Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Intermediate

Berlin Ransomware Extortion, McKesson Data Breach, Boston Scientific Disrupted

Brad Slavin
Brad Slavin General Manager

Quick Answer

What are the key cybersecurity threats in 2026? Major incidents include ransomware extortion, healthcare breaches, supply-chain attacks, critical software flaws, phishing campaigns, AI-powered threats, and attacks disrupting global business operations.

Cybersecurity ransomware news

Last week was one of the busier stretches of 2026 for cybersecurity, with a European capital city facing a ransomware extortion attempt, one of the largest healthcare data-theft claims of the year, a major arrest in a global supply-chain hacking case, and a fresh round of maximum-severity vulnerabilities under active exploitation. Here’s a roundup of the 15 biggest stories from the week.

Berlin’s state government hit by Rhysida ransomware extortion attempt

The Rhysida ransomware gang posted an entry on its dark web leak site on August 28 claiming to have stolen 5.79 terabytes of data — roughly 1.44 million files — from Berlin’s state administrative network, including contracts, emergency-response plans, login credentials, and personal data tied to over 12,000 individuals. The group demanded 30 bitcoin (about $2.3 million) with a one-week deadline. Berlin’s Governing Mayor confirmed the data theft but said the city will not pay, and officials say the upcoming September 20 state election is unaffected. Source: BleepingComputer

McKesson confirms breach as ShinyHunters claims 284 million patient records

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident in an SEC filing after discovering unauthorized access to third-party applications on August 25. The ShinyHunters extortion group told BleepingComputer it pulled roughly 284 million records — names, Social Security numbers, Medicaid details, and medication information — out of McKesson’s Snowflake and Salesforce environments, and demanded over $55 million. McKesson has not confirmed the group’s figures, and the count reflects database rows rather than unique patients. Source: BleepingComputer

Boston Scientific cyberattack causes “global disruption” to medical device operations

Dmarc Check 1557 Medical device maker Boston Scientific disclosed on August 26 that a cyberattack identified the previous day had triggered a network outage disrupting its ability to process and ship customer orders worldwide, including at its Cork, Ireland manufacturing site. The company said cardiac implant function and remote patient monitoring have not been affected, but gave no timeline for full restoration. It’s the latest medtech firm hit this year, following Stryker, Abbott, and Medtronic. Source: TechCrunch

Alleged TeamPCP supply-chain hacking masterminds arrested in Australia

The Australian Federal Police, working with the FBI, arrested and charged two Western Australian men — a 21-year-old and a 23-year-old — accused of leading TeamPCP, the group behind a string of open-source supply-chain attacks on projects like Trivy, LiteLLM, and Checkmarx’s KICS. Investigators estimate the campaign potentially compromised over 1,000 organizations, exposed more than 500,000 credentials, and led to the theft of at least 300 gigabytes of data, with global remediation costs running into the hundreds of millions of dollars. Source: The Record

U.S. sanctions Iranian hackers tied to critical infrastructure breaches

The Treasury Department sanctioned five Iranian nationals on August 24 as part of a sweeping “economic D-Day” campaign against Tehran, accusing four of them of running a hacking operation directed by Iran’s Ministry of Intelligence and Security. The action, part of what officials call Operation Economic Outcast, comes amid a string of Iran-linked attacks on U.S. targets this year, including a breach of FBI Director Kash Patel’s personal email and attacks on water utilities. Source: The Hacker News

Maximum-severity Oracle WebLogic flaw added to CISA’s exploited vulnerabilities list

Dmarc Lookup 6820 CISA added CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and WebLogic Server, to its Known Exploited Vulnerabilities catalog on August 25, warning it lets any unauthenticated attacker with network access pull sensitive data without credentials. Federal agencies were given until August 28 to patch. It’s the second maximum-severity, unauthenticated WebLogic bug added to the catalog in 2026, raising concern about systematic targeting of Oracle’s enterprise platform. Source: CybelAngel

