In partnership with

~7 MIN READ
Fact Group-IB traced the WindRelay banking-fraud malware back nearly a year, finding almost two dozen samples quietly pinging four control servers between November 2025 and July 2026, all before researchers ever bothered to give it a name. (Group-IB, August 2026)
The Signal
 
This week's theme: the price of getting caught keeps climbing, whether you're a ransomware crew missing a payment deadline or a platform settling a privacy case nobody wants to litigate. Here's what broke, what got exposed, and one bug you should check for right now.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
HEALTHCARE EXTORTION
💊 ShinyHunters Wants $55 Million From McKesson. The Deadline Already Passed.
Intro
McKesson moves roughly a third of the prescription drugs sold in North America, and this week that made it ShinyHunters' newest target.
What Happened
The extortion group claims it stole 284 million records, including patient PII, protected health information, prescription and billing data, and internal employee records, after breaching a subset of McKesson's Oncology and Medical-Surgical business units around August 25. ShinyHunters demanded roughly $55 million and gave McKesson until September 1 to start negotiating before publishing the data.
Why It Matters
McKesson says its services are still operating, but a breach at this scale, at a company that touches most of the US pharmaceutical supply chain, puts patient records and daily operations at thousands of downstream providers at risk too.
The Other Side
McKesson hasn't confirmed the 284 million figure, and ShinyHunters has inflated claimed record counts before, so the real scope could land well short of the number on the leak site.
 
👉 Takeaway
If you're a healthcare provider or pharmacy that works with McKesson, assume some of your patient data may be involved until you hear otherwise directly.
TL;DR: ShinyHunters claims it stole 284 million McKesson records and wants $55 million; the deadline already passed.
Further reading: SecurityWeek
🚨 Can't Miss
 
 
SOFTWARE VULNERABILITY
PaperCut shipped emergency patches for two chained NG/MF bugs that let an attacker skip login entirely and run their own code on the server. CISA added both to its Known Exploited Vulnerabilities list on August 31 after confirming active attacks. PaperCut runs print management at hospitals, schools, and government offices worldwide, so this isn't a niche target.
If you run PaperCut NG or MF, patch now. This one skips the password prompt entirely.
 
SUPPLY CHAIN ATTACK
Attackers forged BGP route announcements to hijack update infrastructure for Virtualizor, VPS management software used by hosting providers, redirecting some servers to a malicious package complete with a valid-looking TLS certificate. Softaculous patched it, shipped a security scanner, and says it's moving to cryptographically signed updates.
If you run Virtualizor, check for a rogue java-jre-update.service file and rotate your API credentials regardless.
 
OPEN SOURCE ATTACK
A new Shai-Hulud worm variant, nicknamed Trinitite, compromised a TanStack Query code-generation package with 150,000 weekly downloads by exploiting a gap in its automated publishing workflow. It steals GitHub, npm, cloud, and CI/CD credentials, then republishes them to public repos using the victim's own token to keep spreading.
If your build pipeline pulled @7nohe/openapi-react-query-codegen recently, rotate every credential that touched it.

AI made PMs faster. Multiplayer mode is still broken.

A PM can summarize research, draft a PRD, and mock up a prototype before lunch. The hard part starts when the team has to decide what actually gets built.

Jira Product Discovery gives product teams one place to capture insights, prioritize ideas with consistent frameworks, and build living roadmaps stakeholders can rally around.

And because it’s connected to Jira, the context behind every decision stays with the work—so developers and their agents know not just what to build, but why.

AI helps PMs move faster. Jira Product Discovery helps the whole team build with confidence.

🤖 AI in Cyber
 
 
AI IMPERSONATION
GreyNoise found 824 IPs using six forged crawler identities impersonating Anthropic, OpenAI, Google, and Perplexity bots, scanning for exposed .env files, AWS credentials, and private keys. Real AI crawlers request robots.txt first; these never did, they went straight for the credential files.
Don't trust a User-Agent string. Block by behavior, not by name.
 
INDUSTRY SURVEY
A survey of 1,500-plus security professionals found 87% are seeing more AI-driven threats than last year, but only 46% feel ready to stop them. The gap isn't budget, it's knowledge: teams say static signatures can't keep up with attacks that adapt on the fly.
If your security awareness training hasn't mentioned deepfakes by name yet, that's this quarter's fix.
🏛️ Privacy, Power & Policy
 
 
CHILDREN'S PRIVACY
TikTok and ByteDance agreed to pay $400 million, one of the largest recoveries ever under COPPA, to settle claims they let kids under 13 create accounts and collected their data through Kids Mode without parental consent, then ignored parents' deletion requests.
If your product touches under-13 users, "we didn't know" stopped being a defense a long time ago.
 
CYBER POLICY
A stopgap funding bill pushed back the expiration of the Cybersecurity Information Sharing Act of 2015 from September 30 to December 11, preserving the legal protections that let companies share threat data with CISA and the NSA without getting sued for it.
The reprieve is temporary. If your compliance team was tracking September 30, reset the calendar to December 11.
🛠️ Tools & Tactics
 
 
Practical play
SonicWall confirmed active exploitation of two new zero-days in its SMA 1000 remote-access appliances, the third such pair this year for the same product line. Chained together, they let an attacker reach sensitive functionality unauthenticated, then run arbitrary commands as admin, a serious foothold on networks at mid-size enterprises, government agencies, and managed security providers.
If you run SMA 1000 (models 6210, 7210, or 8200v), patch today and check admin console logs for anything you didn't authorize. SMA 100 devices and SonicWall firewalls are unaffected.

Stop Paying for 6 Tools. One AI Does It All.

Most e-commerce sellers juggle 6–8 tools and pay hundreds monthly to keep operations running. StoreClaw replaces the stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks profit 24/7. Connect your store and let AI handle the work — no prompts, no complex setup, no credit card required.

🧪 Strange Cyber
 
Strange but real
💳 A Bank Employee Called, and 13 Minutes Later Your Card Was Cloned
Intro
A new Android malware combo can clone your contactless card and drain your account in the time it takes to finish a phone call.
What Happened
Group-IB found fraudsters calling victims across Czechia, Slovakia, and Slovenia, posing as bank staff and talking them into sideloading the SpyNote remote-access trojan. Once installed, SpyNote quietly installs a second tool, WindRelay, which turns the victim's phone into a fake payment terminal: the attacker asks the victim to tap their card against their own phone "to verify it," and WindRelay relays that live NFC handshake straight to the attacker's device for real-world purchases.
Why It Matters
The whole con, from first ring to drained account, runs about 13 minutes, and Group-IB found nearly two dozen samples of this malware quietly operating since November 2025 before anyone gave it a name.
The Other Side
It only works if the victim answers the phone, sideloads an app, and taps their card on command, so basic skepticism about unsolicited "bank" calls still stops it cold.
 
👉 Takeaway
Your bank will never ask you to tap your card against your own phone. If a caller asks you to do that, hang up and call the number on the back of the card.
TL;DR: A phone scam plus two malware tools can clone your contactless card in 13 minutes flat.
Further reading: BleepingComputer

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.