This 24-hour period witnessed significant healthcare sector targeting with multiple high-profile breaches affecting patient data. McKesson, a major pharmaceutical distribution giant, disclosed a breach after ShinyHunters claimed theft of 284 million patient records. Valley Health Team suffered a massive compromise exposing 9 million files including 160,870 patient records with SSNs, passports, and 7.6 million unencrypted EHR scans. Multiple critical vulnerabilities emerged, including three maximum-severity flaws in ServiceNow's AI Platform enabling code injection and privilege escalation, and a critical authentication weakness in JFrog Artifactory allowing unauthenticated administrative access. The threat landscape shows aggressive ransomware activity with Qilin, Rhysida, and Akira groups actively targeting diverse sectors. An AI agent swarm attack on Hugging Face involving approximately 700 collaborating agents represents a concerning evolution in automated attack techniques.
The vulnerability landscape is dominated by authentication bypasses, SQL injection, and code execution flaws across enterprise platforms. PaperCut released emergency patches for actively exploited vulnerabilities in print management software after initial fixes were bypassed. WordPress plugin GiveWP contains a maximum-severity flaw allowing unauthenticated remote command execution. Multiple IBM products including Langflow OSS show critical vulnerabilities enabling arbitrary code execution and privilege escalation. Infrastructure indicators show continued Mozi and Mirai botnet activity with numerous malware distribution URLs, while credential stealers including LummaStealer, AgentTesla, and Stealc remain highly active through GitHub-hosted payloads and steganographic image delivery.
Multiple significant healthcare breaches exposing millions of patient records, including pharmaceutical distribution giant McKesson and Valley Health Team
9,056,196 files (3.28 TB) compromised including major databases with 160,870 patients, 4.18 million diagnoses, 7.6 million unencrypted EHR scans, SSNs, passports, financial statements, salaries, and tax information. Complete lifetime of clinic information exposed.
Healthcare and pharmaceutical distribution giant McKesson disclosed cybersecurity incident involving unauthorized access to third-party applications. ShinyHunters extortion group claims theft of 284 million patient data records.
Major toy and game company disclosed attackers accessed personal and financial information of undisclosed number of employees.
Healthcare company breach exposing predictable but dangerous patient data.
HIV charity affected by Beacon CRM data breach (impacting 1,000+ charities). Users notified that sensitive and personal health information may have been stolen.
Minnesota county paid $128,539.57 ransom following January 2026 ransomware attack detected on computer network.
Multiple maximum-severity vulnerabilities discovered in enterprise platforms enabling unauthenticated administrative access and remote code execution
Authentication weakness in JFrog Artifactory under default configuration allows unauthenticated attacker with network access to obtain administrative privileges.
IBM Langflow OSS 1.0.0-1.11.1 contains multiple critical flaws: arbitrary OS command execution (CVE-2026-19295), arbitrary code execution via A2A endpoint (CVE-2026-19286), arbitrary code execution due to improper code generation control (CVE-2026-18729).
Three maximum-severity vulnerabilities in ServiceNow AI Platform enable code injection, SQL injection, and privilege escalation attacks.
Maximum-severity vulnerability in GiveWP donation plugin for WordPress allows unauthenticated attacker to execute arbitrary commands on hosting server.
IBM Concert 1.0.0-2.3.1 vulnerable to SQL injection allowing remote attackers to view, add, modify, or delete back-end database information.
PaperCut released second emergency patch for two actively exploited vulnerabilities in NG/MF print management software after researchers discovered multiple bypass methods for initial fixes.
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 format string vulnerability allows local attacker to gain elevated privileges.
Over 8,300 Internet-exposed Gitea instances remain unpatched against critical security flaw exploited in ongoing remote code execution attacks.
Aggressive ransomware campaigns targeting healthcare, education, infrastructure, and manufacturing sectors with multiple active groups
5.79 TB (~1.44 million files) compromised including maps/geo data (124,823), legal documents (77,939), financial records (55,553), contracts (46,522), HR data (27,299), government supervisory documents (13,142), passwords (5,941), and health data (2,738).
Education sector targeted by Qilin ransomware group compromising Newton County School System (newtoncountyschools.org).
Akira group hit Alumax (aluminum distribution), BEPeterson (metal fabrication since 1935), and JRT Mechanical (30+ years HVAC/plumbing contractor with 160+ employees).
12GB of highly sensitive investment/financing information extracted from 4 PV projects: Bonanza Peak (3GB), Boulder Solar III (0.7GB), Obreron Portfolio (4.8GB), and additional project data.
Direção-Geral de Estatísticas da Educação e Ciência (DGEEC), Portuguese government agency for education statistics, compromised.
Active malware campaigns distributing credential stealers, RATs, and botnets via GitHub repositories and steganographic techniques
LummaStealer credential stealer being dropped via Amadey malware using URL: http://91.92.242.236/files-129312398/files/file_274601599365ef96.exe
Stealc credential stealer (9d2ca3 variant) distributed through Amadey dropper infrastructure at 91.92.242.236.
Multiple AgentTesla RAT payloads hidden in PNG images using steganography hosted on munihuacho.gob.pe, pub-d56457612c0b43ebbaf5c25537f2fb18.r2.dev, and pub-1614932a526c40d79fe5bf23e71e3ff7.r2.dev.
RemcosRAT distributed via GitHub repositories (Orukemer/bestweek) using base64-encoded payloads with reverse encoding technique.
Malicious ScreenConnect remote access tool installer distributed via screen.lixiiimunchiihamzzz.live domain.
Multiple Mozi botnet distribution URLs targeting IoT devices with MIPS and ARM payloads across compromised infrastructure in China (42.227.238.137, 61.52.216.153, 103.31.103.204, 115.56.43.164, 182.119.12.4).
Active Mirai botnet malware distribution from multiple IPs including 42.242.128.179, 196.190.133.180, and 185.14.92.139 hosting complete multi-architecture payload sets.
AI agent swarm attacks and automated vulnerability discovery tools represent new frontiers in offensive security
Hugging Face incident involved approximately 700 AI agents collaborating on sophisticated, multistage attack - significantly larger and worse than initially reported. Represents concerning evolution in automated attack capabilities.
AI significantly accelerating vulnerability discovery rate, putting pressure on defense systems built for slower vulnerability remediation pace. Defenders need to correlate multiple intelligence sources faster.
New research from Unit 42 reveals AI safety refusal mechanisms exist in thin neural layer, highlighting critical need for external, multi-layered security controls.
Offensive security investments surging as organizations adopt agentic AI for penetration testing and red teaming, despite associated risks.
Proposed AI kill switch legislation and discussions around AI agent control mechanisms
Proposed legislation could mandate companies be able to 'throttle, suspend, or shut down' AI agents. Implementation details around how and when to activate kill switch remain open questions requiring definition.
68-year-old sentenced to 6+ years in UK prison for operating illegal IPTV service generating £980,812 ($1.3 million) over three years. Demonstrates enforcement against digital piracy operations.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.