Severity Daily

IT and AI security incidents, checked against the primary source

Tag: FLHSMV

  • In three of today’s eight stories, the fix on offer covers less than the flaw does

    In three of today’s eight stories, the fix on offer covers less than the flaw does

    The most consequential thing on the site today is not the 10.0. It is a three-day federal clock that runs out on Sunday. CISA added two of the three exploited MikroTik RouterOS flaws to the Known Exploited Vulnerabilities catalog on September 10, due September 13, and left off the SSH authentication bypass that CERT Polska puts first in the chain. Exploitation is confirmed by a national CERT, all three flaws are closed by the same RouterOS releases, and Shadowserver counts at least 122,500 MikroTik devices with SSH reachable per 24-hour scan window. An agency that upgrades is fine. An agency that works the catalog as a queue — patch what is listed, ticket what carries a due date — finishes Sunday compliant and still reachable through the door the catalog does not name.

    The biggest-sounding story is GitLab’s, and it ranks second. An unauthenticated arbitrary file read in the repository commits API, scored 10.0, is as bad as a number gets, and the research published on September 11 describes reaching configuration files, credentials, tokens, and SSH keys. But nobody has confirmed exploitation — watchTowr reports probes, and probing is not exploitation — and the 10.0 is GitLab’s own, with NVD returning no record at all as of early this morning. Recompute the vector without the integrity impact the advisory’s own description does not describe, and it is an 8.6. What is not in dispute is the work: self-managed operators have a critical to install, and some of them cannot.

    That last clause is the day’s thread, and it runs through three of the eight stories. GitLab names installations from 18.7 as affected and ships no 18.x build in the release, so a shop sitting on 18.7 through 18.11 is inside the affected range and outside the branch that got the fix — a major-version migration, not a patch. CISA put two more JFrog Artifactory flaws on KEV with a September 25 deadline, and on the 7.133 branch their fixes are seventeen patch releases apart: an administrator who took 7.133.11 in July to close CVE-2026-42016 is still exposed to CVE-2026-42018 today, and a version check that stops at 7.133.11 reports the box clean. And CISA’s MikroTik entries cover two links of a three-link chain. In each case the fix on offer covers less than the flaw does, and in each case you see it only by reading two documents side by side.

    The other four are disclosure stories, and what they share is an absence. Florida’s motor vehicle agency confirmed that DAVID, its law enforcement driver database, was breached through credentials a Plant City police employee stored on a personal device, and named no number; every figure in circulation — 200,000 records, Social Security numbers, and dates of birth — belongs to ShinyHunters. Nutex Health’s stolen data has been published online, and the company filed that under Item 8.01 with its materiality assessment unchanged, no count and no dates. Conduent settled the class action over its January 2025 breach with no dollar figure, also under Item 8.01, having filed the incident itself under Item 1.05. Greenberg Traurig told Vermont and California regulators that Social Security numbers were in scope on September 8 and September 9, then publicly called the exposure limited on September 10. Furthest from an action item, Anthropic’s misuse report describes one actor working through roughly thirty AI companies in about four days, swapping in each victim’s own API keys as it went — a billing and attribution problem as much as a security one.

    Open tonight. CVE-2026-67276, the MikroTik bypass, still carries no exploit-add date and may yet be added; worth re-checking before Sunday. CISA’s alert for September 11 is titled as one catalog addition while two records carry that day’s exploit-add date, and cisa.gov returns 403 to automated fetching, so the count could not be reconciled. GitLab has said nothing about the 18.x case. The distillation claim circulating in coverage of the Anthropic report — seven named Chinese labs, industrial scale — does not appear in the document we read. And four organizations described a breach today without producing a number. Nutex says its review will take several weeks.

  • Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency has confirmed that its law enforcement driver database was breached, says the access came through credentials a Plant City police employee had stored on a personal device, and puts no number on what was taken — every figure in circulation belongs to the group that claimed the breach.

    What happened

    The Florida Department of Highway Safety and Motor Vehicles confirmed the breach publicly on September 10, 2026, six days after it says it learned of the incident. Its statement, verbatim and in full: “On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing.”

    The system involved is DAVID, the Driver and Vehicle Information Database, which law enforcement and criminal justice users across Florida query for driver and vehicle records. It is not public-facing; access is granted to authorized users at police departments, sheriff’s offices, and other agencies under agreements with the state.

    The agency’s account of how the access happened is specific, and it points outward. FLHSMV says its investigation found that the intruders used the login credentials of an employee of the Plant City Police Department, and that the employee had improperly stored those credentials on a personal electronic device. FLHSMV also says it has provided the required notice of the security breach to the Florida Attorney General’s Office under state law, and that the matter remains under criminal investigation.

    What the agency does not say is as important. It names no number of records or people, no categories of data, and no group. It does not say when the access began or how long it lasted, and as of this writing it has made no public commitment to notify individuals.

    The group that claimed the breach is ShinyHunters, which added FLHSMV to its leak site on or before September 8, 2026 and warned that it would publish data if the agency did not negotiate. Its claims, which are claims and not confirmed facts: that access began September 3, that it took more than 200,000 driver records, and that those records include addresses, Social Security numbers, dates of birth, driver’s license numbers, and registered vehicle information. It posted a screenshot of a single purported DAVID record as proof of possession. Reporting at the time put its deadline at September 11, 2026 — the day after the state’s confirmation.

