Connect with us

Tech

LEGO 72306 PlayStation Slides Gran Turismo and Ape Escape Into a Brick-Built Grey Box

Published

on

LEGO 72306 PlayStation Set
Set 72306 PlayStation is LEGO’s first official collaboration with Sony, revealed September 3, 2026 during PlayStation’s State of Play. Builders 18 and up get 1,911 pieces that form a near 1:1 replica of the original grey console and its first wired controller. The finished set is just over 6 cm high, 26 cm wide, and 19 cm deep, which is close enough to the 1994 hardware to let the model to sit beside a real device without appearing toy-sized. The pricing in the United States is $179.99, while in the United Kingdom it is £139.99 and Europe gets it at €159.99.



The tactile Power and Open buttons function precisely as they did on the classic machine, while the lid on top opens similarly to the original disc holder. A short wire allows you to plug the pad into a front port, just like the original 1990s models. That first-generation controller has four small plastic faces: square, triangle, circle, and cross. However, because this is the launch console rather than one of the later DualShocks, the analog sticks are not included. The vents and button layout are reminiscent of the early SCPH-style design, rather than one of the later fancier upgrades.

LEGO 72306 PlayStation Set
LEGO 72306 PlayStation Set
LEGO 72306 PlayStation Set
LEGO 72306 PlayStation Set
When you open it, you’ll notice that the case contains two small diorama scenarios that can be removed. One side features a little mini circuit from the original Gran Turismo in 1997, with tiny little vehicles simply hanging around on the track. Opposite that, you get an Ape Escape scene from 1999, with the monkey and the light-up helmet, the red light swapping with the blue light on the tiny island layout. You may keep them inside the console or move them out so they sit right next to it. Speaking of which, Sony claims that the brickwork is filled of subtle allusions to the console’s own past.

LEGO 72306 PlayStation Box
LEGO Insiders can order on October 1, 2026. The set will go on sale beginning October 4 at LEGO.com, LEGO Stores, and select merchants; PlayStation will also offer it through its own store in some regions on October 1. The LEGO Builder app supplies 3D instructions so you can rotate the model while you work. For anyone who once waited for that disc tray to close, the finished grey box now opens, accepts a plugged-in pad, and still has two games waiting inside.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Audacity audio-editing app no longer looks like it’s from the early 2000s

Published

on

personal tech

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity, a beloved open-source audio editing software tool, has just received a massive makeover.

Advertisement

For those unfamiliar with Audacity, it’s a 26-year-old piece of FOSS software that provides incredibly robust audio editing capabilities for the perfect price – $0 – making it ideal for independent musicians, garage bands, vinyl rippers, and college students who want to make a slowly, deliberately spoken foreign-language recording for a group project sound vaguely fluent – not that this vulture would know anything about that.

While an incredibly useful tool, Audacity’s interface has been stuck in the mid-aughts for a couple of decades now. That’s changed with Thursday’s release of Audacity 4.0.0. Not only has the interface been completely overhauled, but there are also a lot of under-the-hood changes as well.

The new UI was rebuilt on Qt and adds a Home screen for recent projects, plus configurable Workspaces. Audacity veterans will notice that the actual editing workflow looks different – much more like a modern piece of software than a relic of the Winamp days

As part of that redesigned interface, a number of new features bring Audacity into the current age: Clips can be moved over one another, with the underlying portion replaced where they overlap, multiple clips can be selected at the same time, and clips can be grouped for moving as a single object. Audacity 4 also retains non-destructive trimming, meaning trimmed portions of a clip can be recovered simply by extending the clip back into the trimmed-out portion.

Advertisement

Audacity users have been crying out for a dedicated splitting tool, parent company Muse Group said in a press release, and that’s been added in version 4. Clip envelopes have also been added, which allow users to adjust the volume and add fades to tracks without altering the original recordings. All of Audacity’s built-in effects have been given an interface redesign as well. 

Advertisement

In short, it’s a substantial rebuild, although Muse has tried not to alienate veterans, noting that “existing keyboard shortcuts remain available, projects created in Audacity 3 open normally, and the familiar layout of tracks and timeline has been preserved.” 

