By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (September 7, 2026):153 Million Driver’s Licenses Sold On Dark Web, Fire Ant Hackers Turn Cisco Routers Into Spy Platforms, and More

WEEKLY TOP TEN: September 7, 2026, 16:00 GMT

  1. Fire Ant Hackers Turn Cisco Routers Into Spy Platforms

    A Chinese state-sponsored threat actor known as Fire Ant compromised networking infrastructure by embedding covert access on a Cisco IOS XR router, using a persistent GRE tunnel that researchers found had no matching configuration or commit history, indicating a hidden backdoor rather than a misconfiguration. The group leveraged this foothold to intercept and redirect traffic, effectively turning core routing equipment into a surveillance platform. The campaign reflects a growing pattern of nation-state actors targeting edge and core network gear at telecom and critical infrastructure organizations to establish long-term, low-visibility access. Defenders are urged to audit router configurations, commit logs, and tunnel interfaces for signs of unauthorized changes.
  2. CISA Issues Eight Industrial Control System Advisories

    CISA published eight Industrial Control Systems advisories covering vulnerabilities across widely deployed operational technology products, with the bulk affecting Rockwell Automation platforms including RSLinx Classic, the Logix Platform, ControlLogix and CompactLogix controllers, FactoryTalk Activation Manager, and Historian ME, alongside an update to a longstanding Mitsubishi Electric FA engineering software flaw. The advisories detail current security issues, exploit potential, and mitigations for manufacturing, energy, and critical infrastructure operators running the affected equipment. CISA encourages asset owners to review each advisory and apply vendor patches or compensating controls promptly, given the exposure these products carry within industrial networks supporting critical manufacturing and utility operations nationwide.
  3. Aesto Health Breach Exposes 9.5 Million Patient Records

    Aesto Health disclosed a data breach after attackers accessed the company’s AWS cloud infrastructure, exposing sensitive information belonging to more than 9.5 million patients. The healthcare organization said it discovered the intrusion recently and is notifying affected individuals while working with external investigators to determine the full scope of compromised data. The breach ranks among the larger healthcare disclosures of the year and reflects the continued targeting of cloud-hosted medical data stores by threat actors seeking valuable personal and health information. Security teams overseeing healthcare cloud environments are urged to review AWS access controls, credential hygiene, and monitoring for anomalous data access patterns.
  4. Berlin Confirms Data Theft After Rhysida Attack Claim

    Berlin’s city administration confirmed that cybercriminals are attempting to extort the German capital after the Rhysida ransomware gang listed the city on its dark web leak site and claimed to have stolen sensitive data. City officials acknowledged the intrusion and said they are working with law enforcement and cybersecurity experts to assess the scope of the theft and secure affected systems. The incident adds Berlin to a growing list of European municipal governments targeted by ransomware groups seeking to pressure public sector victims into paying for data recovery or non-disclosure, underscoring the sustained risk ransomware poses to government entities managing citizen data and public services.
  5. SonicWall Warns Of Two Exploited SMA1000 Zero-Days

    SonicWall disclosed two zero-day vulnerabilities in its SMA1000 series appliances, tracked as CVE-2026-83549 and CVE-2026-83548, which can be chained together to achieve unauthenticated remote code execution. The company confirmed active exploitation in the wild and urged customers running affected SMA1000 secure access gateways to apply patches immediately. Remote access appliances remain a favored entry point for attackers due to their internet-facing nature and privileged network position, making this disclosure especially relevant for organizations relying on SonicWall for secure remote connectivity. Security teams should prioritize patching, review authentication logs for signs of compromise, and consider restricting exposure of management interfaces where feasible.
  6. Pegasus And NoviSpy Spyware Hit Serbian Activists

    Researchers at the Citizen Lab confirmed that a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware via a zero-click iMessage exploit, while Amnesty International confirmed a new variant of the Android-based NoviSpy spyware on two additional devices. The SHARE Foundation identified at least 14 targets in total, including a member of parliament and a local official, in what it called the largest documented wave of spyware surveillance in Serbia to date. The campaign coincided with local elections and student-led protests, raising concerns about state use of mercenary spyware against civil society. Apple has since patched the exploited iMessage vulnerability.
  7. Leaked Files Tie Russian University To GRU Hacking

    More than 2,000 leaked internal documents from Bauman Moscow State Technical University reveal a hidden department that trained roughly 250 career and reserve students for Russian military intelligence cyber and information operations roles. Reporting tied at least one graduate to GRU Unit 74455, known as Sandworm, which has been linked to destructive attacks including NotPetya. The disclosure, reviewed by an international media consortium and threat intelligence researchers, reframes Russian offensive cyber capability as an institutionalized pipeline rather than isolated threat groups. For defenders, the leak reinforces the value of tracking Russian cyber operations holistically, since espionage, sabotage, and influence campaigns may draw on overlapping personnel and training doctrine.
  8. Coder Registry Infrastructure Compromised To Push Malware

    Attackers compromised Coder’s Cloudflare-hosted infrastructure and added unauthorized registry servers that distributed malicious Terraform modules containing credential-stealing code to users of the platform. The compromise allowed threat actors to insert tampered infrastructure-as-code modules into what appeared to be a trusted registry, creating risk for any organization that pulled modules during the compromised window. Coder has since taken steps to remediate the unauthorized infrastructure, but affected users are urged to audit recently pulled Terraform modules and rotate any credentials that may have been exposed. The incident adds to a growing pattern of supply chain attacks targeting infrastructure-as-code tooling used broadly across DevOps environments.
  9. Manchester Airports Group Data On 8.8 Million Leaked

    A hacker group published roughly 550GB of data belonging to Manchester Airports Group after the company reportedly refused to pay a ransom demand, exposing information on approximately 8.8 million people. The attackers claimed to have gained initial access via exposed administrative keys, and the leak represents a significant escalation from earlier claims of intrusion into confirmed, large-scale data exposure affecting travelers and airport operations. The incident highlights continuing risk to aviation and transportation infrastructure from ransomware groups willing to publish stolen data when demands go unmet. Affected individuals should watch for phishing attempts referencing travel or booking details, and the airport operator continues to work with investigators on remediation.
  10. 153 Million Driver’s Licenses Sold On Dark Web

    A dark web marketplace is offering more than 153 million scanned U.S. and Canadian driver’s license images for sale, with researchers assessing the data likely originates from a breach at identity verification company IDScan.net. The scale of the exposure raises significant identity fraud risk, since driver’s license scans are commonly used to verify identity for financial services, rental applications, and other high-value transactions. IDScan has not publicly confirmed the source of the leak, and the listing has since drawn scrutiny from affected individuals and at least one lawsuit alleging inadequate data protection. Organizations relying on IDScan or similar identity verification vendors should reassess exposure and monitor for downstream fraud attempts using leaked credentials.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

AI in Cybersecurity: From Risk Multiplier to Force Multiplier – Insights for Executives

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.