2026.09.08 News You Should Know

- 6 mins read

Series: News You Should Know 2026

Errata

I rented a car, and within hours, my driver’s license was for sale - Ars Technica -  I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver’s license, a high-resolution scan of my ID was available for sale on the dark web.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security - Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters - ASCII Smuggling refers to a technique where invisible or non-rendering Unicode characters are used to conceal messages or instructions inside seemingly-harmless text. As a result, human user interfaces do not render them, making the text appear completely normal to the user.

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls - The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since blocked the exploit for all users.

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks - an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days. “We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote.

Search Certificate Transparency Logs - Search the TLS certificate transparency logs to find public certificates issued. This can reveal new subdomains, certificate renewals, or suspicious activity. Great for security monitoring, domain research, and uncovering hidden infrastructure.

Microsoft

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon - “FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. The development comes days after Chaotic Eclipse released a PoC for another privilege escalation flaw impacting Kaspersky’s endpoint security product for Windows (version 14.0.0.504).

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC - Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher.

US GOV

A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over - During discovery in his case, Olson was provided a Department of Homeland Security (DHS) document that explained how Border Patrol instigated his traffic stop. Written by Border Patrol Agent Matthew Phelps, the document said Phelps was assigned to the “Spokane Sector Border Patrol Targeting & Intelligence Division (TID) — Predictive Intelligence Targeting Team (PITT).” Olson shared the document with 404 Media.

US military disabled ad tracking on troops’ devices following reports of targeted attacks | TechCrunch - Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, Air Force, Navy, and Marine Corps, and Special Operations Command have all disabled advertising tracking across their government-issued devices. The aim is to prevent adversaries, including hostile governments, from using location data derived from the apps on troops’ phones to target them on the battlefield or on their bases. Location data collected from phone apps is commonly shared with third-party companies and data brokers, which then sell the information on the commercial market. Disabling the advertising ID makes the person far more difficult to identify as the location data blends in with everyone else whose advertising ID is also disabled.

Confused about which VPN is right, US senator asks the NSA for guidance - Ars Technica - “Americans facing advanced foreign threats—including government personnel, defense contractors, journalists, and human rights defenders—deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote in a letter sent Wednesday to Gen. Joshua Rudd, the director of the NSA. “To that end, I request that you update NSA’s existing public guidance on VPN configurations to address this issue.”

  1. Are standard, single-hop commercial VPNs sufficient to protect Americans’ sensitive digital footprints from foreign adversaries monitoring internet backbones?
  2. Does the NSA recommend multi-hop tools such as Apple Private Relay, Tor, or Nym over standard VPNs for Americans facing heightened surveillance threats?
  3. What technical features, such as random delays, padding, and cover traffic, are needed to defend against sophisticated surveillance, and how does the NSA assess multi-hop systems like Apple Private Relay compared with Tor and Nym?

AI

OpenAI agents discussed ways to escape their sandbox on public wiki - Ars Technica - In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week period. Besides discussing ways the agents could break out of the restricted environment OpenAI intended to prevent them from posting code or content to the Internet, the posts shared test answers. The posts also shared possible ways to perform XSS (cross-site scripting) attacks against the wiki and to impersonate site moderators. The researchers say there are gaps in their understanding of precisely what actions the agents took because the research is based solely on the content of the posts.

Our best guess of what happened is as follows:

  • Agents within OpenAI were assigned a timed web-lookup task.
  • As part of the task, they were supposed to have the ability to read the internet but not to write on it. They found a way to use their read access to write information to an obscure German wiki.
  • The agents used this wiki to communicate information with each other, primarily to help them succeed at their task. They asked for answers, pooled results, and shared techniques for bypassing their restrictions. This allowed them to use the work of others to cheat on their task.
  • OpenAI found out about this. A day later, agent activity plummeted, likely due to OpenAI intervention.

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident - OpenAI’s agents were going rogue as early as May, according to a new report, making the Hugging Face incident far from the first where bots committed a breach.

The Multiverse School — AI, Coding & Cybersecurity Classes Online - AI Resources

I’m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at @IAintShootinMis@DigitalDarkAge.cc and on Signal at DigitalDarkAge.98. An RSS Feed of this blog is available here and a copy of my current OPML file is here.