IDScan Confirms Data Breach Exposing 150 Million Driver's License Records
ID verification company IDScan has confirmed it suffered a significant data breach affecting its systems. The incident resulted in the theft of more than 150 million driver's licenses and other government-issued identity documents. Compromised data includes victims' full names along with their identity document details. The breach raises serious concerns given IDScan's role as a major provider of ID verification services handling sensitive personal data.
DGCA Orders Drug Tests for All Pilots After Air India Altitude Drop Incident
India's aviation regulator has mandated drug testing for all pilots following a serious incident involving an Air India flight. The pilot-in-command of an Air India Phuket-to-Delhi flight tested positive for drug use after the incident. On August 4, the aircraft suddenly lost approximately 300 feet of altitude, resulting in injuries to multiple passengers. The regulatory directive appears to be a direct response to the confirmed drug test result linked to that flight.

Three critical settings that prevent data loss when self-hosting AnythingLLM
Self-hosting AnythingLLM via Docker is straightforward, but redeployments silently wipe all workspaces, embeddings, and user data if three key settings are misconfigured. The first involves correctly setting the STORAGE_DIR environment variable and ensuring a persistent volume is actually mounted at that path, since an unmounted path causes irreversible data loss without any warning. The second is a file permissions issue, where a fresh volume mounted to a non-root container user will block writes and trigger misleading SQLite errors, requiring either root access or a pre-boot ownership change. Third, platforms like Railway and Heroku dynamically assign ports via a $PORT variable, but AnythingLLM defaults to port 3001, causing 502 errors unless PORT is explicitly pinned to 3001. The author, who maintains a Railway deployment template for AnythingLLM, notes these fixes apply regardless of whether the app is run on Docker, Fly, Render, Coolify, or similar platforms.
Live Data Shows 77% of Austrian Truck Parking Fills Up Overnight, Stranding Drivers
EU regulation 561/2006 mandates strict driving-hour limits for truck drivers but says nothing about whether parking is actually available when rest breaks are required. Analysis of real-time occupancy data from 85 Austrian motorway truck-parking sites — polled every 60 seconds since June 2026 — shows network-wide occupancy nearly doubles from around 38% at 11:00 to over 76% by 21:00, remaining at that plateau until roughly 4:00 a.m. Critically, the load is unevenly distributed: 40 of the 86 monitored sites recorded zero free bays at least once in the past 30 days, and 33 sites were completely full at some point during the 21:00 hour alone. A typical site like Wiener Neustadt, with 40 bays, averages fewer than 6 free spaces by 20:00 and has hit zero in every evening hour between 18:00 and 23:00. Static mapping tools continue to display full site capacity regardless of actual availability, leaving dispatchers and drivers without the real-time insight needed to plan legally compliant rest stops.
Why One Developer Writes Two Separate Release Notes for Every Shipped Update
A developer at Burning Tribe has adopted a practice of writing two distinct release notes for every software update instead of a single shared changelog. The first note, aimed at users, is limited to three lines and describes only observable changes in plain language, omitting internal details like library versions or refactors. The second is a private note for the developer's future self, recording what problem was being solved, what approaches were tried and discarded, and what conditions might prompt revisiting the decision. Keeping the two notes separate prevents the common pitfall of writing for mixed audiences, which the developer says caused them to quietly abandon a single changelog over time. The author argues that drafting the user-facing note first also helps catch half-finished or bundled changes before deployment, making it a lightweight quality check.
Claude Code's auto memory feature found mostly empty across 21 real-world projects
An audit of Claude Code's auto memory feature across 21 project directories on a single Mac revealed that 17 were completely empty, despite the feature being enabled by default. The remaining four directories contained two to four notes each, and three of those independently recorded the same correction — highlighting that memory does not sync across repositories. Auto memory, distinct from the user-written CLAUDE.md file, allows Claude to save session notes such as user preferences, feedback, project decisions, and references into per-repository directories under ~/.claude/projects/. The feature has a load limit of 200 lines or 25KB at conversation start, is machine-local, and is not shared with subagents. The author chose to disable auto memory in one high-stakes repository running an autonomous agent, citing concerns beyond context size.

