View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

McKesson Confirms Breach as ShinyHunters Claims 284M Records Stolen

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Public HardBreacher PoC Targets Kaspersky Endpoint Security
    A public HardBreacher PoC targets a local privilege-escalation flaw in Kaspersky Endpoint Security.

    • Kaspersky Endpoint Security for Windows v14.0.0.504 on Windows 11 25H2 is affected.
    • The alleged flaw lets a standard local user escalate privileges through the endpoint product.
    • The PoC targets Kaspersky’s UI process and reportedly creates C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with user-controlled permissions.
    • Kaspersky told SecurityWeek it patched the vulnerability; no CVE was assigned in the reported material.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek
  • Check Point Deobfuscates JSCeal’s Compiled V8 Bytecode
    Check Point Research has deobfuscated the JSCeal cryptocurrency stealer.

    • JSCeal targets cryptocurrency applications and can steal credentials.
    • The malware supports keylogging, browser theft, screenshot capture, and HTTPS traffic interception.
    • JSCeal is delivered as obfuscated compiled V8 bytecode (.jsc) and runs through a bundled Node.js runtime.
    • Obfuscation uses RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
      πŸ“Ž Coverage: research.checkpoint.com Β· πŸ‘ via Check Point Research

πŸ“‹ ADVISORIES

  • πŸ“„ Source for McKesson Confirms Breach as ShinyHunters Claims 284M Records Stolen β€” sec.gov

πŸ”“ CVEs & KEV

  • CVE-2026-82641 β€” CVSS 8.8 β€” keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposurekeploy versions 3...

  • CVE-2026-82217 β€” CVSS 8.8 β€” In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agen...

  • CVE-2026-12894 β€” CVSS 8.8 β€” Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side te...

  • CVE-2026-82639 β€” CVSS 8.7 β€” NextChat 2.15.8 through 2.16.1 OpenAI API Key DisclosureNextChat versions fro...

  • CVE-2026-82638 β€” CVSS 8.7 β€” jina-ai reader Server-Side Request Forgery via disabled private-address guard...

  • CVE-2026-82636 β€” CVSS 7.9 β€” Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection duri...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check