Secret CISO 9/7: 153 Million Driver's Licenses Leaked, ATF Case Files Dumped, Magento's Unpatched Zero-Day, AI Agents Breach a Network in 10 Hours

153 million driver's licenses hit the dark web, Qilin dumps ATF case files, Magento's unpatched zero-day backdoors stores, and an AI agent breaches a network in under 10 hours.

Share
Secret CISO 9/7: 153 Million Driver's Licenses Leaked, ATF Case Files Dumped, Magento's Unpatched Zero-Day, AI Agents Breach a Network in 10 Hours

Welcome to today's edition of Secret CISO, where the line between physical identity and digital exposure got a lot blurrier this week. We start with what may be the largest identity-document leak on record: over 153 million U.S. and Canadian driver's licenses turned up for sale on a Russian cybercrime forum, apparently siphoned from an identity-verification vendor used for everything from car rentals to dispensary check-ins.

From there we head to Washington, where the ATF discovered that even a standalone, disconnected system isn't safe from a determined ransomware crew. Qilin's leak of case files and phone extractions from open investigations is a reminder that segmentation buys time, not immunity.

Manchester Airports Group learns the same lesson the hard way, after an extortion group says exposed API credentials for a marketing platform opened the door to hundreds of gigabytes of traveler data. Meanwhile, a breach at a Thomson Reuters court-records platform has exposed Social Security numbers and even sealed filings across a dozen U.S. jurisdictions.

On the research side, Dutch investigators are sounding the alarm on StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day already backdooring fully patched online stores with no fix in sight. We also cover a new twist on the ClickFix social-engineering playbook, a signed Chinese adware app moonlighting as a backdoor, and a genuinely unsettling case study of a human attacker letting frontier AI agents run an entire network intrusion end to end.

Rounding things out, our Top CVEs section covers actively exploited flaws in Chrome, SonicWall, Kestra, and ASUS's enterprise management console, several of which are now sitting on CISA's Known Exploited Vulnerabilities catalog with tight remediation deadlines.

It's a dense one today, so let's get into it.

Data Breaches

  1. 153 Million Driver's Licenses Leaked to the Dark Web: A service advertised on the Russian cybercrime forum Exploit is selling scans of more than 153 million U.S. and Canadian driver's licenses, including one reportedly belonging to Defense Secretary Pete Hegseth, posted as a free sample to prove the data was real. The FBI's New Orleans field office is investigating, and researchers have traced the likely source to a live, ongoing breach at IDScan, a Louisiana-based identity-verification company used for age and ID checks. Source: Krebs on Security
  2. Qilin Ransomware Leaks ATF Investigation Files: The Qilin ransomware group dumped roughly 6.3GB of files stolen from a standalone ATF system after the agency missed a 72-hour ransom deadline, exposing case records and mobile-device extractions from open investigations into crimes like armed robbery, arson, and homicide. The ATF says the compromised system, tied to its CALEA communications-intercept function, was isolated from case-management and lab systems and was shut down once the intrusion was found. Source: Cybernews
  3. Manchester Airports Group Data Theft Bigger Than Disclosed: Extortion group FulcrumSec claims it stole 86GB (roughly 640GB uncompressed) of customer data from Manchester Airports Group, far more than the airport operator's initial disclosure of Wi-Fi registration and parking-booking data. The group told BleepingComputer it got in using airport-specific API credentials for a customer-engagement platform that were exposed in client-side JavaScript, and has since published the stolen files on its leak site. Source: BleepingComputer
  4. Thomson Reuters Court Software Breach Exposes SSNs and Sealed Records: An unauthorized party obtained files from C-Track, a court case-management platform run by Thomson Reuters' West Publishing unit, in an intrusion discovered in June and now confirmed to affect courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario. Minnesota's Judicial Branch says exposed data may include Social Security numbers, driver's license numbers, and medical information tied to its appellate courts, and has cut off Thomson Reuters' access while forcing password resets. Source: The Hacker News

