The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.
A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.