Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech
Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Okta SSO, and accessed Salesforce and Snowflake, allegedly exfiltrating about 1TB and 284 million patient records (records, not unique patients) and demanding a $55M+ ransom, though the claims aren't independently verified. PaperCut issued a second emergency patch after bypasses were found for fixes to two actively exploited vulnerabilities that can be chained for unauthenticated remote code execution; organizations on v23 or earlier must upgrade. Berlin confirms an extortion attempt tied to Rhysida, which claims 5.79TB stolen. WordPress discloses five critical plugin/theme flaws enabling full site takeover, including a 10/10 GiveWP RCE. The White House bans foreign-made bulk power grid equipment over backdoor concerns amid rising critical-infrastructure attacks.
00:00 Top Headlines
00:30 McKesson Breach Fallout
03:18 PaperCut Patch Bypassed
06:02 Berlin Rejects Ransom
07:05 Critical WordPress Takeovers
08:43 Power Grid Tech Ban
10:35 AI Security Weekend Episode Promo
11:10 Closing and Sign Off
Read the original article: