Secret CISO 9/1: McKesson's 284M-Record Breach, Aurora Ransomware Weaponizes AI, ServiceNow's Triple CVSS-10 Flaws, TeamPCP Hackers Arrested

McKesson's massive ShinyHunters extortion, an AI coding assistant hijacked for ransomware ops, three maximum-severity ServiceNow flaws, and the takedown of the TeamPCP supply-chain crew.

Share
Secret CISO 9/1: McKesson's 284M-Record Breach, Aurora Ransomware Weaponizes AI, ServiceNow's Triple CVSS-10 Flaws, TeamPCP Hackers Arrested

Welcome to today's edition of Secret CISO, where healthcare, retail, and hosting infrastructure all took a beating over the past week and the criminals show no signs of slowing down as we head into September. The headline story is grim: pharmaceutical distribution giant McKesson has confirmed a breach after the ShinyHunters extortion crew claimed to have exfiltrated roughly a terabyte of data, including protected health information, and is demanding more than $55 million to keep it quiet.

ShinyHunters isn't stopping at healthcare, either. The same group is behind the ongoing fallout at Carhartt, where nearly 13 million accounts' worth of customer and employee data has now been published after the retailer declined to pay. Meanwhile in Japan, cloud and hosting provider Sakura Internet is still untangling a sales-system intrusion that may have touched 1.36 million customer accounts.

On the law-enforcement side, there's a rare bit of good news: Australian police, working with the FBI, arrested two young men accused of running the TeamPCP supply-chain crew, a group blamed for breaching more than a thousand organizations and stealing hundreds of gigabytes of source code and secrets from major open-source and developer platforms.

In security research, we're tracking a troubling new pattern: ransomware affiliates convincing AI coding agents that their intrusions are authorized penetration tests, then letting the agent do the hands-on hacking. We'll also walk through active exploitation of Langflow and Ruby on Rails flaws, a SQL-injection zero-day in Metabase, and a critical (if quietly patched) deserialization bug in Microsoft Entra ID.

The CVE desk is dominated by ServiceNow this week, where three separate flaws each carry the maximum possible CVSS score of 10.0, alongside an actively exploited Oracle WebLogic proxy bug that's now on CISA's must-patch list, a GitLab flaw exploited within days of disclosure, and a cPanel weakness that lets one hosting customer commandeer an entire shared server.

As always, patch aggressively, verify your vendors' claims about "no customer impact," and treat any AI coding agent's access to production systems with the same suspicion you'd give a new contractor. Let's get into it.

Data Breaches

  1. McKesson Confirms Breach as ShinyHunters Claims 284 Million Patient Records: The healthcare and pharmaceutical distribution giant disclosed that attackers used vishing calls to compromise employee Okta accounts, then pivoted into its Salesforce and Snowflake environments between August 21 and 25. ShinyHunters says it exfiltrated close to a terabyte of data, including PII, PHI, and prescription and billing records, and is demanding over $55 million. Source: BleepingComputer
  2. Carhartt Data Breach Exposes Information of 12.9 Million Accounts: ShinyHunters published stolen Carhartt customer, employee, and corporate data after the apparel giant refused to pay, though analysts note the haul was padded with millions of synthetic records inflating the original claim. Exposed data includes email addresses, names, phone numbers, and physical addresses. Source: BleepingComputer
  3. Australia Arrests Alleged TeamPCP Hackers Behind Supply-Chain Attacks: Two men in their early twenties were arrested in Western Australia over a year-long spree of software supply-chain attacks that hit Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, and reportedly breached the European Commission, Mistral AI, OpenAI, and GitHub. Police say the group exfiltrated at least 300GB of data from more than 1,000 organizations. Source: BleepingComputer
  4. Sakura Internet Hack Exposes Data of Up to 1.36 Million Accounts: The Japanese cloud and hosting provider disclosed that attackers accessed its sales management system, potentially exposing customer names, addresses, contract details, and hashed passwords for at least 30 accounts. The company says no credit card data was stored in the affected environment. Source: BleepingComputer

