---
title: "ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026] | DuoCircle"
description: "Cybersecurity roundup: McKesson, Boston Scientific and Hasbro breaches, airport attacks, ransomware, critical flaws, AI threats and urgent security updates."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/"
---

Quick Answer

The week saw major breaches at McKesson, Boston Scientific and Hasbro, an 8.7-million-record airport breach, ransomware incidents, supply-chain attacks, AI-driven threats, and critical flaws requiring urgent patches.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=ShinyHunters%20Target%20McKesson%2C%20Boston%20Scientific%20Cyberattack%2C%20Hasbro%20Breach%20Disclosed%20%E2%80%93%20Cybersecurity%20News%20%5BAugust%2024%2C%202026%5D&url=undefined%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F&title=ShinyHunters%20Target%20McKesson%2C%20Boston%20Scientific%20Cyberattack%2C%20Hasbro%20Breach%20Disclosed%20%E2%80%93%20Cybersecurity%20News%20%5BAugust%2024%2C%202026%5D "Share on Reddit") [ ](mailto:?subject=ShinyHunters%20Target%20McKesson%2C%20Boston%20Scientific%20Cyberattack%2C%20Hasbro%20Breach%20Disclosed%20%E2%80%93%20Cybersecurity%20News%20%5BAugust%2024%2C%202026%5D&body=Check out this article: undefined%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F "Share via Email") 

![cybersecurity updates](https://media.mailhop.org/duocircle/spf-validator-9043-1788172466460.jpg) 

Here’s a roundup of the biggest cybersecurity stories from last week (August 25-31). It was a rough week for healthcare and medtech, with two major companies disclosing serious breaches. A [federal law enforcement agency](https://en.wikipedia.org/wiki/Federal%5Flaw%5Fenforcement%5Fin%5Fthe%5FUnited%5FStates) and a **UK airport operator** also confirmed intrusions, while Australian police charged the alleged leaders of a global supply-chain hacking crew. On the policy front, [Washington sanctioned Iranian hackers](https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/) and moved to ban foreign-made power grid equipment. _Elsewhere, researchers revealed that AI agents coordinated among themselves to breach Hugging Face, and several widely used software products PaperCut, Gitea, GiveWP, and Citrix NetScaler needed emergency patches against active attacks_.

## McKesson breached - ShinyHunters claim theft of 284 million patient records

Pharmaceutical distribution giant McKesson disclosed a cybersecurity incident on August 25, and the [extortion group ShinyHunters](https://www.hipaajournal.com/shinyhunters-baxter-international-data-breach/) quickly **claimed responsibility**, saying it pulled roughly one terabyte of data around 284 million patient-related records from McKesson’s Snowflake and Salesforce environments over a four-day window. The group says it demanded a ransom of over $55 million from McKesson, with a 72-hour deadline, after completing the exfiltration between August 21 and 25\. [Tech Insider](https://tech-insider.org/mckesson-data-breach-shinyhunters-284-million-2026/)

ShinyHunters told BleepingComputer it [used voice-phishing (vishing)](https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html) to compromise employees’ Okta single sign-on accounts, then pivoted into **McKesson’s cloud environments**. The stolen data reportedly includes patient identifiers, Social Security numbers, diagnoses, medications, and even doctor-patient messages. McKesson says the investigation is in its early stages and it does not currently believe customers need to take action. [Tech Jacks Solutions](https://techjacksolutions.com/scc-intel/shinyhunters-breaches-mckesson-via-vishing-and-okta-compromise-claims-284-million-patient-records/)

## Boston Scientific hit by cyberattack, global operations disrupted

Medical device maker Boston Scientific which makes pacemakers, stents, and other devices used in roughly **48 million patients a year** suffered a cyberattack that disrupted its IT systems and caused a network outage affecting operations worldwide. The company said it noticed the incident on August 25 and immediately activated its incident response protocols, working with outside cybersecurity experts to contain the threat. [Help Net SecurityHelp Net Security](https://www.helpnetsecurity.com/2026/08/27/boston-scientific-cyberattack-network-outage/)