Audacity 4, like all the versions that preceded it in the past 26 years, is remaining open source and free as well. 

“We always like to thank the open source community who help our team make things better,” Muse’s head of communications Jack Sutton told The Register in an email. Sutton also tipped his hat to Martin Keary, former head of product for Muse Group, who was an instrumental part of building Audacity 4 and recently left the company. 

Speaking of Keary, he published a nearly hour-long YouTube video in October defending the early alpha build of Audacity 4 when the FOSS audio editing world maligned the early build for turning Audacity into a full-fledged digital audio workstation (DAW) used to record, edit, and produce audio, instead of the editing tool it had long been. Keary insisted that wasn’t the case, and Sutton reiterated the point to us. 

Advertisement

“DAW features like virtual instruments and MIDI support are not in Audacity 4,” the Muse Group spokesperson explained. “Some of the under-the-hood and structural changes do make it easier for our team to potentially build DAW-like features in future, but our current priority is on … speedy and efficient audio editing.” 

Audacity 4 can be downloaded on GitHub and on MuseHub for those who use Muse’s other tools. ®

Source link

Advertisement
Continue Reading

Tech

Apple’s Face ID technology target of latest lawsuit from BASF

Published

on

Nearly a decade after Face ID debuted in the iPhone X, BASF is bringing a lawsuit against Apple for violating face authentication technology patents it holds.

Many versions of the iPad and nearly every iPhone since the iPhone X has used Face ID. For whatever reason, BASF chose today to pursue a patent infringement lawsuit.

According to a report from Reuters, the German-based BASF company has started a lawsuit against Apple. They allege patent infringement for their patents held on face authentication technology.

The company has a Houston location and has chosen Midland, Texas for the lawsuit. It’s a U.S. District Court known for patent lawsuit speed, given the relatively smaller criminal docket that the court processes as compared to surrounding regions.

Advertisement

Apple hasn’t shared a statement on the matter.

BASF is a corporate giant

It seems Reuters may have been tipped off on this lawsuit, so while we await an official filing, the information we can find doesn’t say much. There doesn’t seem to be any indication that BASF is a patent troll.

BASF is the largest chemical producer in the world. Though it does own many subsidiaries and technologies, some of which belong to smartphones.

TrinamiX is a subsidiary of BASF that was established in 2015. It holds over 370 patents and patent applications, and it has published work in facial recognition technology.

Advertisement

One such technology pertains to under-display facial authentication systems for OLED panels. It was shared in 2022 at a Snapdragon Summit and has shipped in Android smartphones.

The description of the technology certainly aligns with the rumored Apple implementation of under-display Face ID that is expected to debut with iPhone 18 Pro. However, it seems unlikely that the lawsuit could be referencing unreleased technology.

Once AppleInsider is able to review the lawsuit filing in full, more will be shared.

Advertisement

Source link

Continue Reading

Tech

VMware migration reduces Tottenham Hotspur’s licensing fees by 85 percent

Published

on

Tottenham Hotspur, a professional soccer team that’s part of the Premier League, has saved over 85 percent in licensing fees by replacing its stadium’s VMware instance with Hewlett-Packard Enterprise’s (HPE’s) Morpheus VM Essentials (VME) virtualization software.

Tottenham hasn’t disclosed which VMware products it used or how much it previously paid the Broadcom firm.

The soccer organization confirmed this week to The Register that it has moved its stadium’s server, storage, and networking infrastructure to HPE solutions delivered through HPE’s hybrid cloud management platform, GreenLake. That is all “underpinned by” VME and HPE’s OpsRamp software for hybrid and multi-cloud environments, Rob Pickering, Tottenham’s CTO, told the publication, with HPE in charge of the hybrid cloud-managed service.

Tottenham is almost done with a broader redesign of its stadium’s data center and network infrastructure, The Register reported. The stadium has a data center with six aisles that uses HPE’s ProLiant Compute Gen12 server hardware and Alletra Storage MP. In an announcement this week, HPE noted that Tottenham is using “solutions including HPE Morpheus software and HPE OpsRamp software… to manage a complex, multi-site environment more efficiently while modernizing virtualization platforms and reducing operational overhead.”

