VYPR
breachPublished Sep 10, 2026· 1 source

ShinyHunters Claims Florida DMV Hack, N-able Patches Critical RCE Flaw

The ShinyHunters threat group claims a breach of Florida's DMV, while N-able rushes a patch for a critical zero-day in its N-central platform.

The notorious ShinyHunters extortion group has claimed responsibility for a significant data breach affecting Florida's Driver and Vehicle Information Database (DAVID). The group alleges that over 200,000 records containing sensitive personal information of state drivers were exfiltrated. DAVID, managed by the Florida Highway Safety and Motor Vehicles agency, is a critical database used by law enforcement and criminal justice officials.

As proof of their intrusion, ShinyHunters released a screenshot of a DMV record belonging to Jeffrey Epstein, which reportedly included details such as a Social Security number, date of birth, driver's license information, and registered vehicles. The attackers stated they exploited a password-reset vulnerability, which allowed them to compromise multiple accounts, including those allegedly belonging to DMV employees and an FBI agent. They further detailed how they enumerated record IDs to download driver information and images. The group indicated that the breach began on September 3rd and that they have since lost access as Florida officials work to address the vulnerability.

In parallel, N-able has issued an emergency hotfix for a critical vulnerability affecting its N-central remote monitoring and management platform. Tracked as CVE-2026-86218, the flaw carries a maximum CVSS score of 10.0 and permits unauthenticated remote code execution, posing a severe risk to managed service providers and their clients. N-able released Hotfix 4 for N-central 2026.3 on September 5th, updating the platform to build 2026.3.1.14.

While N-able's initial advisory suggested no confirmed exploitation in production, a subsequent company notice confirmed that the vulnerability has been observed being exploited in the wild. This incident follows a pattern of N-central vulnerabilities being abused by threat actors, who in August compromised servers to gain administrative control and leverage the platform's legitimate remote management capabilities to access customer endpoints. These prior attacks involved credential theft, persistence mechanisms, and the deployment of additional remote access tools, with security researchers linking the activity to ransomware operations.

Separately, Bimbo Bakeries USA has disclosed a data breach impacting employee Social Security numbers. The breach occurred after attackers exploited a zero-day vulnerability in Oracle E-Business Suite (EBS) via a third-party vendor. The company learned of the intrusion on December 6, 2025, and confirmed that one compromised file contained employee names and Social Security numbers. While the exact number of affected individuals was not disclosed, the incident timeline and technology align with the exploitation of CVE-2025-61882, a critical Oracle EBS flaw known to allow unauthenticated remote code execution and linked to the Clop extortion operation.

In law enforcement news, French authorities have arrested an 18-year-old suspected member of the ZeroBytes hacking collective. The arrest is linked to cyberattacks targeting France's tax authority and other organizations. The suspect was apprehended in the Paris region on August 18th and is currently in pretrial detention. A second, younger suspect was also arrested and released pending further investigation. Prosecutors suspect the 18-year-old's involvement in attacks against the Directorate General of Public Finances, which had previously disclosed a breach in August.

These incidents underscore the persistent threat posed by various cybercriminal groups, from extortionists like ShinyHunters to those exploiting critical infrastructure vulnerabilities like N-able's N-central. The ongoing exploitation of zero-day flaws, coupled with sophisticated attack vectors, continues to challenge organizations globally, necessitating rapid patching and robust security measures.

Synthesized by Vypr AI