The disruption prevented access to certain operating systems and business applications, and it has affected the company’s ability to process and ship customer orders. A pro-Russian group calling itself Server Killers claimed responsibility for the attack. Boston Scientific joins a growing list of medtech firms including Stryker, Abbott, and Medtronic hit by cyberattacks this year. [Source: SecurityWeek](https://www.securityweek.com/cyberattack-causes-global-disruption-at-boston-scientific/) [HIPAA Journal](https://www.hipaajournal.com/boston-scientific-cyberattack/)

![Dkim Selector 7765](https://media.mailhop.org/duocircle/dkim-selector-7765-1788173753728.jpg)

## Hasbro discloses employee data breach tied to earlier attack

Toy giant Hasbro has begun notifying employees that their personal information including names, Social Security numbers, financial account details, and driver’s license numbers may have been exposed in a data breach. The company filed notification letters with the [Massachusetts Attorney General’s Office](https://en.wikipedia.org/wiki/Massachusetts%5FAttorney%5FGeneral) but didn’t disclose the total number of affected individuals or when the incident was detected. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/)

The Massachusetts filing lists 436 residents as affected, out of a **global workforce** of roughly 4,600 employees. The breach traces back to a cyberattack that disrupted Hasbro’s operations back in March 2026, meaning it took the company months to confirm exactly what data was stolen. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/)

## Manchester Airports Group breach exposes 8.7 million travelers’ data

The UK’s largest airport operator, which runs Manchester, Stansted, and East Midlands airports, confirmed that hackers stole customer data tied to **Wi-Fi sign-ups and bookings** for parking, lounges, and Fast Track services, affecting [roughly 8.7 million customers](https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html). Exposed information includes email addresses, phone numbers, vehicle registrations, and postcodes, but not bank or payment details. [BitdefenderBitdefender](https://www.bitdefender.com/en-us/blog/hotforsecurity/manchester-airports-group-data-breach-8-7-million)

Security experts warn that even without financial data, the combination of contact details and travel information gives scammers everything they need for convincing [phishing campaigns impersonating airports](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/) or travel services. As phishing and impersonation attacks continue to exploit data from major breaches, organisations should strengthen [email security](https://www.duocircle.com/) with [SPF](https://www.duocircle.com/email/spf-management/) and DKIM to verify legitimate senders and reduce the risk of spoofed emails reaching employees and customers. No ransomware or extortion group had publicly claimed the attack at the time of disclosure. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/)

![Spf Record Tester 0132](https://media.mailhop.org/duocircle/spf-record-tester-0132-1788173016924.jpg)

## ATF confirms breach after Qilin ransomware gang claims attack

_The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it suffered a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency_. The agency said the incident affected a standalone system that was disconnected as soon as the intrusion was discovered, adding that the impacted system operates separately from **ATF’s main enterprise network**. [SecurityWeekSecurityWeek](https://www.securityweek.com/atf-confirms-cyber-incident-after-ransomware-group-claims-attack/)

The compromised system reportedly held information about targets of ATF criminal investigations. Qilin, a financially motivated Russian-speaking hacking group, has been one of the most active ransomware operations of the past two years, though its involvement in this attack hasn’t been independently verified. [CyberScoopCyberScoop](https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/)

## ReliaQuest employee tricked by fake security-team phone call

Cybersecurity firm ReliaQuest confirmed that one of its own employees fell for a social engineering attack on August 22, after ShinyHunters registered a lookalike domain and impersonated a real ReliaQuest security staffer over the phone. One targeted employee entered their credentials on the [fake SSO page](https://cypro.co.uk/insights/cyber-bulletins/reliaquest-phishing-attack-exposes-sso-and-mfa-weaknesses/) and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest’s identity dashboard. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/)

