Posts

Showing posts from September, 2026

153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story

Image
Breaking Vendor Risk September 2026  ·  7 min read 153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story. This week, a database of more than 170 million scanned identity documents — driver's licenses, ID cards, travel documents — surfaced for sale, reportedly traced to a single identity-verification company whose scanning equipment sits behind the counter at car rental desks, hotels, casinos, and age-restricted retailers across North America. The company hasn't confirmed the breach. The FBI has opened an investigation. But the part of this story that matters most for small businesses isn't who got breached — it's a gap in the rules that most businesses scanning a customer's ID have never thought to ask about. Late last week, researchers investigating a dark-web identity-theft marketplace found something unusually l...

Software Vendors Just Shipped Records Numbers of Security Patches. Your Patch List Didn't Get Longer by Accident.

Image
Trend Report Patch Management August 2026  ·  8 min read Something changed in how software vulnerabilities get found this year, and the numbers are startling: disclosed flaws are on pace to roughly double last year's already-record total, and the biggest names in software have each shattered their own patch-count records, sometimes by five times over. The cause isn't sloppier code. It's that the tools doing the looking got dramatically better — on both sides of the fight. Here's what's actually happening, and why the way you decide what to patch first matters more now than it ever has. If your IT provider has seemed busier than usual with updates this year, that's not your imagination, and it isn't a coincidence specific to your systems. Something structural shifted in how software vulnerabilities get discovered in 2026, and the scale of it is large enough that security researchers are describing it as...