View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

McKesson discloses breach after ShinyHunters claims patient data theft

๐Ÿšจ ACTIVE EXPLOITATION

๐Ÿ’ฅ BREACHES & INCIDENTS

  • McKesson discloses breach after ShinyHunters claims patient data theft
    McKesson disclosed unauthorized access to third-party applications and data exfiltration.

    • McKesson, its healthcare customers and partners, and their patients are potentially affected.
    • ShinyHunters claims it stole 284 million records linked to tens of millions of patients.
    • The alleged data includes names, addresses, dates of birth, contact details, Social Security numbers, medical records, prescriptions and diagnoses.
    • McKesson said the incident involved unauthorized access to third-party applications and data exfiltration; its investigation is ongoing.
      ๐Ÿ“Ž Coverage: cyberinsider.com ยท ๐Ÿ‘ via BleepingComputer
  • Berlin Rejects Extortion Demand After State Network Data Theft
    Berlin's state government is facing extortion after hackers stole data from its network.

    • Berlin's state government and Senate departments for mobility, transport, climate, and the environment were affected.
    • Attackers claimed to have stolen 5.79 TB of data, including contracts, emails, passwords, and personal information.
    • The leak occurred between August 7 and 12, 2026, before affected departments were isolated on August 14.
    • Rhysida claimed the attack and offered the data for auction with a starting price of 30 bitcoin.
    • The initial access method has not been disclosed.
      ๐Ÿ“„ Source: berlin.de ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Perturbation probing finds LLM safety refusal concentrated in few neurons
    Unit 42 found that aligned LLM refusal behavior can depend on a small number of neurons.
    • The finding applies to aligned large language models, including Qwen3-4B and Qwen3.5-2B.
    • On Qwen3-4B, 50 of 350,208 feed-forward neurons controlled the safety refusal template.
    • Removing those neurons changed response formats on 80% of 520 harmful-prompt benchmark tests.
    • On Qwen3.5-2B, disabling 20 neurons eliminated false agreement across 30 multi-turn questions.
    • A two-forward-pass perturbation-probing method identifies the neurons, while the FFN/Skip ratio predicted 81% of safety-fragility variance across 13 models.
      ๐Ÿ“„ Source: arxiv.org ยท ๐Ÿ“Ž Coverage: unit42.paloaltonetworks.com ยท ๐Ÿ‘ via Palo Alto Unit 42

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Critical JFrog Artifactory Authentication Bypass Enables Admin Access โ€” docs.jfrog.com

๐Ÿ”“ CVEs & KEV

  • CVE-2026-19295 โ€” CVSS 9.9 โ€” Langflow is affected by multiple remote code execution vulnerabilities due to...

  • CVE-2026-18527 โ€” CVSS 9.9 โ€” IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin...

  • CVE-2026-19286 โ€” CVSS 9.8 โ€” Langflow is affected by multiple remote code execution vulnerabilities due to...

  • CVE-2026-3627 โ€” CVSS 9.1 โ€” Multiple Vulnerabilities in IBM Concert SoftwareIBM Concert 1.0.0 through 2.3...

  • CVE-2026-18729 โ€” CVSS 8.8 โ€” Langflow is affected by multiple remote code execution vulnerabilities due to...

  • CVE-2026-82017 โ€” CVSS 8.6 โ€” IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration ...

  • CVE-2026-18904 โ€” CVSS 8.2 โ€” Langflow is affected by multiple authentication bypass, path traversal, autho...

  • CVE-2026-18891 โ€” CVSS 8.2 โ€” Langflow is affected by multiple authentication bypass, path traversal, autho...

  • CVE-2026-18899 โ€” CVSS 7.5 โ€” Langflow is affected by multiple authentication bypass, path traversal, autho...

  • CVE-2026-17203 โ€” CVSS 7.5 โ€” IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin...

  • CVE-2026-16821 โ€” CVSS 7.0 โ€” Vulnerabilities in IBM AIX and PowerVM VIOSIBM AIX 7.2, and 7.3 and IBM Power...

  • CVE-2026-82018 โ€” CVSS 6.8 โ€” IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf FileIGEL OS 12 befo...

  • CVE-2026-19294 โ€” CVSS 6.4 โ€” Langflow is affected by multiple authentication bypass, path traversal, autho...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check