DMV Breach Confirmed, Cisco ISE Patched, Revolut Data Scam
Quick Answer
The latest cybersecurity news includes a Florida DMV breach, Cisco ISE attacks, Revolut data exposure, passkey phishing, ransomware activity, and cloud credential theft, highlighting the need for stronger cybersecurity and email security.
Last week saw a wave of high-impact incidents, from a confirmed nation-state-style breach of Florida’s driver database to a maximum-severity Cisco zero-day being exploited in the wild, a fintech data leak traced to compromised Italian government email accounts, and a foiled Russian plot against undersea internet cables. Phishing gangs also kept up the pressure, abusing everything from Microsoft passkeys to fake voicemail transcripts, while regulators pushed hard on AI governance and passwordless authentication. Here’s a roundup of the week’s biggest cybersecurity stories.
Florida’s DMV database breach confirmed after ShinyHunters extortion threat
Florida’s Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver and vehicle database was breached, after weeks of claims from the ShinyHunters extortion group. The agency said it learned of the breach on September 4 and that it was quickly mitigated with no further breach ongoing. Investigators determined the attacker used compromised credentials belonging to a Plant City Police Department user that had been improperly stored on a personal device.
ShinyHunters told BleepingComputer it exploited a password-reset flaw to compromise several accounts, including ones belonging to DMV employees and an FBI agent, then iterated through record IDs to download driver files, stealing over 200,000 records. The group later posted a leaked record for Jeffrey Epstein as proof of the intrusion. BleepingComputer
Cisco patches maximum-severity ISE zero-day already under attack
Cisco issued emergency patches for a perfect 10.0-severity flaw in its Identity Services Engine (ISE) and ISE-PIC products after confirming active exploitation. The bug, tracked as CVE-2026-76460, lets an unauthenticated remote attacker send a crafted request to an API endpoint and bypass the web-based management interface entirely. Because there are no workarounds, patching is the only mitigation, according to Cisco’s security team.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal civilian agencies until September 19 to patch. Since ISE typically governs network access decisions across an entire organization, a compromise could ripple far beyond a single device. The Hacker News
Revolut hands customer data to scammers posing as Italian officials
Fintech giant Revolut confirmed disclosing sensitive customer information to fraudsters after receiving data requests from what appeared to be a legitimate government email account. Exposed data included contact details, birth dates, occupations, and identity documents, with reports suggesting verification selfies, transaction histories, IBANs, and Bitcoin activity were also affected.
Hackers later told the Financial Times they compromised an Italian government email system and exchanged messages with Revolut for several months while posing as law enforcement, using blockchain analysis to select roughly 680 targets with significant crypto holdings. The attackers are reportedly demanding 10,000 Bitcoin, worth roughly $782 million, and have threatened to leak more data daily if Revolut doesn’t pay. Irish Times
NATO allies foil Russian plot to sabotage undersea cables near Svalbard
NATO disrupted a Russian military exercise that reportedly involved technology designed to damage critical undersea communications cables while leaving little forensic evidence behind. The operation, which involved Russia’s specialist deep-sea unit, was stopped before any cables were damaged, and the targeted area included two 1,400km fibre-optic cables connecting Svalbard with mainland Norway.
The incident is a stark reminder of how much international data traffic rides on physical undersea infrastructure — and how hard it can be to prove who’s responsible when it’s attacked. TechRadar Blackarrowcyber
Microsoft warns of passkey-themed phishing draining Microsoft 365 accounts
Microsoft disclosed that extortion groups are using convincing passkey, MFA, and single sign-on–themed phishing to compromise corporate accounts. Attackers impersonate IT support, often calling or texting employees before directing them to fake or manipulated authentication flows; once inside, they explore Microsoft 365 environments, steal files from SharePoint and OneDrive, and register their own authentication methods to maintain access.
