ€” V8 type confusion zero-day; sixth Chrome zero-day of 2026; CISA KEV Sep 4; FCEB deadline Sep 18HighTechnology & SoftwareA type confusion bug in Chrome's V8 JavaScript engine allows remote code execution inside the sandbox via a crafted HTML page (phishing link, malicious ad, or compromised legitimate site). Full OS compromise requires an additional sandbox-escape; however, CVE-2026-85046 alone provides reliable heap read/write primitives. Reported by Salvatore Gulizia on Aug 4 and patched in Chrome 152.0.7977.82/.83 (Windows/macOS) and 152.0.7977.82 (Linux). Added to CISA KEV Sep 4 with FCEB deadline Sep 18. Enterprise IT teams should audit Chrome update policy; managed fleets often lag stable releases by days when the zero-day is already exploited. The Hacker News ยท Help Net Security ยท BleepingComputer

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

CISA KEV โ€” seven new entries Sep 2; SonicWall SMA1000 SSRF (CVSS 10.0) and command injection chain; federal deadline Sep 5 passedHighGovernment & Public SectorThe Sep 2 batch added CVE-2026-83548 (SonicWall SMA1000 SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection, CVSS 7.8) โ€” chainable to unauthenticated RCE โ€” alongside CVE-2026-9586 (Sangoma Switchvox SQL injection, CVSS 9.3), CVE-2026-82329 (JFrog Artifactory improper authentication), CVE-2026-48710 (Kludex Starlette HTTP smuggling), CVE-2026-49869 (Kestra OS command injection), and CVE-2026-59822 (BerriAI LiteLLM improper authentication). FCEB agencies had until Sep 5 to patch all seven. Non-federal organisations running SonicWall SMA1000 on 12.4.3 or 12.5.0 builds (models 6210, 7210, 8200v) should treat patch application as urgent โ€” public PoC and in-wild exploitation confirmed before the KEV addition. CISA KEV ยท The Hacker News ยท Rapid7
Citrix NetScaler CVE-2026-19490 โ€” BOD 26-04 federal deadline Sep 9 (same as McKesson watch date); exploited in wildMediumTechnology & SoftwareFederal civilian agencies must have patches applied by Sep 9. Non-federal operators of NetScaler ADC and Gateway (AAA virtual servers, SSL VPN, ICA Proxy, CVPN, RDP Proxy) should follow the same urgency โ€” unauthenticated auth bypass with active exploitation since Sep 4 PoC publication. BleepingComputer

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Rhysida โ€” Berlin data dump confirmed; shift from extortion actor to strategic disruptorCriticalGovernment & Public SectorWith 1.44M files now publicly available, Rhysida has completed the full extortion-and-publish cycle against a NATO-member capital government. The dataset's content (critical infrastructure blueprints, federal defense communication plans, CBRN assessments) makes this more than a data-theft event โ€” the material is now freely accessible to any state actor or criminal operator interested in Berlin's infrastructure vulnerabilities. The group has demonstrated willingness to publish even when the ransom is structurally certain to be rejected (government non-payment policy). Cybernews
Qilin โ€” rank 1 sustained; YTD 546; no new high-profile confirmed victims in Sep 6โ€“7 window; Sep 9 McKesson watch (ShinyHunters) remains the week's operative deadlineHighGovernment & Public SectorQilin DLS continues active postings without a single named critical-infrastructure or government victim in the immediate window. YTD trajectory: 546 claims across 103 countries. The ATF major-incident claim (Aug 26) remains under DOJ investigation. ๐ŸŸฅ ATF claim unverified. Ransomware.live
MikroTrik exploitation โ€” network infrastructure globally; state actor early adoption window is openHighTechnology & SoftwareThe CVE-2026-67276 chain gives unauthenticated remote attackers admin control of hundreds of thousands of MikroTik routers with internet-facing SSH. MikroTik devices are heavily deployed in ISPs, enterprise branch offices, and CNI environments across Central/Eastern Europe, Latin America, and South/Southeast Asia. The four-day window between active exploitation (Sep 2) and patch availability (Sep 3) allowed initial-access brokers and state actors to build a foothold in network infrastructure. Devices patched post-Sep 2 should be inspected for rogue accounts before trusting patch validity. CERT Polska ยท AiCybr

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Rhysida's publication of Berlin's critical infrastructure blueprints โ€” water grid, power systems, CBRN assessments, federal defense plans โ€” is not a ransomware incident that resolved; it is a permanent intelligence windfall for any state actor with an interest in Germany's capital.CriticalGovernment & Public SectorThe published files are now indexed, mirrored, and searchable. Every hostile foreign intelligence service with an interest in European capital-city infrastructure now has, at zero cost, operational intelligence that Berlin spent years securing. The thirteen-days-before-election timing is secondary to the strategic consequence: Bundeswehr documents and federal state-of-defense communication plans in a publicly accessible dark-web archive represent a national-security loss that cannot be remediated by patching. Germany's BSI and the BfV will need to assess which of the 12,076 named individuals are in sensitive roles and whether the infrastructure blueprints have been acted on before the data's publication became public knowledge. Cybernews ยท BankInfoSecurity
The IDScan.net breach is structurally different from a credential or PII leak: it places biometric-quality identity documentation for 153 million North Americans in criminal and state-actor hands, and it may have been ongoing for over a year before discovery.CriticalFinancial ServicesGovernment & Public SectorDriver's license images with infrared and UV scans are the exact materials used by government border agencies and financial institutions for identity verification. A state actor possessing this dataset can fabricate credentialed personas at scale, defeating document-based identity assurance in travel, financial services, and physical access systems. The breach's undiscovered duration โ€” the seller claimed ongoing access for "over a year" โ€” means the complete scope is unknown. The FBI investigation is the operative response action; until IDScan.net confirms the breach's full timeline and current access status, its verification pipeline should be treated as untrusted by clients. Krebs on Security ยท CSO Online
The MikroTrik exploitation window illustrates the structural problem with network-edge device security: a zero-day in widely deployed ISP and enterprise routing equipment is exploited by unknown actors for the one day before patches ship, and the patch itself cannot undo initial-access already established.HighTechnology & SoftwareMikroTik's global install base spans CNI, ISP, and enterprise environments disproportionately in regions where security operations are under-resourced โ€” Eastern Europe, Central Asia, Southeast Asia, Latin America. A threat actor with pre-positioned access in ISP routing infrastructure has persistent visibility into network traffic flows and can intercept or manipulate traffic at the carrier level. The one-day exploitation window before MikroTik patched (Sep 2 exploitation observed; Sep 3 patches released) is the operative risk horizon; any device that was internet-accessible on Sep 2 should be assumed compromised until inspected. CERT Polska
Munich Re's $575M acquisition of At-Bay and AXA XL's full acquisition of S-RM in the same August window signal that global (re)insurance capital is now pricing cybersecurity consultancy and MDR capability as core insurance infrastructure, not add-on advisory.HighFinancial ServicesCybersecurityBoth deals move insurers from passive underwriting into active prevention and response. At-Bay's MDR+insurance hybrid model has been validated at SME scale; Munich Re's HSB integration extends it to their specialty insurance book. AXA XL's S-RM integration (140-country incident response, geopolitical intelligence, integrity due diligence) gives an insurer direct forensics and threat-intelligence capacity. The structural signal for the PE/portfolio-holder: cyber insurance economics are shifting from claims-and-reserve models toward prevention-as-profit-center, and the acquirers are willing to pay platform multiples for consultancy capabilities that compress claim frequency. Munich Re PR ยท AXA XL PR
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”