DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 31, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 31, 2026


📊 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. McKesson Data Breach: ShinyHunters Claims Theft of Patient Data

Healthcare giant McKesson has confirmed a major cybersecurity incident after the ShinyHunters extortion group claimed to have stolen 1TB of data, including 284 million records with patient and employee information. The attackers, who are demanding a $55 million ransom, reportedly gained access via a voice-phishing (vishing) attack that compromised employee Okta accounts, allowing them to access Salesforce and Snowflake environments.

📖 Read full report →


2. Boston Scientific Operations Disrupted by Cyberattack

Medical technology manufacturer Boston Scientific is recovering from a cyberattack detected on August 25, 2026, which led to a global network outage. The incident severely disrupted manufacturing, order processing, and shipping operations. The company, which has engaged CrowdStrike for the investigation, stated the attack appeared limited to on-premise systems, with cloud environments unaffected. A full restoration timeline remains unknown.

📖 Read full report →


3. Malicious Browser Extensions Steal Crypto and Credentials

A large-scale malware campaign dubbed 'Superior' has been uncovered, involving 19 malicious browser extensions for Google Chrome and Microsoft Edge. These extensions, some with tens of thousands of users, were designed to steal cryptocurrency wallet secrets, credentials for exchanges like Binance and Coinbase, and other sensitive data. The threat actors either published new extensions or pushed malicious updates to existing, trusted ones.

📖 Read full report →


4. Silver Fox Spreads ValleyRAT via Signed Adware

The cybercrime group known as Silver Fox is distributing the ValleyRAT backdoor by hiding it within a legitimately signed Chinese adware application, 'QN Wallpaper'. The campaign, primarily targeting users in China and India, uses DLL sideloading to execute the malware within a trusted process, thereby evading detection by security software. The sophisticated ValleyRAT provides attackers with full control over compromised machines.

📖 Read full report →


5. Manchester Airports Group Breach Affects 8.7 Million

Manchester Airports Group (MAG), a major UK airport operator, has disclosed a cyberattack that exposed the personal data of approximately 8.7 million customers. The compromised information, collected through services like parking and Wi-Fi registration, includes customer contact details and vehicle registration numbers. The group operates Manchester, London Stansted, and East Midlands airports.

📖 Read full report →


6. DoD Suspends CMMC Phase II Requirements for Review

The U.S. Department of Defense has suspended the Phase II requirements of its Cybersecurity Maturity Model Certification (CMMC) program, which were set to begin on November 10, 2026. While a reform task force reviews the program's third-party assessment component, the DoD emphasized that Phase I self-assessment requirements, based on NIST SP 800-171, remain fully in effect for all defense contractors.

📖 Read full report →


7. Infostealer Exposes Blind Eagle APT Operator's Toolkit

An embarrassing operational security (OPSEC) failure has exposed the inner workings of a cybercriminal linked to the South American APT group 'Blind Eagle'. The operator's own machine was infected with an infostealer, which exfiltrated browser history and other data. The revealed information details the actor's malware production pipeline, including research into crypters and the use of services like Firebase and HostGator for infrastructure.

📖 Read full report →


8. Qilin Ransomware Claims Attack on U.S. ATF

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed it was the target of a cyberattack after the Qilin ransomware group added the federal agency to its data leak site. The breach reportedly affected a standalone computer system that contained information on ATF investigation targets. The agency responded by disconnecting the compromised system to prevent further damage.

📖 Read full report →


9. Spring Ring: Voice Phishing via Microsoft Teams Targets Enterprises

Between January and April 2026, a threat campaign dubbed 'Spring Ring' targeted over 150 employees across at least 10 companies by abusing Microsoft Teams. Attackers, impersonating IT support personnel from external tenants, initiated voice phishing (vishing) calls to manipulate victims. The objectives were twofold: either trick users into executing remote management tools and custom malware or, in a more advanced variant, escalate the attack to perform NTLM relay attacks against the organization's domain controllers using tools like PetitPotam. This campaign signifies a tactical evolution, blending social engineering with real-time voice interaction on trusted collaboration platforms to bypass traditional security controls and gain deep network access.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)