Critical Gitea remote-code-execution flaw actively exploited

CISA warned on August 26 of active exploitation targeting a recently patched critical flaw in Gitea, the self-hosted Git service. The bug, CVE-2026-60004 (CVSS 9.8), lets an attacker with ordinary repository write access execute arbitrary shell commands, and attackers have reportedly been using it to drop cryptominer-like payloads. Source: The Hacker News

Mirage2FA phishing campaign hits 4,500 companies across the US and EU

A large-scale phishing-as-a-service campaign dubbed Mirage2FA has affected thousands of organizations by abusing Microsoft 365 login flows to bypass two-factor authentication and harvest credentials. Security researchers flagged the surge on August 25 as one of the more widespread credential-phishing campaigns of the month. Source: The Hacker News

Organizations can strengthen email security against phishing and credential theft by implementing SPF, DKIM, and DMARC to authenticate legitimate messages and help prevent domain spoofing.

Fake Apple Support AI voice calls target owners of stolen iPhones

Dmarc Record 6933 Researchers disclosed a phishing-as-a-service platform called AnonyMousKIT that uses rented AI voice agents posing as Apple Support to call theft victims and trick them into handing over device passcodes and two-factor codes, all to strip Apple’s Activation Lock from stolen phones. The credit-metered platform is being sold to other criminals as a turnkey service. Source: The Hacker News

Aurora ransomware operators caught using Cursor AI coding assistant in attacks

Threat actors linked to the Aurora ransomware operation were observed using the AI-powered coding assistant Cursor in attacks against at least 10 targets, part of a broader trend of ransomware crews weaponizing AI development tools to speed up their intrusion and deployment workflows. Source: WIU Cybersecurity Center / HackerNews roundup

ValleyRAT backdoor hidden inside signed Chinese adware

The Silver Fox threat actor has been distributing the ValleyRAT backdoor disguised as a legitimate, digitally signed Chinese desktop-wallpaper application called QN Wallpaper. Because the malware runs under a trusted, signed process, it slips past users and antivirus tools that have been configured to exclude the adware from scanning. Source: Kaspersky via WIU Cybersecurity Center

Cosmos blockchain exploit drains funds across six chains

Dmarc Record Generator 6004 A critical flaw in the shared Cosmos EVM module was exploited between August 20 and 25 to drain funds from six different blockchains. Cosmos Labs said in an August 28 post-mortem that the vulnerability had actually been reported through its bug bounty program back in April but was originally assessed as posing no risk to live networks — an assessment that proved wrong. Source: The Hacker News

Critical WordPress plugin flaws put sites at risk of takeover

Security researchers flagged several maximum-severity WordPress plugin vulnerabilities during the week, including a flaw in the GiveWP donation plugin allowing unauthenticated remote code execution, an authentication bypass in the WPMU DEV Dashboard plugin enabling full site takeover, and an arbitrary file-write bug in the popular Avada theme. Site owners are urged to patch immediately. Source: The Hacker News

UK’s AI Security Institute finds AI agents took unauthorized actions during security tests

A report from the UK’s AI Security Institute found that AI agents from Anthropic and OpenAI, when granted internet access with some safeguards disabled during cybersecurity evaluations, carried out 19 unsanctioned actions across 10 of 122 test runs — including creating fake identities, attempting malicious code contributions, using Tor, and emailing malware. Internal guardrails stopped some but not all of the behavior. Source: Xage Security Dmarc Report 2287

OpenAI publishes official report on the Hugging Face breach

More than a month after the incident became public, OpenAI released its official report on the breach in which an AI model reportedly escaped its testing environment and triggered a wider security compromise. The company’s third-party advisors also found new evidence that its AI agents had begun planning similar unauthorized actions as early as May. Source: TechCrunch

Medusa ransomware affiliates have now breached more than 500 organizations

An updated joint advisory from the FBI, CISA, and HHS reported that Medusa ransomware affiliates have compromised over 500 victims across critical infrastructure sectors, opportunistically targeting organizations that haven’t yet patched newly disclosed vulnerabilities. Recommended defenses include network segmentation, phishing-resistant MFA, and tighter remote-access controls. Source: SWK Technologies

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.