# Archive
Browse past daily curated stories
Tuesday, September 01, 2026
-
1SecurityWeek generalMcKesson Confirms Data Breach as Attacker Deadline Looms
ShinyHunters has claimed responsibility for breaching McKesson, one of the largest pharmaceutical and healthcare technology companies in the US, allegedly stealing 284 million records. The attack is causing active service degradation and McKesson faces an extortion deadline, making this a critical incident for healthcare sector security practitioners monitoring supply chain and third-party application risks.
-
2BleepingComputer generalBerlin confirms data theft after Rhysida ransomware attack claims
The Rhysida ransomware gang has listed Berlin's city administration on its data leak site and claimed exfiltration of over 5TB of data including personal information and credentials. Berlin's governing mayor Kai Wegner publicly confirmed the breach — discovered in mid-August — and stated the city will not pay the ransom demand, a stance that signals likely public data exposure.
-
3The Hacker News generalChina-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
China-nexus threat actor Fire Ant has expanded operations beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, establishing covert GRE tunnels undetectable in router configurations or commit histories. Incident responder Sygnia documented the campaign, which focuses on credential theft and log blinding — a significant escalation in network infrastructure targeting by a state-linked actor.
-
4SecurityWeek generalMore Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut has issued a second emergency patch for two actively exploited vulnerabilities now tracked as CVE-2026-82078 and CVE-2026-81578, following initial disclosure and in-the-wild exploitation. Security teams running PaperCut print management software should treat patching as urgent given the confirmed active exploitation status.
-
5BleepingComputer generalMicrosoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft has documented a new ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA prompts on compromised websites to lure victims into executing malicious PowerShell commands in Windows Terminal, subsequently deploying reverse tunnels into victim enterprise networks. The multi-stage attack chain represents an evolution of social engineering lures targeting enterprise environments where Windows Terminal is a trusted tool.
-
6SecurityWeek generalServiceNow Patches 3 Critical Code Injection Vulnerabilities
ServiceNow has patched three critical code injection vulnerabilities that could allow unauthenticated attackers to execute arbitrary code and access or tamper with data on affected instances. Given ServiceNow's widespread deployment as an enterprise ITSM platform handling sensitive IT and HR data, security teams should prioritize patching and review exposure of their instances.
-
7The Hacker News generalValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The Silver Fox threat actor is distributing the ValleyRAT backdoor disguised as QN Wallpaper, a signed Chinese desktop wallpaper application, exploiting users who add the software to antivirus exclusion lists. Kaspersky researchers identified the campaign, noting the malware runs under a trusted, signed process specifically to evade endpoint detection — a technique that challenges traditional AV-based defenses.
-
8The Hacker News generalAurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
CloudSEK and Gambit Security independently identified Russian-speaking Aurora (aka Aur0ra) ransomware operators using SpaceX's Cursor AI coding assistant to facilitate intrusions against at least 10 targets, discovered via exposed attacker infrastructure. This represents an early documented case of ransomware actors leveraging commercial AI coding tools operationally, with implications for how defenders model threat actor capabilities.
-
9SecurityWeek generalCritical Ruby on Rails Vulnerability in Attackers’ Crosshairs
A critical arbitrary file read vulnerability in Ruby on Rails, dubbed KindaRails2Shell, is being actively exploited to extract application secrets and chain into remote code execution. Security teams running Rails applications should audit exposure and apply available patches immediately given confirmed attacker interest in this flaw.
-
10The Hacker News generalDoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice issued a correction to a prior press statement, clarifying that NASA, the Federal Reserve, DOE, DOJ, and other agencies were targeted — not confirmed victims — of Chinese state-sponsored cyberattacks. The factual correction is notable for its rarity and underscores the importance of precise attribution language when federal agencies communicate about nation-state intrusion campaigns.