Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.
Category: securityweek
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.
McKesson Confirms Data Breach as Attacker Deadline Looms
The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities.
Anthropic Warns Claude Users of Infostealer Malware Infections
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.
Boston Scientific Still Recovering From Cyberattack
The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.
Extortion Group Claims Manchester Airports Group Data Breach
FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.
Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
The ruling is part of Anthropic’s legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year.
Berlin Won’t Pay Extortion Group Claiming Data Theft
The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.
More Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.
Hasbro Data Breach Exposed Employee Personal Information
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank…
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.
