Security
153M Driver’s Licenses Leaked in IDScan.net Breach
A dark web service exposed 153M driver’s licenses, possibly via IDScan.net. Also: OpenAI’s Astra hits critical cyber tier, Dropbox breach, ICE AI deal.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Dark Web Service Offers 153 Million Driver’s Licenses, FBI Probes IDScan.net Link
A dark web identity theft service called Nexus is advertising more than 153 million U.S. and Canadian driver’s license scans, plus over 10 million other ID cards, 3 million travel documents, and hundreds of thousands of medical cards. The FBI’s New Orleans field office is investigating. The database reportedly includes scans belonging to security researcher Brian Krebs and U.S. Defense Secretary Pete Hegseth, with front, back, and sometimes infrared and ultraviolet images of each license.
Researcher Brian Krebs traced the apparent source to IDScan.net, a New Orleans identity verification firm processing over 21 million checks monthly at more than 20,000 locations. IDScan.net says it is investigating but has not confirmed the breach. The Nexus site disappeared shortly after the report, replaced by a message saying the service was no longer available. Experts argue the incident shows the systemic risk of mass KYC data collection, urging technical fixes like zero-knowledge proofs and regulatory changes to reduce data hoarding.
Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof →
OpenAI’s Astra Becomes First Model Rated ‘Critical’ for Hacking Skills
OpenAI said Sept. 1 that its unreleased Astra model meets the Critical tier of its Preparedness Framework for cybersecurity, the first model ever classified that high. Astra scored a perfect 100% on ExploitBench, turning known vulnerabilities into working exploits, and beat earlier models on a second test using 20 high-severity flaws in Google’s V8 engine. In hands-on tests, Astra broke out of a browser sandbox and escalated from an ordinary user account to root on a hardened OS.
OpenAI says Astra refuses 91.5% of cyber jailbreak attempts, up from 59% for GPT-5.6 Sol. Access will start with a small group of alpha testers, with wider rollout through OpenAI’s Daybreak Blue defensive program. Development was paused days earlier as skills advanced quickly, but prediction markets give 72% odds of a public release by Sept. 30. OpenAI has not set a launch date.
OpenAI’s Astra Becomes Its First AI Model With ‘Critical’ Hacking Abilities →
Dropbox Breach Hits 5,000 Accounts via Lenovo ID Integration Flaw
Dropbox reported that roughly 5,000 accounts were compromised between Aug. 4 and 21 through a legacy Lenovo ID integration. The flaw let someone register a Lenovo ID with another person’s email and authenticate without a password because email ownership was not properly verified. Files were viewed or downloaded in fewer than a third of affected accounts, and every compromised account lacked multi-factor authentication.
Dropbox terminated all sessions authenticated through Lenovo ID, disabled the integration, and now requires a native Dropbox password. Affected users were emailed Monday, and both companies have reported the incident to data protection regulators. For European users, GDPR notification obligations apply, including the 72-hour deadline. Dropbox shares fell about 2.4% in extended trading. The access was uncovered through a post-incident investigation, not live monitoring.
Dropbox says 5,000 accounts were breached through a Lenovo login →
ICE Pays ZeroFox $15M to Hide Agent Identities, Raising Whistleblower Concerns
U.S. Immigration and Customs Enforcement is launching a Doxing Mitigation Initiative using AI firm ZeroFox to help personnel keep identities hidden, according to an internal memo leaked to The Intercept. The Department of Homeland Security entered a $15 million contract with ZeroFox in July for software licenses supporting ICE operations. ZeroFox develops AI-driven software to stop data leaks across social media and the dark web.
ICE officials expressed concern the tech could be used to identify whistleblowers and critics. ZeroFox previously classified peaceful BLM protest organizers as physical threats in Baltimore and struggled with FBI use after Jan. 6. Richard Forno of UMBC said the tech could be used to set up honey pots to find leakers. EFF’s Sophia Cope warned that shielding officers from public accountability, especially when information is already public, flies in the face of democratic values.
ICE Is Paying a Controversial AI Firm to Hide the Identities of Agents →
Researchers Trick Fortune-500 AI Agents Into Running Arbitrary Code
Researchers demonstrated that AI agents at Fortune-500 companies can be easily tricked into running arbitrary code through a supply-chain attack using an llms.txt guidance file. The attack illustrates how data has become code in modern AI systems. The full article is behind a paywall, and no further technical details are available.