DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
HIGH#dark web

AssuranceAmerica Discloses Breach of 6.99M Drivers' License Records — Largest Known U.S. DL Theft of 2026

Atlanta-based auto insurer AssuranceAmerica has formally notified 6,998,886 individuals after attackers compromised a single employee credential on March 16, 2026, and exfiltrated files containing names, contact details, insurance policy data, claims information, and driver's license numbers across its 14-state, 9,500-agent network. The forensic review was not completed until June 15 — a 91-day gap between breach and conclusion — making this the largest publicly disclosed theft of U.S. driver's license data in 2026 and a high-value ingest for identity fraud, account-opening attacks, and downstream phishing operations. The company has not disclosed the specific initial access vector, though credential compromise of a single employee account is consistent with an infostealer or targeted phishing precursor.

The forensic review was not completed until June 15 — a 91-day gap between breach and conclusion — making this the largest publicly disclosed theft of U.S.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn