Cybersecurity News — 2026-09-04
Generated: 2026-09-04 | Week in review | Sources: BleepingComputer, The Hacker News, Help Net Security, SecurityWeek, HIPAA Journal, Infosecurity Magazine, The Register, Cybernews, TechRadar, Malwarebytes, Bitdefender, Rapid7, cybersecuritynews.com
1. Every flaw attackers actually used this week was in something facing the public internet
Four separate stories, one shape. PaperCut — the software offices use to manage printing — needed two emergency patches within a day of each other after attackers reached the server without logging in at all. SonicWall confirmed two previously unknown flaws in its SMA1000 remote-access appliances were being exploited right now, chained together to run commands on the very box that decides who gets onto the network. Researchers published working attack code for a Microsoft Exchange flaw that hands over every mailbox on the server. And five critical WordPress plugin and theme flaws — TranslatePress, Avada, Pods — let a stranger become an administrator. None of these are unusually badly written products. They are simply the parts of a business a stranger can reach at all.
Why it matters for your business: ask whoever runs your IT for a plain list of everything in your business that answers a connection from the internet — website, mail server, VPN or remote-access box, print server, any self-hosted tool — and switch off whatever isn't genuinely needed. Everything left on that list is what an attacker gets to try, and it is a much shorter list than "all our software", so it is the one worth patching first.
2. In almost every case the fix already existed — the damage lived in the gap before it was installed
The Exchange flaw (CVE-2026-62911) was patched by Microsoft back in August, yet researchers counted nearly 22,000 servers worldwide, hundreds of them in the UK, still running the vulnerable version when the attack code went public this week. The five WordPress flaws all had fixes out on the day they were disclosed, which is the normal WordPress pattern — the flaw and the fix are published together, so the entire risk sits in how long a site waits. PaperCut is the sharpest version: criminals found a way round the first emergency patch inside 24 hours, so anyone who patched once and considered the job done was still exposed. A patch you have downloaded and not installed protects nobody.
Why it matters for your business: treat "a fix has shipped" as the moment the clock starts, not the moment it stops. For anything on your internet-facing list, agree with your IT provider what "urgent" means in days rather than weeks, and when a vendor issues a second patch in the same week — as PaperCut did on 28 August 2026 — confirm you are on the later one, because "we already patched that" is exactly how a half-fixed server stays open.
3. Two of the week's biggest account takeovers never involved guessing a password
ShinyHunters says it got into McKesson, a giant of US healthcare distribution, by phoning staff, posing as IT support and talking them into handing over their Okta single sign-on details — the one login that then unlocks everything else. The group claims roughly 284 million records. Dropbox, meanwhile, confirmed around 5,000 accounts were accessed after a gap in Lenovo's email verification let someone register a Lenovo ID using a stranger's email address and then use the "sign in with Lenovo" shortcut to walk straight into the matching Dropbox account. No password was needed in either case. Both attacks went through the machinery that proves who you are, rather than around it.
Why it matters for your business: work out which accounts unlock other accounts — your email, your single sign-on provider, your website admin — and protect those with a passkey or a physical security key rather than a code from an app or text, because a code can be relayed to an attacker in real time and a passkey cannot. Then check that multi-factor authentication is switched on for the destination account, not only for the "sign in with" provider, and that anyone who can reset a password will always call back on a number they already hold.
4. The system that leaked was usually not the one with the brand on it
Manchester Airports Group lost details on around 8.7 million people — names, emails, phone numbers, postcodes, vehicle registrations — through free Wi-Fi sign-ups, car parking and lounge bookings, the peripheral conveniences rather than anything to do with flying. A dark-web listing of 153 million driver's licences and ID documents was traced by researchers to IDScan.net, a verification vendor working quietly behind firms like Hertz and FedEx; IDScan has not confirmed a breach and the FBI is investigating. Dropbox's 5,000 compromised accounts were the result of a flaw in Lenovo's sign-in system, not Dropbox's. And alongside McKesson's patient records sat a parallel haul of Salesforce data. In each case the security of a trusted name was set somewhere its customers had never thought to look.
Why it matters for your business: write down every outside company that holds or touches your customers' details — fulfilment, bookings, payments, email marketing, identity or age checks, your support desk — and include the small conveniences like a Wi-Fi sign-up form or a mailing list, because that is where this week's largest UK leak came from. Ask each supplier two questions: is multi-factor authentication on for your staff accounts, and how quickly would you tell us if you were breached? If a vendor handles ID document images, also ask what happens to the image after the check has run.
5. Several victims could not say what had happened — and in two cases the criminals spoke first
Boston Scientific detected an attack on 25 August that took down manufacturing, orders and shipping worldwide; a week later it still could not give a recovery timeline and had not said whether ransomware was involved, how attackers got in, or whether data was taken. McKesson's breach became public because ShinyHunters announced it and started a 72-hour ransom clock. The IDScan haul surfaced as a marketplace listing, with the company yet to confirm anything at all. That is not necessarily evasion — a week into a serious incident, plenty of organisations genuinely do not yet know. But it means the people affected learn what happened from whoever stole the data, on that person's schedule.
Why it matters for your business: decide now, on paper, what you would tell customers and staff in the first 24 hours of an incident, and who says it — a short honest holding message written in advance beats silence while you work out the facts. Then answer the harder question Boston Scientific's week illustrates: could you keep taking orders, invoicing and reaching customers if your main systems were dark for seven days? Write down the fallback — a phone list, a manual order pad, a second way to contact customers — before you are improvising it live.
Sources
- Help Net Security — ShinyHunters claims it stole 284 million patient records from McKesson
- BleepingComputer — McKesson discloses breach after ShinyHunters claims patient data theft
- HIPAA Journal — ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws
- Help Net Security — PaperCut NG/MF vulnerabilities exploited in zero-day attacks
- Rapid7 — PaperCut NG/MF Critical Zero-Day Exploited in the Wild
- The Hacker News — Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
- cybersecuritynews.com — WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks
- BleepingComputer — Manchester Airports Group says hackers stole travelers' data
- Infosecurity Magazine — Manchester Airports Group Hit by Cyber Incident
- Bitdefender — Manchester Airports Group cyberattack exposes data of 8.7 million customers
- The Register — Boston Scientific discloses 'global disruption' in ongoing cyberattack
- SecurityWeek — Cyberattack Causes Global Disruption at Boston Scientific
- SecurityWeek — Boston Scientific Still Recovering From Cyberattack
- SecurityWeek — SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
- BleepingComputer — SonicWall warns of actively exploited SMA1000 zero-day flaws
- Help Net Security — SonicWall SMA 1000 appliances under attack via zero-day flaws
- The Hacker News — Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- TechRadar — Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
- Cybernews — Dropbox Lenovo Breach Let Hackers Access 5,000 Accounts Without Passwords
- Help Net Security — Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
- BleepingComputer — Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
- Cybernews — 153M driver's licenses for sale after alleged leak from IDScan
- Malwarebytes — 153M+ driver's licenses for sale on new dark web platform