n8n Launches AI Assistant in Preview to Build Automation Workflows via Plain Language
n8n has released n8n Assistant, a preview AI-powered tool that converts plain-language descriptions into editable automation workflows on its canvas. The feature is available by default on new n8n Cloud instances and for self-hosted Docker deployments running version 2.36 or later. Unlike black-box AI generators, the assistant creates standard n8n workflows that teams can inspect, modify, and debug using execution history and node-level logs. It can also request credentials, run the workflow, and suggest fixes when errors occur, though human review of logic, permissions, and third-party configuration remains necessary. n8n has flagged the feature as still in active development and advises users to thoroughly test generated workflows before deploying them in critical processes.
pypdf silently fails to check boxes when wrong on-state string is passed
A quirk in pypdf's update_page_form_field_values() allows developers to set a checkbox value using strings like 'Yes', 'true', '1', or Python's True boolean, yet the box remains visually unchecked in PDF viewers. The function returns no error, raises no exception, and logs nothing, even though the underlying field value and appearance state are never actually updated. This happens because PDF checkboxes have no universal on-state name — the checked value is defined per field inside the document's own appearance dictionary, commonly '/Yes' but sometimes '/On', '/1', or a custom string. The only reliable fix is to read the correct on-state string directly from the PDF field's '_States_' list at runtime, rather than hardcoding an assumed value. Developers using pypdf 6.18.0 should update their form-filling logic to dynamically retrieve the field-specific on-state before calling the update function.
BeaconKVM Lets You Access BIOS and Fix Crashed PCs Remotely via Browser
BeaconKVM is a hardware-based KVM device that allows users to remotely access a computer at the BIOS level, even when the operating system has crashed or is unresponsive. Unlike conventional remote desktop tools such as TeamViewer, a KVM works by acting as a virtual monitor, keyboard, and mouse, enabling control before the OS loads. Users set up the device by purchasing or building it on a Raspberry Pi 4B, registering it via a QR code, and then accessing it through the Beacon Console in a browser. The solution supports BIOS-level tasks like changing settings or reinstalling an operating system remotely, without requiring third-party networking tools like Tailscale or ZeroTier. BeaconKVM is designed for non-technical users and small businesses, with no monthly subscription fee.

Hackers Use Google Sheets and Tampermonkey to Steal Crypto via Browser Hijack
Cisco Talos has disclosed a high-priority ClickFix campaign in which attackers distribute fake cryptocurrency API vulnerability reports through forums and Telegram to trick users into pasting malicious JavaScript into their own browsers. The injected code establishes persistence via the Tampermonkey browser extension and fetches obfuscated scripts from publicly accessible Google Sheets using the Google Visualization API. Once active, the scripts hook browser fetch requests and clipboard activity, silently replacing legitimate cryptocurrency deposit addresses with attacker-controlled ones. Because the campaign relies entirely on legitimate Google infrastructure and user-trusted sites, the malicious traffic blends into normal browsing activity and largely evades detection. Security researchers recommend managing browser extension allowlists, monitoring script retrievals from Google Sheets APIs, and independently verifying destination wallet addresses through a separate trusted channel.
ClearFake Campaign Uses WebDAV and Fake CAPTCHAs to Deploy Stealers and Remote Access Tools
Cisco Talos has identified a ClearFake attack campaign, tracked as UAT-10820, that uses fake Google CAPTCHA pages to trick users into pasting malicious commands into the Windows Run dialog. The infection chain leverages WebDAV and BNB Smart Chain to deliver malware, with rundll32.exe loading DLLs remotely to deploy the Amatera stealer. One attack branch also installs ZigCryptoStealer and a Go-based reverse proxy, and attempts to disable endpoint detection using a vulnerable driver. A separate branch, observed at a Ukrainian government organization, progresses from Amatera to an unauthorized NetSupport Manager installation for persistent remote access. Talos recommends blocking rundll32.exe execution from internet UNC paths, restricting WebDAV access, and educating users not to paste commands from browser instructions into system dialogs.
Critical SAP NetWeaver Flaw CVE-2026-58240 Allows Unauthenticated Cluster-Wide RCE
A critical vulnerability tracked as CVE-2026-58240, dubbed S4GET, has been disclosed by Onapsis on September 8, 2026, affecting SAP NetWeaver Message Server. The flaw allows an unauthenticated attacker to manipulate the Message Server into treating their IP address as a trusted cluster host, subsequently enabling OS command execution via SAP Gateway with administrator-level privileges. Commands run as the 'adm' OS user across all application servers in the cluster, potentially enabling credential theft, backdoor installation, and lateral movement. SAP has issued Security Note 3759472 with patches across multiple kernel branches, and administrators are urged to restrict SAP GUI connection sources and remove direct internet exposure of the Message Server port. No real-world exploitation has been publicly reported, but the attack requires no user interaction and poses severe risk to any reachable SAP deployment.
Critical SAP Kernel Flaw CVE-2026-44756 Allows Pre-Auth Remote Code Execution
A maximum-severity vulnerability dubbed OVERPASS (CVE-2026-44756, CVSS 10.0) has been disclosed in the SAP Kernel, affecting products including SAP NetWeaver AS ABAP, SAP Web Dispatcher, and SAP S/4HANA. The flaw is a buffer overflow in Extended Passport (EPP) processing that can be triggered before any authentication takes place, allowing attackers to execute arbitrary OS commands with SAP administrative privileges. It is exploitable remotely over HTTP(S), SAP GUI, or RFC, requiring no valid SAP account or user interaction. SAP addressed the issue through Security Note 3747649, published on its September 2026 Security Patch Day, and urges organizations to prioritize patching internet-facing systems first. Until patches are applied, SAP recommends restricting access via SAProuter, jump hosts, and Web Dispatcher, while monitoring for application-layer anomalies and suspicious SAP process activity.