Microsoft recommends phishing-resistant MFA, restricting sensitive cloud resources to managed devices, and disabling unnecessary device-code authentication. BleepingComputer Blackarrowcyber
IDScan.net confirms breach behind 153 million leaked driver’s licenses
Separately from the Florida incident, ID-verification vendor IDScan.net confirmed a breach tied to a dark-web listing of more than 153 million scanned driver’s licenses from the US and Canada, first flagged by Krebs on Security. The exposure is now the subject of an FBI probe and multiple lawsuits, underscoring how permanent this kind of leak is for victims — unlike a password, a face or a driver’s license number can’t simply be reset. Help Net Security
UK government begins retiring passwords for 23 million citizens
The UK rolled out passkey sign-in across GOV.UK One Login, covering tax, childcare support, and State Pension services. More than 23 million Brits can now use a face scan, fingerprint, or PIN instead of a password, following a trial in which over 300,000 people switched over, and almost one in ten daily sign-ins are already using passkeys.
Officials note passkeys are phishing-resistant since credentials are tied to a specific website and can’t leak the way passwords can in a data breach — though for now, the option only supplements passwords rather than replacing them outright. Cybernews cybernewsprivacyguides
Sandworm chains Cisco flaws to deploy Cyclops Blink malware
The Russian state-linked group known as Sandworm has been observed chaining multiple Cisco vulnerabilities to deploy its Cyclops Blink malware, a tool historically used to build resilient botnets out of compromised network edge devices. The activity fits a broader pattern this year of state-backed actors targeting internet-facing routers and firewalls to gain durable footholds inside networks. Dark Reading
China-linked hackers exploit Chrome-Windows zero-day chain to deploy GRIMWEDGE
Researchers uncovered a Chinese state-linked espionage campaign chaining a Chrome and Windows zero-day exploit to deploy new malware dubbed GRIMWEDGE. The same exploit chain appears to have powered two separate espionage operations, highlighting how a single high-value vulnerability chain can be shared or independently discovered by multiple threat clusters. The Hacker News
Trezor users targeted by phishing after marketing vendor Brevo is breached
Hardware wallet maker Trezor warned that roughly 347,000 of its users were targeted in phishing attacks following a breach at Brevo, a third-party email marketing platform Trezor used. The incident is a reminder that a company’s own security posture doesn’t matter much if a vendor holding its customer contact list gets compromised. BleepingComputer
This week’s cyberattacks highlight why strong email security with SPF, DKIM, and DMARC is essential for preventing phishing and data breaches.
Almost 8,000 organizations hit by fake voicemail transcript phishing campaign
A large-scale credential-phishing campaign disguised as voicemail transcript notifications has hit close to 8,000 organizations. The emails mimic legitimate voicemail-to-text alerts from business phone systems, luring recipients into entering their credentials on a fake login page — a tactic that continues to succeed because it exploits routine, low-suspicion notifications employees see every day. TechRadar
Surfshark VPN says hackers breached internal testing and proxy servers
VPN provider Surfshark disclosed that attackers breached some of its internal testing and proxy infrastructure. The company said the affected systems were separate from its production VPN service, but the incident adds to a string of breaches this year affecting privacy and security vendors themselves. BleepingComputer
Twitch data leak claim exposes 40,000 streamers
A threat actor claimed to have leaked data belonging to roughly 40,000 Twitch streamers. Separately, a malicious Twitch-related browser extension was found leaking OAuth tokens from nearly 31,000 users, giving attackers a way to hijack accounts without ever touching Twitch’s own servers directly. Cybernews

Swiss court sentences Ukrainian ransomware developer to nearly 13 years
A Swiss court sentenced a 52-year-old Ukrainian national to almost 13 years in prison for his role developing ransomware used in attacks against multiple victims. In a separate case, a Conti ransomware crew member was sentenced to four years in prison, part of a steady drumbeat of law-enforcement action against ransomware developers this year. The Register
LiteSpeed Enterprise flaw could let one hosting account seize a shared server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user escalate to root access on a shared-hosting server, cPanel warned. Because shared hosting environments run many unrelated customer sites on the same machine, a flaw like this could let one compromised or malicious tenant take over every other site on the box. Security Affairs
Mass-scanning campaign exploits Vite flaw to steal cloud credentials
Researchers at F5 Labs disclosed an automated, mass-scanning campaign targeting internet-exposed Vite development servers, designed to steal AWS and Azure cloud credentials, configuration files, and infrastructure state files. The campaign is a reminder that developer tools left accidentally exposed to the internet remain one of the easiest ways for attackers to reach an organization’s cloud environment. The Hacker News
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.
LinkedIn Profile →