AI and IT News Recap: September 3, 2026: A Dark Web Market Sells 153 Million Driver's Licenses, Google Ships a Model That Writes Its Own Patches, and a Lenovo Login Opens Dropbox
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท September 3, 2026

Your fast, no-spin read on the AI and IT news that actually matters to a business owner today. Wednesday brought a dark web service selling 153 million driver's license scans, a Google model built to find and fix vulnerabilities on its own, and a Dropbox breach that needed nothing but your email address.
๐ The AI and IT news at a glance
๐ A dark web market began selling 153 million US and Canadian driver's license scans, and the FBI has opened an investigation into the suspected source, identity verification firm IDScan.net.
๐ค Google shipped Gemini 3.8 Flash plus a cybersecurity variant, 3.8 Flash Cyber, that finds vulnerabilities and writes working patches.
๐ค Anthropic announced Enterprise Frontier Safeguards, which keeps Claude monitoring logs in the customer's own cloud instead of Anthropic's.
๐ก๏ธ A maximum-severity Cisco Nexus 9000 flaw lets an unauthenticated attacker run code as root on the switch.
๐ก๏ธ Attackers got into about 5,000 Dropbox accounts using only an email address, via a Lenovo ID verification flaw.
๐ก๏ธ Aesto Health disclosed a breach affecting more than 9.5 million patients, the second largest healthcare breach of the year.
๐ก๏ธ A new Android trojan, StreamRat, spread through fake TV streaming ads on Meta and TikTok and takes near-total control of the phone.
๐งฐ Anthropic released an open-source blueprint for building shopping and merchant agents, with a Claude Code plugin to wire it to your own catalog.
Missed yesterday? Catch up with the September 2 recap.
๐ Top story: 153 million driver's license scans turned up for sale, and the FBI is investigating
A dark web service called Nexus began selling access to more than 153 million driver's license scans from the United States and Canada, along with more than 10 million other ID cards, over three million travel or international documents, and at least 579,000 medical cards including cannabis dispensary cards. Brian Krebs started digging after a source pointed him on August 31 to a listing on the Russian-language cybercrime forum Exploit, where the seller claimed to hold identity documents for more than 170 million people and used a scan of Krebs's own Virginia driver's license as the sample. The service added roughly 400,000 more licenses within 24 hours, which suggests the source was still feeding it.
The trail led to IDScan.net, a New Orleans identity verification company whose technology validates government-issued IDs at more than 20,000 locations and processes over 21 million verifications a month. Its customer list includes Hertz, Target, FedEx, Caesars Entertainment, Motorola Solutions, and Jack Henry. The evidence is circumstantial but specific: the stolen records include front and rear scans captured with standard, infrared, and ultraviolet imaging, which matches capabilities IDScan documents in its own technology, and nine people who let Krebs search the database confirmed the timestamps matched moments when they had recently handed over an ID, often while traveling. Krebs's own license and his mother's were scanned seconds apart on a day they both presented ID at the same Hertz counter. Records reportedly included Defense Secretary Pete Hegseth and identity information tied to an FBI assistant director. IDScan told Krebs it was investigating but did not issue a detailed response. The FBI's New Orleans field office has opened an official investigation, and the Nexus site went dark shortly after Krebs published.
In short: A dark web service was selling more than 153 million driver's license scans apparently sourced from identity verification provider IDScan.net, and the FBI has opened an investigation.
What it means for your business: If your business scans customer or visitor IDs through a third-party verification vendor, the question to ask this week is how long that vendor retains the scan images and whether you can turn retention off, because you inherit the breach exposure of every image they keep.
My take: The detail that should bother every business owner here is not the number, it is the mechanism. Nobody in this story chose to hand their license to a data broker. They rented a car, checked into a hotel, or walked into a dispensary, and a scanner at the counter quietly created a permanent high-resolution copy including the infrared and ultraviolet layers that exist specifically to prove a document is genuine. That is the part that makes these records worth paying for: they defeat the verification checks meant to catch fakes. If you operate one of these scanners, you are a collection point in someone else's data pipeline, and "our vendor handles that" is not a retention policy. Ask what is stored, where, and for how long, and get the answer in writing.
