Cybersecurity News — 2026-09-01
Generated: 2026-09-01 | Sources: BleepingComputer, The Hacker News, Help Net Security, SecurityWeek, HIPAA Journal, Infosecurity Magazine, The Register, cybersecuritynews.com, Rapid7, Bitdefender
1. A Phone Call to the Help Desk Was All It Took to Steal Records Tied to Tens of Millions of Patients
McKesson, one of the largest healthcare distribution companies in the US, confirmed a breach after the extortion group ShinyHunters said it walked out with roughly 284 million records — patient names, addresses, dates of birth, Social Security numbers, medication and diagnosis details — plus a parallel haul of internal Salesforce data. The group says it got in the same way as several other big breaches this year: by phoning company staff, posing as IT support, and talking them into handing over their Okta single sign-on details — the one login that then unlocks everything else. ShinyHunters says it demanded $55.2 million (roughly £44m) and gave McKesson 72 hours to pay before publishing.
Why it matters for your business: single sign-on (using one login — Google, Microsoft, Okta — to access several tools) makes one stolen password very powerful. If your business relies on it, put phishing-resistant multi-factor authentication (a passkey or hardware key, not a text code) on that one account above all others, and make sure whoever can reset it will always call back on a number they already have before acting on an urgent request.
2. Office Print-Management Software Needed Emergency Patching Twice in Two Days
PaperCut, software many offices use to manage and track printing, had to release two emergency patches within a day of each other after researchers found attackers could reach the server without logging in at all, disguise a request to look like an ordinary print job, and use it to plant a hidden database driver that ran their own code. Security firm Huntress said it caught the technique being used for reconnaissance on real customer systems before the first patch had even shipped, and a second patch was needed within 24 hours because criminals had already found a way round the first one.
Why it matters for your business: if your business or IT provider runs PaperCut NG or MF, confirm you're on the second emergency release (dated 28 August 2026), not just the first — a half-patched server is still exposed through the same workaround attackers already found.
3. Five Popular WordPress Add-Ons Could Let a Stranger Take Over Your Website
Researchers disclosed five separate critical flaws this week in widely used WordPress plugins and themes — including TranslatePress (installed on more than 400,000 sites), the Avada theme, and the Pods plugin — that let an attacker either log in as an administrator without a password or upload their own code to run on the server. The Pods flaw is the starkest: no account or login is needed at all to become an administrator. Fixes are already out for all five, which is the normal pattern with WordPress — the flaw and the fix are published together, so the risk sits entirely in how long a site goes before it's updated.
Why it matters for your business: if your website runs on WordPress, check today whether TranslatePress, Avada or Pods are installed and update every plugin and theme to its latest version — most successful WordPress attacks target a flaw that was patched months earlier and the site owner simply hadn't updated yet.
4. An Airport Group's Wi-Fi Sign-Up Page Exposed Contact Details for 8.7 Million Travellers
Manchester Airports Group — which runs Manchester, Stansted and East Midlands airports — confirmed that hackers stole data on around 8.7 million customers, including details entered for free airport Wi-Fi, car parking, lounge access and Fast Track bookings: names, email addresses, phone numbers, postcodes and vehicle registration numbers. No payment card details were taken and flights weren't affected, but the stolen information is exactly what's needed to send a convincing "there's a problem with your parking booking" or "your flight has changed" phishing message.
Why it matters for your business: worth passing on to staff and family directly, since this will land as a consumer scam rather than a business one — treat any unexpected email or text about an airport booking, parking charge or refund with suspicion for the next few months, and go to the airport's own site or app to check rather than clicking through.
5. A Global Medical Device Maker Is Still Recovering a Week After Its Systems Went Down — With No Timeline
Boston Scientific, one of the world's largest makers of medical devices, detected a cyberattack on 25 August that knocked out systems supporting manufacturing, customer orders and shipping worldwide. A week on, the company still can't give a timeline for full recovery and hasn't said whether the attack involved ransomware, how attackers got in, or whether data was stolen; as of the most recent update, no extortion group has claimed responsibility either. For a company that size the disruption is a cash-flow and reputation problem — for a smaller business, the same kind of outage, unable to take or ship orders for a week or more, can be existential.
Why it matters for your business: ask whether your business could keep taking orders, invoicing and talking to customers if your main systems went down for a week, and write the answer down — a phone list, a manual order process, a backup way to reach customers — before you're the one improvising it live.
Sources
- Help Net Security — ShinyHunters claims it stole 284 million patient records from McKesson
- BleepingComputer — McKesson discloses breach after ShinyHunters claims patient data theft
- HIPAA Journal — ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws
- Help Net Security — PaperCut NG/MF vulnerabilities exploited in zero-day attacks
- Rapid7 — PaperCut NG/MF Critical Zero-Day Exploited in the Wild
- The Hacker News — Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
- cybersecuritynews.com — WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks
- BleepingComputer — Manchester Airports Group says hackers stole travelers' data
- Infosecurity Magazine — Manchester Airports Group Hit by Cyber Incident
- Bitdefender — Manchester Airports Group cyberattack exposes data of 8.7 million customers
- The Register — Boston Scientific discloses 'global disruption' in ongoing cyberattack
- SecurityWeek — Cyberattack Causes Global Disruption at Boston Scientific
- SecurityWeek — Boston Scientific Still Recovering From Cyberattack