Threat Brief — 2026-09-02 — Nuclear agency breached, 153M licenses for sale
Executive summary: Today's intake is light on new vulnerabilities but carries two notable developments. Attackers exploited long-known commodity flaws in ownCloud to compromise the Philippines nuclear agency, stealing reactor databases and personnel records — a concrete demonstration of the damage unpatched software inflicts in sensitive environments. Separately, the FBI is investigating a dark-web service offering digital scans of over 153 million U.S. and Canadian driver's licenses, a scale of identity-data exposure that warrants vigilance against synthetic-identity fraud.
Top items
- Philippines nuclear agency breached via unpatched ownCloud flaws. Threat actors exploited commodity vulnerabilities in ownCloud for initial access, then exfiltrated reactor databases, personnel records, and credential stores. This is a new victim-detail development in the ongoing ownCloud KEV story first reported 2026-08-17 by CISA. The vulnerabilities involved are known and were already added to CISA's Known Exploited Vulnerabilities catalog, yet the targeted agency had not remediated them — underscoring that KEV listing alone does not guarantee patching in critical-infrastructure sectors. (src: DarkReading); first reported (src: CISA)
- FBI investigating dark-web service selling 153M+ driver's license scans. A newly launched identity-theft service is offering digital scans of more than 153 million driver's licenses from individuals in the United States and Canada. KrebsOnSecurity reports that some individuals whose licenses appear in the service have confirmed the data's authenticity. At this scale, the offering represents a significant resource for identity fraud, credential stuffing, and social-engineering pretexting. The FBI probe is active; the service's data sources and collection methods are not yet publicly confirmed. (src: KrebsOnSecurity)
Themes
Patch velocity remains the gap. The Philippines nuclear agency compromise is the latest in a recurring pattern this period: attackers do not need zero-days when known-exploited vulnerabilities remain unpatched for weeks or months. The ownCloud flaws were KEV-listed over two weeks before this breach was reported.
Identity-data commodification at scale. The 153M-license service, combined with recent healthcare breaches (Aesto Health, McKesson/ShinyHunters), points to a deepening market for verified personal documents — not just credential dumps, but scans suitable for passing KYC checks.