Source: FBI Probes Service Selling 153M Driver's Licenses, KrebsOnSecurity
๐ค AI
Google shipped a model built to find security holes and write the patch
Google released Gemini 3.8 Flash on Tuesday alongside a purpose-built cybersecurity variant called Gemini 3.8 Flash Cyber, its third Flash release in six weeks. The general model is pitched as Google's best reasoning and coding workhorse, improving on its predecessor across software engineering, agentic tasks, and multi-step reasoning, and on DeepSWE v1.1, a long-horizon software engineering benchmark, Google says it outperforms most larger frontier models at a fraction of the cost. Pricing holds at the 3.7 Flash introductory rate of $0.75 per million input tokens and
.75 per million output tokens, which is the part most businesses will actually feel.
The Cyber variant is the more consequential release. It is built to autonomously discover software vulnerabilities and generate working patches for them, and Google is not selling it openly: access runs through a new Fairwind Program limited to vetted security researchers, government agencies, and critical infrastructure operators. The numbers Google published are strong. Its Chrome Security team found the model produced 2.6 times more correct patches for Chrome vulnerabilities than the best commercial models it evaluated, and its Cloud Vulnerability Research team used it to find a critical foundational vulnerability in under two hours in an area where discovery normally takes months.
In short: Google launched Gemini 3.8 Flash and a gated cybersecurity variant, 3.8 Flash Cyber, that autonomously finds vulnerabilities and writes patches for them.
What it means for your business: The general model is a straightforward price-performance improvement if you already build on Gemini, but the Cyber variant is a signal worth reading: the vendors are now gating their best defensive tooling, so the software you buy will get patched faster than anything you maintain yourself.
My take: Two frontier labs in two days have now shipped a model that finds and exploits unknown vulnerabilities, and both have decided normal customers cannot have it. That tells you the capability is real and that the labs know the offensive and defensive versions are the same product. What I find more useful than the benchmark is the Chrome result, because patching is the unglamorous half nobody automated well. Finding a bug has always been easier than shipping a correct fix for it. If that ratio genuinely holds up outside Google's own codebase, the practical effect over the next year is that big vendors close holes faster, and the gap between well-maintained commercial software and the custom app your business had built five years ago gets wider.
Source: Google Launches Gemini 3.8 Flash and 3.8 Flash Cyber, iClarified
Anthropic will let enterprises keep Claude's monitoring logs in their own cloud
Anthropic announced Enterprise Frontier Safeguards on Tuesday, a system meant to settle a real complaint from business customers: the tension between zero data retention and the fact that safety monitoring requires somebody to retain something. Under EFS, monitoring data is stored in cloud infrastructure the customer controls, in Amazon S3, Azure Blob Storage, or Google Cloud Storage, under the customer's own encryption keys and access policies. Anthropic's automated systems still scan for misuse, but no Anthropic employee performs human review of that data. The company frames it as detection staying with Anthropic while custody, keys, and human review move to the customer.
The rollout is phased, beginning later this fall, and Anthropic says it will not charge for EFS. Customers eligible for the new system get zero data retention on Fable 5 and Fable 5.1 during the transition. This is the same week Anthropic also detailed its response to recent security incidents, and the two are related: the pitch to regulated industries is that you can have the audit trail without handing the audit trail to your vendor.
In short: Anthropic's new Enterprise Frontier Safeguards keeps Claude misuse-monitoring data in the customer's own cloud storage under the customer's keys, with no Anthropic human review, rolling out in phases this fall at no extra cost.
What it means for your business: If a compliance or legal review has been the thing blocking Claude at your company, this removes the specific objection that a vendor holds readable logs of your prompts, though you now own the storage, the keys, and the responsibility for both.
My take: This is a genuinely good structural answer to a problem most vendors handle with a contract clause instead of architecture, and it is worth noting Anthropic is not charging for it. The catch is one most buyers will underestimate. Zero data retention that depends on your own S3 bucket means your own bucket policy is now part of your AI safety posture, and misconfigured object storage remains one of the most common ways companies leak data. Trading "the vendor can read my logs" for "my logs sit in a bucket my team configured" is an improvement only if somebody actually owns that bucket. Ask who that is before you sign.
Source: Developing Enterprise Frontier Safeguards with our customers, Anthropic
๐ก๏ธ IT and security
A maximum-severity Cisco switch flaw hands over root
Cisco disclosed CVE-2026-20212 on Tuesday, a 9.8-severity flaw affecting Nexus 9000 series switches that contain Silicon One ASICs. TCP ports 43210 and 43211 are reachable through the default Layer 3 virtual routing and forwarding instance, and an unauthenticated attacker who can reach either port can send crafted input that executes as code with root privileges, or knock the device offline. The underlying weakness is classified as binding to an unrestricted IP address, which is a polite way of saying a management service was listening where it should not have been.
