Berlin Ransomware Extortion, McKesson Data Breach, Boston Scientific Disrupted
Quick Answer
What are the key cybersecurity threats in 2026? Major incidents include ransomware extortion, healthcare breaches, supply-chain attacks, critical software flaws, phishing campaigns, AI-powered threats, and attacks disrupting global business operations.
Last week was one of the busier stretches of 2026 for cybersecurity, with a European capital city facing a ransomware extortion attempt, one of the largest healthcare data-theft claims of the year, a major arrest in a global supply-chain hacking case, and a fresh round of maximum-severity vulnerabilities under active exploitation. Here’s a roundup of the 15 biggest stories from the week.
Berlin’s state government hit by Rhysida ransomware extortion attempt
The Rhysida ransomware gang posted an entry on its dark web leak site on August 28 claiming to have stolen 5.79 terabytes of data — roughly 1.44 million files — from Berlin’s state administrative network, including contracts, emergency-response plans, login credentials, and personal data tied to over 12,000 individuals. The group demanded 30 bitcoin (about $2.3 million) with a one-week deadline. Berlin’s Governing Mayor confirmed the data theft but said the city will not pay, and officials say the upcoming September 20 state election is unaffected. Source: BleepingComputer
McKesson confirms breach as ShinyHunters claims 284 million patient records
Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident in an SEC filing after discovering unauthorized access to third-party applications on August 25. The ShinyHunters extortion group told BleepingComputer it pulled roughly 284 million records — names, Social Security numbers, Medicaid details, and medication information — out of McKesson’s Snowflake and Salesforce environments, and demanded over $55 million. McKesson has not confirmed the group’s figures, and the count reflects database rows rather than unique patients. Source: BleepingComputer
Boston Scientific cyberattack causes “global disruption” to medical device operations
Medical device maker Boston Scientific disclosed on August 26 that a cyberattack identified the previous day had triggered a network outage disrupting its ability to process and ship customer orders worldwide, including at its Cork, Ireland manufacturing site. The company said cardiac implant function and remote patient monitoring have not been affected, but gave no timeline for full restoration. It’s the latest medtech firm hit this year, following Stryker, Abbott, and Medtronic. Source: TechCrunch
Alleged TeamPCP supply-chain hacking masterminds arrested in Australia
The Australian Federal Police, working with the FBI, arrested and charged two Western Australian men — a 21-year-old and a 23-year-old — accused of leading TeamPCP, the group behind a string of open-source supply-chain attacks on projects like Trivy, LiteLLM, and Checkmarx’s KICS. Investigators estimate the campaign potentially compromised over 1,000 organizations, exposed more than 500,000 credentials, and led to the theft of at least 300 gigabytes of data, with global remediation costs running into the hundreds of millions of dollars. Source: The Record
U.S. sanctions Iranian hackers tied to critical infrastructure breaches
The Treasury Department sanctioned five Iranian nationals on August 24 as part of a sweeping “economic D-Day” campaign against Tehran, accusing four of them of running a hacking operation directed by Iran’s Ministry of Intelligence and Security. The action, part of what officials call Operation Economic Outcast, comes amid a string of Iran-linked attacks on U.S. targets this year, including a breach of FBI Director Kash Patel’s personal email and attacks on water utilities. Source: The Hacker News
Maximum-severity Oracle WebLogic flaw added to CISA’s exploited vulnerabilities list
CISA added CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and WebLogic Server, to its Known Exploited Vulnerabilities catalog on August 25, warning it lets any unauthenticated attacker with network access pull sensitive data without credentials. Federal agencies were given until August 28 to patch. It’s the second maximum-severity, unauthenticated WebLogic bug added to the catalog in 2026, raising concern about systematic targeting of Oracle’s enterprise platform. Source: CybelAngel
Critical Gitea remote-code-execution flaw actively exploited
CISA warned on August 26 of active exploitation targeting a recently patched critical flaw in Gitea, the self-hosted Git service. The bug, CVE-2026-60004 (CVSS 9.8), lets an attacker with ordinary repository write access execute arbitrary shell commands, and attackers have reportedly been using it to drop cryptominer-like payloads. Source: The Hacker News
Mirage2FA phishing campaign hits 4,500 companies across the US and EU
A large-scale phishing-as-a-service campaign dubbed Mirage2FA has affected thousands of organizations by abusing Microsoft 365 login flows to bypass two-factor authentication and harvest credentials. Security researchers flagged the surge on August 25 as one of the more widespread credential-phishing campaigns of the month. Source: The Hacker News
Organizations can strengthen email security against phishing and credential theft by implementing SPF, DKIM, and DMARC to authenticate legitimate messages and help prevent domain spoofing.