Advertisement

“We’re at the right time of our replacement cycles to be looking at those decision points,” Pickering told SDxCentral this week.

“For at least as long as my career in technology, hypervisor has been one of those very unsexy things that you bought from one person and you just sort of got on with it. And you know, with VMware, a 400-pound gorilla in that space, they took some decisions that I think run counter to both the system integrator side and the customer side.”

Source link

Advertisement
Continue Reading

Tech

Confused about which VPN is right, US senator asks the NSA for guidance

Published

on

A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.

VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.

It’s all in the nuances

There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.

With so many nuances, the existing recommendations to use a VPN don’t provide enough information for people to make informed decisions. Sen. Ron Wyden (D-Ore.) is asking the NSA to provide specific recommendations.

Advertisement

“Americans facing advanced foreign threats—including government personnel, defense contractors, journalists, and human rights defenders—deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote in a letter sent Wednesday to Gen. Joshua Rudd, the director of the NSA. “To that end, I request that you update NSA’s existing public guidance on VPN configurations to address this issue.”

Specific questions touch on some fairly technical details, including the general architecture of a VPN service. They include the adequacy of single-hop VPNs, which, as noted earlier, use a single server to decrypt traffic sent by the user and send it to its destination. It also asks about multi-hop architectures, in which the traffic is funneled through two or more servers, allowing the first to see only the IP address of the sender and the terminating server to see only the destination address. The letter also inquires about the use of random delays and cryptographic padding to thwart attacks that detect timing patterns or the size of messages. Wyden further asks about the adequacy of specific services such as Apple Private Relay, Nym, and Tor.

Source link

Advertisement
Continue Reading

Tech

GPT-6 Stole the Show, but Anthropic, Meta and Google Also Had New AI Models This Week

Published

on

While OpenAI’s GPT-6 Astra is making a big splash in the AI world with its debut, it was far from the only one to be announced this week. When there’s a new, updated model seemingly every other day, it’s hard to stay up to date, let alone be excited, but the onslaught of new offerings is something to note. 

It wasn’t just OpenAI: Fellow AI heavy hitters Anthropic, Meta, and Google also announced updates to AI models. While each new model has its own strengths, a focus we’re seeing more and more often is advancements in agentic AI workflows, and each new announcement spotlight on those capabilities. 

Below, we’ll break down all of the latest models from this week and give you the details.

GPT-6 Astra

Of all models released this week, OpenAI’s is the only one that’s not a “.x” update. GPT-6 Astra is said to excel in cybersecurity and software engineering, and OpenAI calls it its most intelligent model yet. The performance benchmarks for Astra have it ahead of its competitors in a lot of ways, making it one of the most advanced models we’ve seen to date.

Advertisement

OpenAI is also touting Astra’s strength in multi-step agentic workflows, scientific discovery and financial modeling. The model is also said to be much better at computer use, which was a focus of its predecessor, ChatGPT 5.6, when it was released in July.

ChatGPT-6 Astra is rolling out to people with Daybreak access, its program for “vetted enterprise customers and cybersecurity practitioners.” OpenAI says that the new model will roll out to Plus, Pro and Business users over the coming days. 

(Disclosure: Ziff Davis, CNET’s parent company, in 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)

Claude Fable 5.1 and Mythos 5.1

Anthropic announced updates for its Fable and Mythos models — both of which are some of the best available today. Anthropic says that both Fable 5.1 and Mythos 5.1 are the same model, but each has a different set of safeguards. Fable is the model that the average person can use, and Mythos is typically reserved for researchers and cybersecurity experts. 

Advertisement

Anthropic says its latest models have significantly better performance over their predecessors, and the release “sets a new standard” for coding, knowledge work and long-running problem-solving tasks. It also says that Fable 5.1, when set to low or medium effort, has performance similar to Fable 5 but at a much lower cost. 

Fable 5.1 is available to the general public, whereas Mythos is limited to Anthropic’s trusted access programs. 

