Sep 1: PaperCut KEV, McKesson Deadline, MAG Claim
CISA adds two PaperCut CVEs to KEV; active intrusions confirmed. McKesson deadline active. FulcrumSec confirms 80GB Manchester Airports claim. WatchGuard patches critical RCEs.
- PaperCut: CISA added CVE-2026-82078 and CVE-2026-81578 to KEV on Aug 31. Active intrusions confirmed. Federal deadline Sep 14.
- McKesson breach confirmed. ShinyHunters claims 284M records; attacker deadline now active. Record count unverified.
- FulcrumSec claims 80GB exfiltrated from Manchester Airports Group. MAG confirmation not issued as of publication.
- Aurora ransomware operators confirmed using Cursor AI in attacks on 20-plus organizations across nine countries.
- Aesto Health: 9.5M patient records stolen from AWS-hosted infrastructure.
CISA added two PaperCut CVEs to its Known Exploited Vulnerabilities catalog on August 31. Active intrusions confirmed as of September 1. Two extortion deadlines are live. A healthcare data breach affecting 9.5 million surfaced this morning.
PaperCut: KEV, Active Intrusions, Federal Deadline Sep 14
CVE-2026-82078 and CVE-2026-81578. Both added to CISA KEV on August 31. Active data theft attacks using these vulnerabilities confirmed by BleepingComputer on September 1. Federal agencies must remediate by September 14 under Binding Operational Directive 22-01.
Confidence: exploitation confirmed (CISA KEV, BleepingComputer named-outlet reporting). Emergency Patch Release 2 is the remediation path. Any PaperCut NG or MF deployment without that patch should be treated as exposed. Full coverage: PaperCut Active Intrusions: CISA Adds Flaws to KEV.
Extortion: Two Active Deadlines
McKesson. Company confirmed the breach. ShinyHunters claims 284 million records. The attacker’s payment deadline is now active as of September 1. Record count of 284M is ShinyHunters’ claim; not independently verified. Full coverage: McKesson Breach: ShinyHunters Deadline Now Active.
Manchester Airports Group. FulcrumSec claims 80GB exfiltrated and threatens public release. MAG disclosed a cyberattack on August 28; FulcrumSec has now taken credit and set a leak timeline. Confidence: MAG has not confirmed FulcrumSec’s specific claim as of publication. Full coverage: FulcrumSec Claims 80GB Manchester Airports Hack.
Aurora Ransomware: AI-Assisted Intrusion Operational
Aurora ransomware operators used Cursor AI to assist attacks against more than 20 organizations across nine countries. Attribution from CloudSEK and Gambit Security, published in The Hacker News. Confidence: two named research firms, single reporting chain; treat as reported.
AI-assisted intrusion tooling is now operational in active ransomware campaigns. Coverage: Aurora Ransomware Uses AI Coding Tools in Attacks.
Round-up
- Aesto Health: 9.5 million patients affected after attackers accessed AWS-hosted healthcare infrastructure. Personal and health records stolen. Per SecurityWeek. Confidence: breach scope from company disclosure.
- WatchGuard Fireware OS: Three critical vulnerabilities in the iked process allow unauthenticated remote code execution. Patch available. Per SecurityWeek.
- Langflow and Rails: Active exploitation of CVE-2026-0768 (Langflow) and a critical Ruby on Rails flaw for credential probing and C2 activity, per VulnCheck. Per The Hacker News. Prior Langflow coverage: Public PoC for Langflow 9.8 Unauth RCE.
- ATM Jackpotting: Five Venezuelan nationals pleaded guilty to ATM jackpotting attacks against U.S. machines. Per BleepingComputer.
- CISA KEV — CVE-2026-82078, CVE-2026-81578
- BleepingComputer — PaperCut zero-days used in data theft attacks
- SecurityWeek — McKesson breach, ShinyHunters deadline
- SecurityWeek — FulcrumSec Manchester Airports claim
- The Hacker News — Aurora ransomware, Cursor AI
- SecurityWeek — Aesto Health AWS breach, 9.5M affected
- SecurityWeek — WatchGuard critical patches