DAILY BRIEFING
McKesson Data Breach, Berlin Ransomware Extortion, and PaperCut Patch Bypass
Today's briefing covers major data breaches, active exploitation of enterprise software, and critical vulnerabilities across public and private sectors.
5 stories2 min read

Third-party integrations and unpatched infrastructure remain primary vectors for wide-scale data exfiltration and administrative access across impacted organizations.
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. Extortion group ShinyHunters claims to have stolen 284 million patient data records during the breach.
- Why it matters
- The compromise exposes a massive volume of sensitive patient data, posing severe privacy and extortion risks for healthcare organizations relying on McKesson's ecosystem.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
An integer overflow flaw in Cosmos EVM (affecting v0.6.0-v0.6.1 and v0.7.0-v0.7.1) allowed unauthenticated state manipulations and fund minting/burning after post-delegation write-backs failed unchecked subtraction, resulting in active exploitation across Cosmos EVM chains.
- Why it matters
- All Cosmos EVM chains supporting permissionless vesting-account creation are susceptible to token supply manipulation, financial loss, or chain halts.
PaperCut releases second emergency patch for exploited flaws
PaperCut released a second emergency security patch for PaperCut NG and MF to address two actively exploited flaws after researchers discovered bypasses for the vendor's initial fixes.
- Why it matters
- Organizations relying on PaperCut remain exposed to active exploitation if they only applied the first patch round, risking full server compromise.
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP donation plugin for WordPress allows unauthenticated attackers to execute arbitrary commands on the underlying host server.
- Why it matters
- Unauthenticated RCE allows attackers to gain full operational control over hosting environments running vulnerable GiveWP installations without needing valid credentials.
- What to do
- Update the GiveWP plugin to the latest safe version immediately.
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government confirmed an extortion attempt following an August compromise of its administrative network. Attackers claim to have exfiltrated 5.79 terabytes of data and personal details of 12,076 individuals from the Senate Department for Mobility, Transport, Climate Protection and Environment.
- Why it matters
- Government administrative networks hold sensitive employee and citizen data, leaving affected individuals vulnerable to extortion or follow-on phishing attacks when ransom demands are denied.
Key takeaways
- McKesson disclosed a breach involving third-party apps as ShinyHunters claims theft of 284 million patient records.
- Berlin's state government refused extortion demands following a 5.79 TB data theft from its administrative network.
- PaperCut issued a second emergency patch after threat actors bypassed initial fixes for actively exploited flaws.
- A max-severity GiveWP WordPress plugin vulnerability enables unauthenticated remote code execution on web servers.