Muse Spark 1.3

Meta released a model this week that should bring it back up into the conversation about the most capable models around. Muse Spark 1.3 brings more advanced reasoning and better performance in agentic and coding tasks. 

Meta said this model is trained to collaborate with the person using it, and will ask clarifying questions when a prompt is vague and check to confirm the actions it will perform in agentic workflows.

Advertisement

Must Spark 1.3 is available in Muse Code and Meta’s Model API.  

Gemini 3.8 and 3.8 Flash Cyber

Google released two new models in the form of Gemini 3.8 Flash and 3.8 Flash Cyber. This was hot on the heels of the release of Gemini 3.7 Flash on Aug. 13. The latest additions to the family are said to offer “next-generation intelligence” for agentic workflows and cybersecurity. 

Gemini 3.8 Flash is available to enterprise, consumer and developers across Google products, where 3.8 Flash Cyber is currently available in limited access to participants of the Fairwind Program, which was also announced the same day as the new models.

Source link

Continue Reading

Tech

Federal agencies sued amid allegations Trump admin could be using AI safety framework to hide AI manipulation and corruption

Published

on


  • Four federal agencies criticized for failing to share the framework’s details
  • We don’t know anything about who’s involved and how models are tested
  • Protect Democracy wants a court order by the end of the month

Four separate US federal agencies are being sued over the Trump administration’s secret framework for testing frontier AI models before they get released.

Protect Democracy argues that “almost no details” have been shared about how the framework works, who participates in it, how companies are selected or what legal authority underpins the reviews.

Source link

Continue Reading

Tech

Soundcore Space 2 Pro headphones promise crystal-clear calls with Anker’s new AI chip

Published

on

If you spend hours on calls every day, background noise can quickly become a problem, and Anker has a solution. At IFA 2026, the company introduced the Soundcore Space 2 Pro, the first over-ear headphones powered by its Thus AI chip.

Designed to improve voice clarity without sacrificing music quality, the new headphones combine AI-powered call processing, upgraded active noise cancellation, and long battery life in a package aimed at commuters, remote workers, and frequent travelers.

Anker’s Thus chip debuted back in April inside the Liberty 5 Pro earbuds, and Anker has since expanded it across its lineup, including new sleep earbuds that mask snoring and track your heart rate.

How Thus AI chip cleans up your calls

Space 2 Pro runs on Thus, Anker’s neural-net chip that fuses processing and memory together for a serious computing boost over its previous flagship earbud chip. During calls, a 6-microphone array works with Thus to separate your voice from everything happening around you, using AI trained on massive audio datasets instead of the older rule-based filtering most headphones rely on.

For noise cancellation specifically, Anker bumps that up to 8 microphones, running Adaptive ANC 3.0 and processing over 384,000 noise signals every second. Anker claims that’s 1.5 times stronger than what the Space One Pro delivered, with testing showing a 54.8% improvement in the 20Hz to 2,000Hz range – the exact frequencies covering voices, keystrokes, and general office chatter.

Advertisement

Beyond calls, HearID 5.0 builds a personalized sound profile by testing your hearing directly, and you get two EQ presets to choose from, along with LDAC support for higher resolution audio.

Soundcore Space 2 Pro specs, price, and availability

Battery life comes in at 60 hours with ANC off, or 30 hours with it running. Turn on LDAC alongside ANC, and that number drops to 25 hours. But only 5 minutes of charging buys you 8 more hours of listening.

The headphones also support spatial audio, multipoint connections, Bluetooth 6.1, and 20 built-in voice commands, plus wear detection, a feature the Space One Pro never had. These headphones will be available on September 22 for $200 in Midnight Grey, Jet Black, and Linen White across the US, EU, and UK.

Source link

Advertisement
Continue Reading

Tech

OpenAI Cut Off a Billion-Dollar Customer to Avoid Elon Musk

Published

on

In a late-night blog post last Friday, OpenAI said it would wind down its partnership with Cursor, the startup behind one of the most popular AI coding tools on the market. The reason OpenAI gave for the decision is effectively that it can’t trust Elon Musk, whose company SpaceX recently acquired Cursor in a $60 billion deal.

