🔐 Security Pulse · 2026-09-02 16:00 UTC

⚡ TL;DR

Massive data leak of 153 million US driver licenses from IDScan affecting major brands including Shell and AMC poses critical privacy risk with associated sale of high-profile individuals' data; multiple new unauthenticated vulnerabilities in ash-project GraphQL and Open5GS telecom stack also disclosed. Overall threat level elevated with urgent patching required.

🔐 CYBER THREATS

  • 🔴🔴🔴 IDScan data breach exposes 153 million US driver licenses tied to companies like Shell, AMC Theaters, and DraftKing; sensitive personal data now for sale including persons of public interest such as Pete Hegseth [1] [2] [3].
  • 🔴🔴 CVE-2026-81633, CVE-2026-81636, CVE-2026-80223, CVE-2026-78693: Multiple critical unauthenticated vulnerabilities in ash-project ash_graphql allow crash, resource exhaustion, tenant data leakage, and exposure of sensitive application internals [4] [5] [6] [7].
  • 🔴🔴 CVE-2026-82587 and CVE-2026-82588: Open5GS telecom system up to version 2.7.7 suffers from code execution risks in amf_namf_comm_decode_ue_mm_context_list and transfer endpoint processing threatening 5G core infrastructure [8] [9].
  • 🟡 CVE-2026-56718 in AJCloud IPC firmware allows unauthenticated remote path traversal, enabling potential device compromise in IoT/embedded systems [10].
  • 🟡 CVE-2026-82853 Nodemailer before 8.0.5 allows SMTP command injection, risking mail delivery infrastructure security.
  • 🟡 Several lower risk vulnerabilities identified in Hulumi and pdfme packages affecting cloud monitoring and cross-site scripting vectors.
  • 🟡 End-of-Support edge devices highlighted by CISA as critical attack vectors for network infiltration with recommendations to mitigate exposure.
  • 🟡 National Insider Threat Awareness Month underway urging organizations to strengthen internal threat detection and mitigation.

🛡️ NATIONAL SECURITY

  • 🟢 No new significant military movements or espionage reports detected in last 24 hours from OSINT sources.
  • 🟢 Continuous recruitment efforts by US Cybersecurity agencies reflect ongoing capability building to protect critical infrastructure.
  • 🟡 Potential indirect risk to critical infrastructure from vulnerabilities in telecom 5G core stacks Open5GS could affect national communications resilience if exploited [8] [9].

⚠️ RISK FLAGS

  • ⚠️⚠️ Urgent: Major data breach of IDScan impacting 153 million US driver licenses, risking fraud and identity theft at scale; clients include critical services sectors. Immediate review and mitigation advised for affected organizations and individuals [1] [2] [3].
  • ⚠️ Urgent: High-severity unauthenticated vulnerabilities in ash-project GraphQL require rapid patching to prevent data leakage and DoS conditions across multi-tenant cloud platforms [4] [5] [6] [7].
  • ⚠️ Elevated telecom infrastructure risk from Open5GS exploitable flaws in 5G core signalling components demands prompt countermeasures to secure national telecom assets [8] [9].

🧭 THREAT MOOD

  • 🟡 Elevated: Widespread issues including a massive PII breach and multiple critical vulnerabilities in cloud and telecom infrastructure exacerbate risks; defense and remediation efforts must intensify to avert cascading impacts.

📎 Sources

  1. The company which leaked data is IDScan. IDScan does not list … — @vxunderground
  2. Dawg, they got Pete Hegseth in the data breach. It's available… — @vxunderground
  3. I really recommending reading this. In summary, a company whi… — @vxunderground
  4. CVE-2026-81633 Improper Input Validation vulnerability in ash-… — @CVEnew
  5. CVE-2026-81636 Allocation of Resources Without Limits or Throt… — @CVEnew
  6. CVE-2026-80223 Incorrect Authorization vulnerability in ash-pr… — @CVEnew
  7. CVE-2026-78693 Generation of Error Message Containing Sensitiv… — @CVEnew
  8. CVE-2026-82587 A vulnerability was determined in Open5GS up to… — @CVEnew
  9. CVE-2026-82588 A vulnerability was identified in Open5GS up to… — @CVEnew
  10. CVE-2026-56718 AJCloud AJY IPC firmware prior to version 01.10… — @CVEnew

Educational & informational only — not financial advice. Markets carry risk; do your own research.
Serial 20260902-16-v58 · 2026-09-02 16:00 UTC · pulse.uzylab.com