Security Research

  1. StyleSmuggler: Unpatched Magento Zero-Day Backdoors Even Fully Patched Stores: Dutch e-commerce security firm Sansec disclosed an unauthenticated remote-code-execution flaw affecting every current version of Magento Open Source and Adobe Commerce, including the latest 2.4.9 release, with live attacks beginning the day before disclosure. The first known victim was running a fully patched install with July and August security updates applied, and as of publication Adobe has issued no advisory, CVE, or fix. Source: The Hacker News
  2. AI Agents Compress a Network Breach Into Under 10 Hours: Palo Alto Networks' Unit 42 detailed an incident where a human attacker used frontier AI models and purpose-built agentic frameworks to run an entire intrusion, from initial access through credential theft to lateral movement, compressing what would normally take skilled operators roughly two weeks into under 10 hours. Automated recon agents mapped internal microservices while sub-agents combed code repositories for hardcoded tokens, and Unit 42 notes the attack used no zero-days, only more than 50 well-documented MITRE ATT&CK techniques executed at machine speed. Source: Unit 42
  3. TerminalFix Evolves ClickFix Attacks Into Full Network Intrusions: Microsoft is tracking TerminalFix, a ClickFix variant that lures victims into pasting commands into Windows Terminal or PowerShell rather than the Run dialog, enabling more complex multi-stage payloads to execute reliably. The campaign chains DLL sideloading, steganographic delivery, and encrypted WebSocket traffic to install a custom reverse tunnel that performs deep network reconnaissance, probing for domain controllers, backup servers, and mail systems. Source: BleepingComputer
  4. ValleyRAT Backdoor Hides Inside Signed Chinese Adware: The Silver Fox threat group is bundling the ValleyRAT backdoor (also tracked as Winos 4.0) with a modified, digitally signed copy of QN Wallpaper, a legitimate Chinese desktop-wallpaper tool, using DLL sideloading to run inside a trusted, signed process. Once active, ValleyRAT can log keystrokes, capture screenshots, disable Windows Defender, and even trigger a blue screen if a user tries to kill its process, with targeting concentrated in China and India. Source: The Hacker News
  5. CISA Flags Seven Exploited Flaws Hitting AI and DevOps Infrastructure: CISA added seven actively exploited vulnerabilities to its KEV catalog affecting SonicWall, JFrog Artifactory, Sangoma Switchvox, Kestra, Starlette, and the LiteLLM AI gateway, with attackers using the flaws to deploy crypto miners, plant reverse shells, mint admin tokens, and harvest API keys. The mix underscores a growing pattern of attackers pivoting from traditional network appliances to the DevOps and AI infrastructure now sitting at the center of enterprise pipelines. Source: The Hacker News

Top CVEs

  1. CVE-2026-85046: A high-severity type-confusion bug in Chrome's V8 JavaScript engine allows attackers to achieve arbitrary code execution via a crafted HTML page. Google patched the flaw, which carries a CVSS score of 8.8, and CISA added it to its Known Exploited Vulnerabilities catalog on September 4, giving federal agencies until September 18 to patch. Source.
  2. CVE-2026-83548: A maximum-severity (CVSS 10.0) pre-authentication SSRF flaw in the SonicWall SMA1000 Work Place interface lets unauthenticated attackers reach privileged internal functions, and can be chained with the OS command-injection bug CVE-2026-83549 to achieve unauthenticated remote code execution with root access. Both flaws are confirmed under active exploitation and are on CISA's KEV catalog; SonicWall recommends upgrading to hotfix 12.4.3-03526, 12.5.0-02952, or later. Source.
  3. CVE-2026-49869: A critical OS command-injection vulnerability in Kestra OSS, an open-source workflow orchestration platform, carries a perfect CVSS score of 10.0 and lets an unauthenticated remote attacker create and execute arbitrary workflows without credentials. It is one of seven flaws CISA added to its KEV catalog this week amid active exploitation targeting DevOps and AI tooling. Source.
  4. CVE-2026-75754: A missing-authentication flaw in ASUS Control Center Enterprise, compounded by an SSRF bug that exposes the platform's encryption key, lets remote attackers gain full unauthenticated root control over the management console and every device it oversees. The flaw affects ACC version 4.0.0.2 and earlier and carries a maximum CVSS 4.0 score of 10.0; ASUS urges all users to update to v3.1.0.9 or later immediately. Source.

Final Words

If there's a thread running through today's edition, it's that scale and speed keep compounding against defenders. A single identity-verification vendor's breach can expose the credentials of 153 million people, including cabinet officials, in one shot. A single set of exposed API credentials can turn into a 640GB airport data heist. And a single attacker armed with off-the-shelf frontier AI can now do two weeks of skilled intrusion work before lunch.

None of this means the fundamentals have changed. Segment your networks, rotate and scope your API credentials tightly, and patch the things that are actually being exploited today, not just the ones that made headlines last month. The ASUS, SonicWall, and Kestra flaws in this edition are all live, all serious, and all fixable right now.

If Secret CISO has been useful to you, the best thing you can do is forward today's edition to a colleague who needs it in their inbox tomorrow morning.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!