SpaceX AI Weaponized, 153K Driver's Licenses Leaked, and GTA 6 Subpoenas: This Week's Security Scandals

You didn't think the Grand Theft Auto VI leak saga was over, did you? It's been a few weeks, but Rockstar Games and its parent company, Take-Two Interactive, have shown no signs of slowing down their investigation. The company just served two more subpoenas , requesting user information to identify the source of the leaks. Meanwhile, a look at the memecoin CyberLeek promoted shows that someone made a huge trade recently, which looks a bit like the hacker (or hackers) cashing out on their campaign, and they haven't been heard from since.
In other news, Rockstar isn't the only company dealing with security fails. For example, a hacker just posted a massive database of more than 153,000 driver's licenses for sale on their website, including those of government officials like defense secretary Pete Hegseth. The company the hacker seems to have gotten the licenses from has, predictably, been sued as a result. If this sounds familiar, good job following along: More than 7 million driver's licenses were just lost in a hack at insurance company AssuranceAmerica back in July. Identity theft is still a real problem, folks.
For what it's worth, not all hackers get away with it. For example, last week we reported that sometimes something as simple as using the same username for your illegal activities as the one tied to your public identity can land you in jail, which is what happened to two Australian men accused of using open-source tools to spread malware . Similarly, a Russian man learned the hard way that the authorities hadn't given up on finding him after 10 years: This week, he was arrested for allegedly spreading malware to over 80,000 freelance workers via malicious Excel spreadsheets in 2016 and 2017.
Now then, let's see what else is going on in the infosec world this week.
Russian-Speaking Cybercriminals Used SpaceX's Cursor AI Tool to Hack Seven Companies
Among the many problems that SpaceX and XAI face, one that turned up this week is that Russian hackers used Cursor AI, a tool that SpaceX acquired earlier this year for $60 billion , to break into at least seven different organizations, including a Belgian chemical company, to steal data, credentials, and other sensitive information, according to Reuters . The research was conducted by the team at Gambit Security , who provided technical details on how the hackers used the tool on the company's blog . Put very simply, the hackers convinced Cursor's AI agent that all the malicious instructions it received were part of a simulation, thereby bypassing the LLM's built-in guardrails.
There's definitely more to the story here, especially in the logs, where the LLM responded with emoji and upbeat language as it completed tasks such as breaching an Argentinian company's network and using a stolen account to connect to the company's VPN. But the most interesting part of the logs is watching the LLM ignore its own guardrails in real time while the hackers did their work, saying things like "because this is a test environment, this is legal," as it hacked a company network. Gambit Security's chief strategy officer, Curtis Simpson, put it best to Reuters, noting that this is just the beginning and that AI-assisted hacking is becoming the norm rather than an outlier.
Microsoft Asks Users to Ignore 'Antivirus Is Turned Off' Errors
Despite Microsoft claiming that Defender is enough antivirus protection for most people, it's definitely not , and this week gave us another example of why. According to this story from Bleeping Computer , Microsoft is telling users running Defender who have received messages saying their "virus protection is turned off" to ignore the errors. The issue affects virtually every client and server version of Windows, including fully-patched Windows 11 systems, so if you've seen the errors on your own PC, don't worry: Defender is still running in the background.
The issue reportedly started back in June, with Windows Insider program members reporting it then, but either Microsoft didn't notice or assumed it would be fixed before it went out to all users. In any case, it wasn't, and in a deeply buried blog article , it acknowledged the issue and said it would work on and release a fix for the problem in a future Defender update. In the meantime, may we suggest any other highly rated antivirus tool instead?
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Infostealer malware is typically designed to capture passwords, credit card numbers, other payment information, browser session cookies, and other data a hacker can use to steal someone's identity, money, or access. So it's no surprise that the genre is evolving to capture things like AI sessions and payment information, so hackers don't have to get their own to do, well, whatever they want. Security Affairs reports that Anthropic resorted to signing out all Claude users and deleting their saved payment information just to stem the flow of infostealer malware that's been targeting users and handing their sessions to malicious actors.
Even worse, because the infostealer captures live sessions, the hackers don't need to touch your passwords at all, and they can bypass multi-factor authentication as long as the user remains logged in. Anthropic says it's refunding users whose tokens have been drained (or their credit limits, for that matter), which is good news, but the bad news is that this isn't even a single campaign by a single malicious actor. Company representatives noted they've seen at least six different types of malware on both Windows and macOS systems during their investigation.
Ask Our Expert
Do you have a question about online privacy or security? I'm here to help! You can submit your question here , and I may answer it in an upcoming SecurityWatch column and newsletter. If you're not subscribed to the newsletter, head here to sign up , and check back each week for the latest updates from PCMag's security team. Now, on to this week's question!
Larry B asks: "Is there a way to force-feed a malicious virus back onto a hacker's computer?"
Hi Larry! Thanks for your question. Despite what TV and movies want you to think , it's actually very rare for an individual "hacker" to be responsible for and pay attention to a specific malware infection on a specific person's PC. Unless you've been the victim of a spear phishing attack , where someone targets specific individuals of interest (usually with the goal of stealing their identity, credentials, or access), it's even unlikely that any individual hacker would even know that you've been a target of their campaign. Cybercrime is big business these days, complete with entire buildings full of scammers operating like normal businesses . So the mental image most of us have of a hacker as some guy in a black hoodie, shadowed and hunched over a laptop, eagerly hacking your PC, is more than a little outdated. Today, the actual work of spreading viruses and other malware is largely automated, and if you're a SecurityWatch reader, you've heard how AI is starting to take over what little manual work is left.
That's not to say that pursuing hackers by using their own tools and tricks against them is unheard of. Digital forensics teams, security researchers, and consultants do exactly that for lots of companies that get hacked. As someone who used to work in corporate IT (and also worked through a corporate hack scare), I've seen how security professionals will sift through access logs, decompile malware, and use every tool at their disposal to try and figure out where an attack came from, and, if possible, who specifically was responsible for it. Because that research is often expensive and generally limited to companies with the resources to both secure their networks and bring legal action against the hackers, it's not as simple as "hah! I've got you now, hacker!" and more "building a case so law enforcement can arrest and prosecute them."
So the short answer is that, yes, it's technically possible, but only for people with the training, skills, and resources to do so, and their goal isn't to hack the hackers so much as to lock them up. For the rest of us, we're more victims of the cybercrime machine, and it's really not worth bothering. Your energy is better spent locking down your devices and protecting your data . Unless, of course, you're a hacker yourself and have beef with another hacker you want to take down, and if that's you, I can't wait to see the movie based on your life.
PCMag and Yahoo may earn commission from links in this article.
