ShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid tech

Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech

 

Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently verified. PaperCut issued a second emergency patch after bypasses were found for fixes to two actively exploited vulnerabilities that can be chained for unauthenticated remote code execution; organizations on v23 or earlier must upgrade. Berlin confirms an extortion attempt tied to Rhysida, which claims 5.79TB stolen. WordPress discloses five critical plugin/theme flaws enabling full site takeover, including a 10/10 GiveWP RCE. The White House bans foreign-made bulk power grid equipment over backdoor concerns amid rising critical-infrastructure attacks.

 

00:00 Top Headlines

00:30 McKesson Breach Fallout

03:18 PaperCut Patch Bypassed

06:02 Berlin Rejects Ransom

07:05 Critical WordPress Takeovers

08:43 Power Grid Tech Ban

10:35 AI Security Weekend Episode Promo

11:10 Closing and Sign Off

This article has been indexed from Cybersecurity Today

Read the original article: