McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related data records. McKesson says it discovered the intrusion on August 25 and that its investigation is still in its early stages, while the attackers claim they used vishing calls against employees to compromise Okta single sign-on accounts and pivot into Salesforce and Snowflake environments, demanding over $55 million after McKesson allegedly failed to respond.
More Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut has shipped a second emergency patch after researchers found the first fix for two actively exploited zero-days could be bypassed, with the chained flaws allowing unauthenticated attackers to bypass authentication and achieve remote code execution on PaperCut NG/MF print management servers. The vulnerabilities have since been added to CISA’s Known Exploited Vulnerabilities catalog, and roughly 1,000 instances remain exposed to the internet, most of them in North America and Europe.
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors linked to the Aurora ransomware operation have been caught driving SpaceX’s Cursor coding agent through hands-on network exploitation, using it to plan attacks, scan for privileged accounts, and attempt authentication-relay attacks across at least ten victim organizations between April and May. Researchers who found the group’s exposed infrastructure say the operator worked in Russian while deliberately excluding former Soviet states from targeting, and that the same toolkit has since been linked to more than twenty victims across nine countries.
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
The extortion group FulcrumSec says it stole around 86GB of data from Manchester Airports Group after finding airport-specific marketing platform API credentials exposed in client-side JavaScript, a haul the group says is far more detailed than the limited exposure the airport operator initially disclosed. Samples shared with reporters reportedly include nearly 200,000 records tied to upcoming 2026 travel bookings complete with dates and personally identifiable details, raising concern about highly targeted phishing against affected travelers even though no payment data was involved.
Critical Vulnerability in GiveWP Plugin Allows Remote Code Execution
A critical flaw in the GiveWP WordPress donation plugin, used on more than 100,000 sites, let unauthenticated attackers chain an unsafe PHP deserialization helper with the donation-processing flow to execute arbitrary commands on the hosting server. Even sites with registration disabled were exposed through an unauthenticated account-creation path, and the plugin’s developers have since patched the issue in version 4.16.7.2, with administrators urged to update immediately.