The exposure detail matters more than the score. An affected switch does not need to be internet-facing to be at risk, because the flaw is exploitable from any compromised or less-trusted internal network segment that can reach those ports, with no privileges and no user interaction required. Cisco has released fixed NX-OS software and recommends upgrading for full remediation. For organizations that cannot patch immediately, Cisco has tested an infrastructure access control list workaround that permits only required management and control-plane traffic, and administrators can alternatively deny TCP traffic to the device's own addresses on ports 43210 and 43211. As of Wednesday, Cisco's security incident response team said it was not aware of malicious use or public exploit code.
In short: Cisco patched CVE-2026-20212, a 9.8-severity Nexus 9000 flaw that lets an unauthenticated attacker on a reachable network segment execute code as root.
What it means for your business: If your network runs on Nexus 9000 switches, this is a patch-or-filter task for your network provider this week, and "it is not on the internet" is not a reason to defer it.
My take: The lesson in this one is about the shape of the risk, not the CVE. Core switches are the least-patched devices in most business networks because rebooting one takes the office down, so they get deferred indefinitely. What makes this flaw awkward is that it is reachable from inside, which means the compromised laptop in accounting is enough. That collapses the usual internal-versus-external distinction people use to justify the delay. Nobody exploited it yet, which is exactly the window you want to patch in, and it will close quietly once someone publishes working code.
Source: Critical Cisco Nexus 9000 Flaw Allows Remote Root Code Execution, eSecurity Planet
Attackers got into Dropbox accounts using nothing but an email address
Dropbox has begun notifying users that attackers gained unauthorized access to their accounts by abusing its Lenovo ID third-party sign-in integration, and the mechanism is about as basic as authentication failures get. Lenovo's system let anyone register a Lenovo ID with any email address without verifying that they controlled that inbox. An attacker could create a Lenovo ID using a victim's email, then use "sign in with Lenovo" to walk straight into that person's Dropbox account without ever touching the Dropbox password. Victims did not need to have an existing Lenovo ID for this to work.
The window ran from August 4 to August 21, and Dropbox says at least 5,000 accounts were affected, with files viewed or downloaded in about a third of them. Dropbox has expired all sessions authenticated through Lenovo IDs and now requires users to enter their Dropbox password when authenticating with a Lenovo ID. Affected users are advised to change their Dropbox and email passwords and turn on two-step verification.
In short: A Lenovo ID email verification flaw let attackers sign into roughly 5,000 Dropbox accounts using only the victim's email address, with files accessed in about a third of them.
What it means for your business: Take ten minutes and look at the connected accounts and sign-in methods on your business file storage, because every "sign in with" option you leave enabled is a second front door whose lock somebody else maintains.
My take: Federated login is one of the better security decisions available to a small business, right up until you remember it means outsourcing your front door to whoever runs the identity provider. Dropbox did nothing wrong at the protocol level; it trusted an assertion that a partner had verified an email address, and the partner had not. That is the whole failure. The practical takeaway is boring and effective: audit which third-party sign-in providers are enabled on the accounts that hold your company's files, and disable the ones nobody uses. A login method you forgot you turned on is pure downside.
Source: Dropbox accounts breached through Lenovo email verification flaw, BleepingComputer
A healthcare data vendor lost records on 9.5 million patients
Aesto Health, a Birmingham, Alabama company that handles data migration, electronic health record exchange, and legacy data archiving for healthcare providers, has disclosed a breach affecting 9,540,683 individuals. That figure, reported to the Department of Health and Human Services Office for Civil Rights, makes it the second largest confirmed healthcare breach of the year so far, behind a 15 million record incident at DentaQuest. The stolen data is close to a complete identity kit: full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, Social Security numbers, and other government ID numbers.
The timeline is the uncomfortable part. Aesto discovered the incident on December 18, 2025, and its investigation determined attackers exfiltrated data from portions of its Amazon Web Services infrastructure between December 2 and December 18. The company began notifying affected individuals on August 21, roughly eight months later, offering 24 months of Experian identity theft protection and credit monitoring. At least two dozen Aesto healthcare provider clients across several states are affected, and some are handling notification themselves.
In short: Aesto Health disclosed that attackers stole personal and health data on more than 9.5 million patients from its AWS environment in December 2025, with notifications beginning in August 2026.
What it means for your business: If you are a healthcare provider, your breach notification obligations follow your patients' data into every vendor that touches it, so knowing which of your vendors archive old records is not an IT question but a liability question.