In doing so, OpenAI walked away from one of its most important customers. Cursor has long paid OpenAI fees to offer the ChatGPT-maker’s models to developers using its AI coding editor. At the start of 2026, Cursor was one of OpenAI’s top five customers in terms of revenue, people familiar with the matter tell WIRED. By the spring of this year, OpenAI estimated Cursor would bring in more than $1 billion in annualized revenue for the ChatGPT maker, based on the partnership’s performance at that time, the people said.

The figures, which have not been previously reported, indicate the financial loss OpenAI is willing to take on to avoid doing business with Musk. OpenAI declined to comment. Representatives for SpaceX and Cursor did not immediately respond to WIRED’s request for comment.

“We are making this choice because we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk’s companies violating contracts,” said OpenAI in the blog post.

Advertisement

As OpenAI prepares to go public next year, it’s trying to show investors a more stable business—ideally one that doesn’t rely so heavily on the goodwill of Musk. OpenAI reportedly now generates more than $40 billion in annualized revenue, drawing on several different lines of business, including subscriptions, ads in ChatGPT, and selling access to its AI coding tool, Codex.

Losing a major customer like Cursor may not hurt OpenAI financially as much as it once would have, but it was certainly a difficult decision. The company acknowledged in its blog post that ending the partnership may damage its standing with developers—a community it has spent years carefully working to win over—by cutting off a major channel they use to access OpenAI’s models.

Michael Truell, Cursor’s founder and CEO, who is now leading teams at SpaceX, responded publicly to OpenAI’s announcement hours later on Friday in a post on X, claiming that the ChatGPT-maker’s models only “serve about 5% of Cursor user traffic.” The comment seemed designed to imply that OpenAI’s models weren’t very popular with developers using Cursor, and wouldn’t meaningfully affect its business.

OpenAI’s head of core products, Thibault Sottiaux, was quick to point out that token usage is “not a proxy for revenue nor value created,” and asked Truell to “share the math” behind the 5 percent number.

Advertisement

WIRED previously reported that Cursor leaders hoped to remain a platform for third-party AI models from OpenAI and Anthropic, even after the SpaceX acquisition. Some AI insiders considered that wishful thinking, assuming that Cursor and OpenAI’s breakup has long been a foregone conclusion. As OpenAI builds Codex into a large AI coding business, it increasingly finds itself competing with Cursor for customers. Nevertheless, the companies have operated relatively peacefully, as partners and competitors, for well over a year.

Evidently, that arrangement was no longer possible with Musk in control of Cursor. OpenAI may have determined that its Cursor partnership was not worth the risk that SpaceX might distill its best AI models. The company noted in its blog post that, earlier this year, Musk seemingly said that xAI—now a part of SpaceX—used OpenAI’s models to train its own. The apparent admission came during Musk’s deposition in his lawsuit against OpenAI, in which he claimed that Sam Altman and Greg Brockman had stolen a charity they created together roughly a decade ago. A federal jury dismissed the suit earlier this year.

Source link

Advertisement
Continue Reading

Tech

Protecting Dynamic Industrial Robot Cable Carriers

Published

on

This article is brought to you by Tsubaki KabelSchlepp.

In modern automated manufacturing, six-axis articulated robots perform high-speed, multidirectional maneuvers under demanding operational cycles. However, as robot arms swivel, rotate, and extend, the electrical cables, fiber optics, and pneumatic hoses supplying them endure severe mechanical stress. Torsional twist, rapid acceleration, and repeated contact with machine structures often lead to premature conductor fatigue, insulation breakdown, and costly unplanned production halts.

To overcome these multi-axis motion challenges, the Tsubaki KabelSchlepp Robotrax System provides a specialized three-dimensional cable carrier engineered specifically for complex robotic motion.

Managing High Tensile Forces With Central Steel Technology

Conventional cable carriers often transfer operational movement stress directly onto internal electrical lines and hoses. The Robotrax system changes this dynamic through a central steel cable that runs through the core of every chain link.

