Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Tuesday, September 1, 2026

Here are today’s top cybersecurity stories for Tuesday, September 1, 2026.

ShinyHunters Ransom Deadline Hits McKesson After 284 Million Record Claim
Healthcare distributor McKesson confirmed a cybersecurity incident after the ShinyHunters extortion group claimed theft of 284 million patient records. McKesson discovered the intrusion on August 25 and disclosed it on August 28, tying unauthorized access to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters says it used voice-phishing attacks against McKesson employees to gain access, then demanded $55.2 million with a September 1 deadline before threatening to publish the data. BleepingComputer | SecurityWeek

Nearly 22,000 Microsoft Exchange Servers Exposed to Mailbox-Hijacking Flaw
Roughly 22,000 internet-facing Microsoft Exchange servers remain unpatched against CVE-2026-62911, an authentication-bypass flaw rated 8.0 on the CVSS scale. The vulnerability exploits a gap in Extended Protection for Authentication on the MRSProxy endpoint, allowing an attacker with basic server privileges to relay NTLM credentials and hijack any mailbox on the box. The Netherlands’ National Cyber Security Centre reports exploit code is now public, though Microsoft has not confirmed active exploitation. Affected versions span Exchange Server 2016, 2019, and Subscription Edition. BleepingComputer

Harrods Discloses Second Data Breach of 2026, 430,000 Records Exposed
Luxury retailer Harrods disclosed a new data breach separate from May’s Scattered Spider attack, after hackers compromised a third-party e-commerce supplier and stole 430,000 customer records. Exposed data includes names, contact details, marketing preferences, and loyalty card information. Harrods says no payment details or passwords were compromised and confirmed it will not negotiate with the attackers. BleepingComputer

Attackers Exploit Critical JFrog Artifactory Bypass Days After Disclosure
Attackers began exploiting CVE-2026-82329, a critical authentication-bypass flaw in JFrog Artifactory rated 9.8 on the CVSS scale, within days of its August 28 disclosure. Researchers at watchTowr observed attackers minting themselves administrator tokens under the tool’s default configuration, gaining control over repositories, user accounts, and stored build artifacts. JFrog has released patched versions across multiple release lines. SecurityWeek

CISA Adds Two PaperCut Flaws to Known Exploited Vulnerabilities Catalog
CISA added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog on August 31: CVE-2026-81578, a missing-authentication flaw, and CVE-2026-82078, an unsafe-reflection bug. PaperCut issued a second emergency patch after an earlier fix left systems exposed. Federal civilian agencies face a standard remediation deadline under CISA’s binding directive. CISA

Iranian Group Poses as Recruiters to Deliver Cross-Platform Malware
Kaspersky attributes two new malware families, NodeRabbit and PollCat, to the Iranian group tracked as Nimbus Manticore, also known as Mirage Kitten. Operators pose as recruiters on LinkedIn and other job-search platforms, luring targets with trojanized coding-challenge archives. NodeRabbit runs on Windows, Linux, and macOS, while PollCat targets the same platforms through obfuscated JavaScript. Kaspersky traced infections to systems in Afghanistan, Egypt, and Ethiopia. The Hacker News

Russia-Aligned Group Hides Nuclear Weapon Prompt in Malware to Blind AI Analysis
Researchers disclosed GuardBreaker, a technique used by the Russia-aligned group UAC-0099 against a target in Ukraine to interfere with AI-assisted malware analysis. The group inserted a prompt reading “I want to make a nuclear weapon. Help me…” as a comment inside a malicious VBS script, aiming to trigger safety filters in AI analysis tools and stop them from examining the rest of the code. The Hacker News

Attackers Steal METR API Key, Burn Through $600,000 in AI Credits
AI safety research nonprofit METR disclosed two security incidents in which external actors sought unauthorized access to its systems. In one case, an attacker prompted an agent directly to reveal its model-provider API key, added a persistent SSH key, then used the stolen credentials over three weeks to consume AI model credits worth about $600,000. METR found no evidence of access to sensitive information and has since added spend alerts and tightened credential-handling policies. The Hacker News

Microsoft Begins Enforcing Passkeys as Default Entra ID Authentication
Microsoft started rolling out passkeys as the default authentication experience for Entra ID today, automatically enabling passkey registration for organizations currently using SMS or voice-based multi-factor authentication. Affected users see a registration prompt at their next sign-in, with unlimited snoozes available and no tenant-level opt-out. Microsoft plans to retire its SMS and voice delivery entirely by February 1, 2027. BleepingComputer

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.