My take: Nobody in this story is an Aesto customer in the way patients understand the word. These are the records a practice migrated off an old system years ago, parked with an archiving vendor, and stopped thinking about. That is the pattern worth noticing: the highest-risk copy of your data is usually the one nobody is actively using, because it gets the least attention and the fewest controls while retaining every sensitive field. Eight months from discovery to notification is also a long time, and it is a reminder that when a vendor holds your data, you do not control the clock on telling your own customers.
Source: Aesto Health says data breach affects over 9.5 million patients, BleepingComputer
A fake streaming app from a Meta ad takes over the whole phone
ThreatFabric documented a new Android banking trojan it calls StreamRat, promoted to Spanish-speaking users through a fake television streaming campaign on Meta, and also pushed via TikTok. The Meta campaign ran from June 11 to July 3, 2026, focused on Spain, and reached an estimated 570,950 accounts in the European Union at least once. Victims sideload the app package, then grant a sequence of permissions the app requests, and that sequence is what does the damage.
StreamRat abuses Android's Accessibility Services and MediaProjection to give operators near-complete control of the device, combining VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and the ability to block the screen or internet connection. In practice, the operator watches which app the victim opens, serves a matching fake login page, harvests what gets typed, and uses intercepted unlock details to get into the device directly. Banking sessions, messages, and any other sensitive account on the phone are in scope. ThreatFabric's practical advice is the right heuristic: stop the installation when a streaming app asks for system controls that have nothing to do with streaming.
In short: StreamRat is a new Android trojan distributed through fake streaming app ads on Meta and TikTok that abuses Accessibility Services to take near-complete control of infected phones.
What it means for your business: If staff read company email or approve multi-factor prompts on personal Android phones, an accessibility-abusing trojan on that phone defeats those prompts, which is an argument for keeping work accounts on managed devices or at least off sideloaded-app phones.
My take: The campaign ran as paid advertising on Meta for three weeks and reached over half a million people in the EU, and that is the part I would not skip past. This was not a shady forum link; it was an ad, in a feed, with a budget. Ad platforms remain a reliable malware distribution channel and the review process clearly did not catch it. For a business owner the defense is unglamorous and effective: install Android apps only from the Play Store, and treat any request for Accessibility permissions as a hard stop unless the app is an actual accessibility tool. Accessibility access is functionally the keys to the phone.
Source: Uncovering StreamRat: From Meta Ads to Full Device Takeover, ThreatFabric
๐งฐ New tooling for builders and business
Anthropic published a build-it-yourself blueprint for shopping agents
Anthropic released an open-source commerce agents blueprint on Tuesday, aimed at teams that want an AI agent handling storefront or merchant work without designing the whole thing from scratch. It ships two reference agents: a shopping agent that searches a catalog, compares products, assembles a cart, and hands the customer to checkout, and a separate merchant agent that analyzes sales, monitors inventory, and recommends pricing or promotional actions. There are four vertical implementations covering retail, travel, telecom, and ticketing, plus a Claude Code plugin that scaffolds an agent against your own systems or reviews one you have already built. It deploys wherever you already run Claude, including the Claude API, Amazon Bedrock, Microsoft Foundry, and Google Cloud Vertex AI.
Anthropic's pitch includes the guardrails and harnesses, which is the part teams usually underestimate, and it cites retailers running shopping agents on Claude seeing carts up to 35% larger and shoppers 60% more likely to complete a purchase. Shopify has published its own implementations of the blueprint on GitHub, which is a useful signal that this is meant to be forked rather than admired.
In short: Anthropic open-sourced a blueprint with reference shopping and merchant agents, four industry implementations, and a Claude Code plugin for wiring it to your own catalog.
What it means for your business: If you sell online and have been wondering what an AI shopping assistant would actually take to build, this is a concrete starting point rather than a demo, though the conversion numbers are vendor-supplied and your catalog data quality will decide whether it works.
My take: The genuinely useful thing here is the guardrails, not the agents. Anyone can wire a chatbot to a product catalog in an afternoon; the hard part is stopping it from inventing a discount, recommending a discontinued item, or confidently describing a product attribute that does not exist. A blueprint that has already thought through those failure modes saves a team real time. The honest caveat is that a shopping agent is only as good as your catalog, and most small retailers have inconsistent attributes, stale inventory counts, and product descriptions written by three different people over six years. Fix that first, because an agent will surface every gap faster than any customer ever did.
Source: Building Commerce Agents with Claude, Anthropic
That is the AI and IT news that matters for September 3, 2026. Have a question about how any of this hits your business? Reach out to the KeyChange team, and check back tomorrow for the next recap.