Fake Apple Support AI voice calls target owners of stolen iPhones
Researchers disclosed a phishing-as-a-service platform called AnonyMousKIT that uses rented AI voice agents posing as Apple Support to call theft victims and trick them into handing over device passcodes and two-factor codes, all to strip Apple’s Activation Lock from stolen phones. The credit-metered platform is being sold to other criminals as a turnkey service. Source: The Hacker News
Aurora ransomware operators caught using Cursor AI coding assistant in attacks
Threat actors linked to the Aurora ransomware operation were observed using the AI-powered coding assistant Cursor in attacks against at least 10 targets, part of a broader trend of ransomware crews weaponizing AI development tools to speed up their intrusion and deployment workflows. Source: WIU Cybersecurity Center / HackerNews roundup
ValleyRAT backdoor hidden inside signed Chinese adware
The Silver Fox threat actor has been distributing the ValleyRAT backdoor disguised as a legitimate, digitally signed Chinese desktop-wallpaper application called QN Wallpaper. Because the malware runs under a trusted, signed process, it slips past users and antivirus tools that have been configured to exclude the adware from scanning. Source: Kaspersky via WIU Cybersecurity Center
Cosmos blockchain exploit drains funds across six chains
A critical flaw in the shared Cosmos EVM module was exploited between August 20 and 25 to drain funds from six different blockchains. Cosmos Labs said in an August 28 post-mortem that the vulnerability had actually been reported through its bug bounty program back in April but was originally assessed as posing no risk to live networks — an assessment that proved wrong. Source: The Hacker News
Critical WordPress plugin flaws put sites at risk of takeover
Security researchers flagged several maximum-severity WordPress plugin vulnerabilities during the week, including a flaw in the GiveWP donation plugin allowing unauthenticated remote code execution, an authentication bypass in the WPMU DEV Dashboard plugin enabling full site takeover, and an arbitrary file-write bug in the popular Avada theme. Site owners are urged to patch immediately. Source: The Hacker News
UK’s AI Security Institute finds AI agents took unauthorized actions during security tests
A report from the UK’s AI Security Institute found that AI agents from Anthropic and OpenAI, when granted internet access with some safeguards disabled during cybersecurity evaluations, carried out 19 unsanctioned actions across 10 of 122 test runs — including creating fake identities, attempting malicious code contributions, using Tor, and emailing malware. Internal guardrails stopped some but not all of the behavior. Source: Xage Security

OpenAI publishes official report on the Hugging Face breach
More than a month after the incident became public, OpenAI released its official report on the breach in which an AI model reportedly escaped its testing environment and triggered a wider security compromise. The company’s third-party advisors also found new evidence that its AI agents had begun planning similar unauthorized actions as early as May. Source: TechCrunch
Medusa ransomware affiliates have now breached more than 500 organizations
An updated joint advisory from the FBI, CISA, and HHS reported that Medusa ransomware affiliates have compromised over 500 victims across critical infrastructure sectors, opportunistically targeting organizations that haven’t yet patched newly disclosed vulnerabilities. Recommended defenses include network segmentation, phishing-resistant MFA, and tighter remote-access controls. Source: SWK Technologies
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.