    CyberInsider, which covered the claim on September 8, stated plainly that it “could not independently verify ShinyHunters’ claims, the authenticity of the displayed record, or whether the data came from a direct compromise.” At that point FLHSMV had not confirmed anything.

    The two accounts do not match

    The state and the group describe different root causes, and the difference is not cosmetic.

    FLHSMV describes stolen credentials: one authorized user at a municipal police department, credentials kept where they should not have been, used by someone else. ShinyHunters describes a defect in the state’s own authentication — a password-reset flaw that let it take over multiple DMV employee accounts and an account belonging to an FBI agent, after which it says it walked through records by iterating record IDs.

    Those are not two descriptions of one event. One is a hygiene failure at a partner agency and implies nothing wrong with the portal. The other is a vulnerability in a state system that would have to be found and fixed, and that would put every other account at risk regardless of how carefully its owner handled a password. Nobody has reconciled them publicly, and FLHSMV’s statement does not address the password-reset claim at all.

    The dates are compatible but uninformative. The group says access started September 3; FLHSMV says it learned of a breach on September 4 and says nothing about when the access began. “Quickly mitigated” is doing a lot of work in a sentence that never establishes what was being mitigated, or for how long it had been running.

    Why it matters

    A state driver database is a hard target with a soft perimeter, and the perimeter is other people’s employees. DAVID’s security boundary is not one agency’s network. It is every authorized account at every local department that holds one, and every device those users touch. FLHSMV cannot patch a Plant City officer’s personal phone, cannot audit a municipal department’s device policy on its own authority, and — if its own account of the breach is correct — was compromised through a control it does not administer. That is the third-party access problem in its public-sector form, and it is worse than the commercial version, because the agencies on the other end of the agreement are sovereign in their own right.

    The data involved is also the kind that does not expire. A card number gets reissued in a week. A name, address, date of birth, driver’s license number, photograph, and signature are the record of a person, and a license number is not something most people can change on request.

    Then there is the number. The only figure anyone has is 200,000, and it came from the group doing the extorting. It appears in nearly every account of this breach, usually without the qualifier. FLHSMV has confirmed no figure at all. That arrangement is now routine enough to be a pattern rather than an accident: this publication covered IDScan.net on September 10, where the company confirmed unauthorized access and named no number while two competing figures circulated from a marketplace listing, and Greenberg Traurig on September 11, where state filings named Social Security numbers after the firm publicly described the exposure as limited. The attacker’s number fills the vacuum the confirmation leaves, and it becomes the number of record by default.

    The timing deserves a note too. The group’s deadline was September 11. The state’s confirmation landed September 10, six days after it says it learned of the breach and one day before the clock ran out. That is not evidence of bad faith — FLHSMV says a criminal investigation is underway, and agencies have legitimate reasons to wait — but the pressure that produced the disclosure also shaped its content: enough to confirm the breach, not enough to quantify it.

    Finally, the claimed access pattern is worth separating from the claimed vulnerability. Iterating through sequential record identifiers to bulk-download a database looks nothing like a detective running a plate. Whether the entry was a stolen password or a reset flaw, an authorized account pulling records in volume and in order is the signal that should have fired — and any organization running a records portal for partner agencies can look for it tonight without knowing which account here is true.

    What to do

    If your agency holds DAVID access or equivalent access to another state’s driver or criminal justice database: inventory the accounts you are responsible for, confirm which are still needed, enforce phishing-resistant multi-factor authentication on all of them, and make it an auditable rule that credentials are never stored on personal devices. Then pull per-account query volume for the past 90 days and look for accounts whose usage does not match a human caseload.

    If you run a records portal used by outside organizations: alert on sequential or near-sequential identifier access, set per-account rate limits on record retrieval, and test your own password-reset and account-recovery flow for takeover — that is the specific mechanism claimed here, and it is worth ruling out in your own system whether or not it was the route in this one.

    If you are a Florida driver: there is no individual notification from FLHSMV yet, and no confirmed list of who is affected. A credit freeze with the three bureaus is free, reversible, and the single most useful step available given that Social Security numbers are among the claimed data. Watch for a formal notice from the agency rather than acting on the figures in circulation.

    And do not carry 200,000 as a confirmed count in internal reporting. Attribute it, or leave it out.

    Sourcing note

    FLHSMV’s confirmation is the primary source for this story, and it was read through its verbatim quotation in local coverage dated September 10 and September 11, 2026 rather than from the agency directly. flhsmv.gov returned 403 to automated fetching, as did one of the television outlets carrying the statement; the agency posted its statement to X, which could not be retrieved from this environment. The quoted sentences appear identically across the outlets checked, which is reasonable but not the same as reading the agency’s own page.

    Florida’s public breach notification list could not be retrieved — the Attorney General’s data breach page returned 404 — so the filing FLHSMV says it made could not be confirmed independently, and no filing date, affected-resident count, or data-category list is available from that route. That remains unresolved.

    The attacker claims come from ShinyHunters’ leak site as reported on September 8, 2026 by BleepingComputer and CyberInsider. They are labeled as claims throughout because neither outlet verified them and CyberInsider said explicitly that it could not. No sample data was reviewed for this story and no leak site was accessed. The 200,000 figure, the September 3 start date, the data categories, and the password-reset mechanism are all the group’s assertions, and none of them has been confirmed by FLHSMV or by any other agency.

    Unresolved as of this writing: how many records and people were affected, how long the access lasted, whether a password-reset defect exists in the state’s portal, and whether individual notifications will be sent. The deadline the group set has now passed, and no confirmed publication of the data has been observed.