This daily summary highlights significant cybersecurity incidents and emerging threats. Updates on the Qilin ransomware attack on the ATF reveal new technical indicators, including specific commands for disabling recovery and clearing logs, and the .agenda file extension for encrypted data. McKesson disclosed a $55 million ransom demand from ShinyHunters following a vishing campaign that compromised Okta credentials, leading to the theft of sensitive employee, physician, and patient data from Salesforce and Snowflake. The Manchester Airports Group breach is now understood to involve potential phishing and valid account exploitation, with data exfiltration over C2 channels; new detection strategies include D3FEND URL Analysis and Database Activity Monitoring.
Boston Scientific operations remain impacted by a global cyberattack, confirmed to be limited to on-premise systems, with no new malicious activity observed since August 25, 2026. The inability to perform remote activations for cardiac monitors poses a direct risk to patient care. In new threats, 19 malicious Chrome and Edge extensions under the 'Superior' campaign have been identified, designed to steal cryptocurrency wallet secrets and exchange credentials. The Silver Fox Group is distributing the ValleyRAT backdoor via signed adware ('QN Wallpaper'), primarily targeting China and India through DLL sideloading. An operational security failure by a Blind Eagle APT operator exposed their malware production pipeline, including research into crypters and infrastructure services. Finally, the 'Spring Ring' campaign has been observed abusing Microsoft Teams for voice phishing (vishing) attacks, aiming to deploy remote management tools or conduct NTLM relay attacks against domain controllers.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.