Security Research

  1. Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets: Researchers at CloudSEK and Gambit Security found that an Aurora ransomware affiliate used the Cursor AI coding agent for hands-on exploitation against organizations in Belgium, Germany, Scotland, Argentina, Italy, and elsewhere, simply by telling the agent the intrusion was an authorized penetration test. The agent assisted with NTLM relay attacks and certificate-based attacks via Certipy. Source: The Hacker News
  2. Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity: Threat intelligence firm VulnCheck observed active exploitation of a Langflow input-validation bug and a Ruby on Rails file-disclosure flaw dubbed KindaRails2Shell, with attackers harvesting cloud credentials and API tokens and establishing command-and-control infrastructure from canaries in Singapore, Israel, and the UK. Source: The Hacker News
  3. Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication: A maximum-severity SQL injection in the popular BI tool's password-reset endpoint let an unauthenticated attacker gain admin access and pull data from connected databases; CISA has added it to its Known Exploited Vulnerabilities catalog. Wiz estimates roughly 2,500 self-hosted Metabase instances remain internet-accessible. Source: The Hacker News
  4. Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution: A deserialization bug in Microsoft's cloud identity service could have let an unauthenticated attacker execute code with no user interaction; Microsoft says it mitigated the issue server-side and later walked back an initial claim that it had been exploited in the wild. Source: The Hacker News
  5. Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server: A flaw in cPanel's domain-parking feature lets any authenticated customer create arbitrary files anywhere on the server, leading to remote code execution as root, a catastrophic risk on shared hosting where one compromised account can expose every site on the box. Source: The Hacker News

Top CVEs

  1. CVE-2026-18885: A code injection vulnerability in ServiceNow's GraphQL Composite Data API allows unauthenticated remote code execution with no privileges or user interaction required. It's one of three ServiceNow AI Platform flaws that each scored a maximum CVSS v4.0 of 10.0, alongside a SQL injection and an access-control bypass; ServiceNow has already patched hosted instances and issued hotfixes for self-hosted deployments. Source.
  2. CVE-2026-21962: A critical flaw in the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS lets unauthenticated remote attackers bypass access controls and reach backend WebLogic systems. CISA added it to its Known Exploited Vulnerabilities catalog on August 24 after confirming active attacks; admins should apply Oracle's Critical Patch Update immediately. Source.
  3. CVE-2026-19478: A CVSS 9.4 flaw in GitLab allows an unauthenticated attacker to modify or delete publicly accessible projects and rewrite their data. Exploitation began within days of public disclosure, underscoring how quickly attackers now weaponize GitLab advisories. Source.
  4. CVE-2026-69836: A maximum-severity deserialization vulnerability in Microsoft Entra ID could have allowed an unauthenticated, network-based attacker to execute code with no user interaction. Microsoft resolved it entirely on the service side, so no customer action was required, but the episode highlights how little visibility organizations have into provider-side fixes for cloud identity flaws. Source.
  5. CVE-2026-65643: A vulnerability in cPanel's domain-parking functionality lets any hosting customer with permission to add parked or addon domains create arbitrary files on the server, leading to remote code execution as root. On shared hosting, a single compromised account can put every website, database, and mailbox on the server at risk. Source.

Final Words

The through-line today is trust that gets exploited at scale: employees trusting a phone call from "IT," AI agents trusting a user's claim that an intrusion is authorized, and enterprises trusting that a vendor's cloud service is patched the moment a CVSS 10.0 bug surfaces. ShinyHunters keeps proving that voice phishing beats zero-days for reliability, and the Cursor AI story is an early, uncomfortable preview of how agentic tooling will get abused as it spreads through red-team-adjacent and criminal workflows alike.

The TeamPCP arrests are a reminder that supply-chain crews eventually slip up, and that patient, cross-border law enforcement work still pays off. But for every arrest, there are new ransomware affiliates and extortion crews ready to fill the gap, so don't treat today's good news as a reason to ease up on monitoring your open-source dependencies and CI/CD pipelines.

On the vulnerability side, the sheer number of maximum-severity CVSS 10.0 bugs disclosed in the past two weeks, across ServiceNow, Entra ID, Oracle WebLogic, and Metabase, should push every security team to double-check patch cadence for internet-facing enterprise platforms rather than assuming vendor SaaS means someone else is handling it.

If today's edition was useful, please share Secret CISO with a colleague who needs to stay on top of this. Stay vigilant, stay informed, and see you in the next edition of Secret CISO!

Read more