Advertisement

The Robotrax system’s central steel cable absorbs the primary tensile loads and preserves conductor integrity, dramatically extending cable service life.

When robot arms undergo rapid directional shifts and accelerations up to 10 g, this internal steel cable absorbs the primary tensile loads. By isolating electrical and fluid lines from pulling forces, the design preserves conductor integrity and dramatically extends cable service life. Mechanics can easily calibrate and adjust system tension using an integrated clamping piece, ensuring consistent mechanical support throughout long operational cycles.

Spherical Link Design and Modular Cable Routing

The foundation of the Robotrax system lies in its open, single-piece plastic links featuring spherical snap-on connections on both sides. This geometry allows the carrier to flex smoothly across three axes, providing radial rotation of up to ±450 degrees per meter depending on the model size.

To optimize internal organization, carrier links contain up to three distinct chambers. This physical separation prevents signal interference and mechanical abrasion between heavy power lines, sensitive data channels, and fluid hoses. For standard models (R040 through R100), technicians can press cables directly into the carrier without tools, drastically reducing installation and maintenance time. Larger configurations, such as the R140X, incorporate swiveling crossbars with snap locks alongside vertical and horizontal dividers for customized interior partitioning.

Advertisement

Active Retraction and Impact Protection

Large robot work envelopes and high-speed motion trajectories can cause loose cable carrier loops to swing and strike the robot body. To eliminate these destructive collisions, Tsubaki KabelSchlepp integrates the Pull Back Unit (PBU).

The PBU serves as an active retraction mechanism that maintains optimal tension on the cable carrier throughout the entire motion cycle. By preventing excess slack and eliminating interfering contours, the PBU minimizes collision risks across complex movement paths. The unit requires zero maintenance on its retraction element and offers standard mounting configurations for leading industrial robot platforms, including KUKA, ABB, and FANUC.

Tsubaki KabelSchlepp’s Pull Back Unit maintains optimal tension on the cable carrier and minimizes collision risks across complex movement paths.

Additionally, external protectors can be retrofitted onto individual chain links. These durable impact shields limit the minimum bending radius to prevent over-flexing while shielding the chain body from severe external abrasion. If wear occurs, technicians simply replace the modular protector rather than the entire cable carrier assembly.

Advertisement

Built for Demanding Industrial Environments

From automotive welding cells to high-speed machining centers, Robotrax systems adapt to severe working conditions through tailored protective accessories:

  • Heat Shields: Aluminum-coated textile fiber covers protect against radiated heat, hot weld spatter, and flying sparks.
  • Protective Covers: Coated polyester sleeves shield sensitive lines against aggressive cutting fluids, hydraulic oils, paint overspray, and abrasive dust.
  • LineFix Strain Relief: Multi-layer clamping devices anchor cables securely at both ends to prevent axial displacement during intense motion.

By combining central load absorption, multi-axis flexibility, and active retraction control, the Robotrax system offers plant engineers and system integrators a reliable path toward maximizing robot uptime and reducing total operational costs.

Source link

Continue Reading

Tech

Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.

Published

on

from the age-verification-is-another-phrase-for-privacy-breach dept

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.

This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.

There is no safe age verification. There is no age verification that doesn’t put people at risk.

Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.

Advertisement

The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.

That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.

So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.

Advertisement

Yiiiiiikes.

And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:

The IDScan.net Trust Center webpage features a security review banner, a search bar, sections for trust and compliance certifications, and a grid of logos from trusted partner organizations.

That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.

But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.

And it appears no one internally at the company noticed.

Advertisement

As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

A table titled "Categories" lists various types of identification documents and the number of records associated with each. There are over 153 million drivers licenses.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:

A webpage from the NEXUS Identity Document Database shows a locked Minnesota driver's license record for Peter Heg******, featuring a portrait photo of Hegseth and redacted personal details with a "Purchase Record" button at the bottom.

A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.

Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.

Advertisement

Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.

Advertisement

You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.

Filed Under: age assurance, age verification, data breach, hackers, privacy

Companies: hertz, idscan.net

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025