Security
McKesson Breach Exposes 284M Patient Records in ShinyHunters Attack
Healthcare giant McKesson confirms data theft after ShinyHunters claims 284M records; ATF, UK airports, and Cosmos chains also hit.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
McKesson Confirms Breach After ShinyHunters Claims 284M Patient Records Stolen
McKesson, a major U.S. healthcare and pharmaceutical distribution company, disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claimed responsibility, stating it stole 284 million patient data records. McKesson discovered the incident on August 25, 2026, and said its investigation remains in the early stages, with the company not yet determining the incident to be material to its financial condition.
McKesson discloses breach after ShinyHunters claims patient data theft →
ATF Confirms Cyberattack on System With Investigation Target Data
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that a cyberattack it publicly disclosed involved a standalone computer system containing information about targets of ATF investigations. The system was not connected to other ATF systems and was quickly shut down when the breach was discovered. The ransomware group Qilin claimed responsibility, but its involvement has not been independently confirmed. ATF said the incident has not impacted its ability to perform its missions.
ATF confirms cyberattack hit system containing info on its investigation targets →
Cyberattack on 3 UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group (MAG), which operates Manchester Airport, London Stansted and East Midlands Airport, exposed personal information belonging to about 8.7 million customers. The compromised data included email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said it discovered the intrusion Tuesday after attackers accessed its systems over the weekend, and refused to pay the ransom demanded. The company said there was no impact on airport operations or aviation security.
Cyberattack on 3 UK Airports Exposes Data of 8.7 Million Customers →
Poisoned Scanner Compromise Hits 2,500 Companies via AI Supply-Chain Package
The March 2026 compromise of LiteLLM, an open-source gateway used to route traffic to large language models, may have exposed secrets belonging to more than 2,500 organizations, according to threat-intelligence firm CloudSEK. The attack chain began when attackers compromised Trivy, a widely used open-source security scanner, and pushed malicious images to Docker Hub. Two malicious LiteLLM releases were then published to PyPI carrying credential-stealing code, reading cloud access keys, SSH keys, and other secrets from build environments.
How a Poisoned Scanner Reached 2,500 Companies Through One AI Supply-Chain Package | HackerNoon →
Fake North Korean IT Workers: Huntress Details Red Flags for Hiring Teams
Huntress has uncovered at least five North Korean operatives hired so far this year, using techniques the firm described as genuinely wild. Workers linked to the Famous Chollima group applied for jobs at IT, sales, and healthcare companies through normal channels, completed standard onboarding, and in some cases performed the work normally while sending pay back to the regime. Red flags include the use of VPNs, PiKVM, and Guermok devices, along with suspicious ID documents and infrastructure patterns.
Android 17 Hides Browsing Destinations From Carriers With ECH Support
Android 17 includes platform-wide support for Encrypted Client Hello (ECH), making it the first major mobile operating system to build the standard directly into the OS. ECH addresses the plaintext Server Name Indication (SNI) field in the TLS handshake, which announces the destination hostname to every node on the network path. Google also added three other network protections: carriers can now disable 2G by default, apps must request permission for local network access, and Certificate Transparency is enforced by default.
Android 17 Hides Your Browsing Destinations From Carriers, Closing HTTPS Privacy Gap →
Cosmos Labs Says It Wrongly Cleared Bug Behind $5.7 Million Six-Chain Hack
Cosmos Labs said attackers stole funds across six blockchain networks between Aug. 20 and Aug. 25 using a flaw in Cosmos EVM, the shared software that lets Cosmos chains run Ethereum-style applications. A researcher had identified the flaw and submitted a report through the bug bounty program on April 25, but Cosmos Labs concluded funds on live networks were not at risk. The attacker exploited an integer underflow bug to trick networks into crediting wallets with effectively infinite tokens, with losses including 720.9 million MANTRA tokens and nearly 3 billion TAC.
Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack →
First Android Auto Trojan Turns Millions of Car Radios Into Global Botnet
Kaspersky researchers identified a previously undetected Android-based trojan that infected connected car radios produced by Chinese manufacturer DoFun, turning them into a global botnet. The campaign was attributed with high confidence to the MoYu group, based on shared infrastructure with the Badbox cybercriminal platform. The attack exploited the automatic update mechanism in a pre-installed app called TWCore, allowing attackers to install hidden modules that routed internet traffic through infected devices for advertising click fraud.
Brave Browser Adds Email Aliases to Help Users Evade Tracking
The latest version of the Brave browser, 1.94, introduces a feature called Email Aliases that allows users to generate disposable email addresses when signing up to a new service. Using an alias keeps the user’s real email address hidden from the website while still forwarding messages. The new feature addresses the risk of cross-site identity matching, reduces spam, and protects users from threats such as phishing attacks that can follow data breaches. The alias system is free for up to five aliases, with a paid Premium version planned.
Brave browser adds email aliases to help users evade tracking →
Cambodia Shuts Down 700 Scam Centers, Arrests 30,000 in Cybercrime Crackdown
Phnom Penh authorities announced that a year-long operation against organized cybercrime resulted in the shutdown of more than 700 online scam centers and the arrest of nearly 30,000 individuals, including 15 senior officials and law-enforcement officers suspected of facilitating the schemes. The crackdown targeted networks accused of defrauding victims in Asia, Europe, and North America with fraudulent investment, romance, and high-yield schemes. Amnesty International raised concerns about due process, while the government indicated plans to retrain former scam-center workers.
Cambodia shuts down 700 scam centers, arrests 30,000 in cybercrime crackdown →
Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing
Polygon Labs disclosed that it patched a batch of security vulnerabilities through two hard forks—Austin on its Bor client and Kyoto on its Heimdall client—that were rolled out privately before mainnet activation. The Austin fork closed two denial-of-service paths in block processing, while the Kyoto fork addressed consensus-hardening issues. Polygon stressed that none of the flaws were observed being exploited on mainnet and that both upgrades are now mandatory for node operators.
Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing Them →
Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. Anthropic has identified multiple malware including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a small number of Macs.
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage →
Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures. The operation was uncovered by application security company Socket, and the investigation indicates it may have been active since early 2024. Five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically. Socket warns that the malicious framework may have more modules and new payloads are expected.
Chrome Web Store extensions caught stealing crypto, browser data →