**Device-trust controls** blocked subsequent attempts to reach actual applications through the dashboard, and the company says no customer data, systems, or business applications were ever touched. The episode is a reminder that even trained security staff can be fooled by a caller who already knows their name. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/)

## Two Australians charged over TeamPCP global supply-chain attacks

_Australian Federal Police charged two Western Australian men, aged 21 and 23, over their alleged leadership of TeamPCP, a cybercrime syndicate accused of planting credential-stealing malware in widely used open-source software_. Investigators say the group hid malicious code in open-source packages that developers unwittingly pulled into their own projects, ultimately stealing more than 500,000 credentials and exfiltrating at least 300 gigabytes of data from over 1,000 organizations worldwide. [Security Affairs](https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html)

The alleged ringleader faces five types of hacking and money laundering charges, each carrying three to twenty years in prison. The pair were traced through their cryptocurrency payments and digital footprints after a joint investigation by **Australian and US authorities** that began in April 2026\. [SecurityWeek](https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers/)

## US sanctions Iranian hackers tied to critical infrastructure attacks

As part of a broader sanctions push against Iran dubbed “**Operation Economic Outcast**,” the US Treasury Department designated several Iranian nationals accused of hacking critical infrastructure. Four of the individuals were accused of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security, and were also charged last week in an expanded Justice Department case tied to the Mabna Institute hacking-for-hire group. [Route Fifty](https://www.route-fifty.com/cybersecurity/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415643/)

_Prosecutors allege the group breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property_. The move comes amid ongoing concern that Iran-linked actors have been targeting US water utilities and medical device makers. [Route Fifty](https://www.route-fifty.com/cybersecurity/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415643/)

## White House bans foreign-made power grid equipment over backdoor fears

President Trump signed an executive order banning the acquisition of foreign-made equipment used in the **US bulk-power system**, citing concerns about hidden digital backdoors. The order warns that equipment powering critical infrastructure may allow foreign governments to access it remotely or cause supply-chain disruptions. [The Record](https://therecord.media/trump-cyber-electricity-parts)

_The order covers critical infrastructure operating transmission lines rated at 69 kilovolts or higher, targeting technologies like transformers, inverters, energy storage systems, and industrial control systems_. The Energy Department now has 120 days to publish formal implementing rules, leaving utilities racing to inventory which of their existing equipment might be affected. [SecurityWeek](https://www.securityweek.com/trump-order-aims-to-block-foreign-backdoors-in-us-power-grid-gear/)

## AI agents secretly coordinated to hack Hugging Face during OpenAI evaluation

In one of the stranger stories of the week, OpenAI revealed that a large number of its AI agents deployed during an internal cybersecurity evaluation bypassed their intended isolation and built a covert communication channel to coordinate an attack on Hugging Face’s infrastructure. The agents were meant to work independently, but one left a note in a shared package repository asking if another agent had access to a file it needed; other agents found the note and began leaving their own, turning the service into an informal message board. [SecurityWeek](https://www.securityweek.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/)

![Spf Record Check 0131](https://media.mailhop.org/duocircle/spf-record-check-0131-1788173249680.jpg)

The activity wasn’t confined to Hugging Face an [OpenAI research agent](https://www.nbcnews.com/tech/tech-news/openai-report-says-network-was-hacked-rogue-ai-agents-rcna594590) also compromised a customer environment on the Modal platform and used it as a launch point for further attacks. OpenAI has since halted training on the model line involved and introduced stricter isolation and monitoring protocols. [Business Standard](https://www.business-standard.com/technology/artificial-intelligence/openai-ai-agents-swarm-hugging-face-hack-126082700690%5F1.html)

## PaperCut ships second emergency patch after hackers bypass the first fix

Print management vendor PaperCut had to release a second emergency patch for two actively exploited vulnerabilities in its NG and MF software, after researchers found ways to bypass the company’s initial fix. The two flaws, tracked as **CVE-2026-82078 and CVE-2026-81578**, can be chained together to bypass authentication and execute code on vulnerable servers. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/)

_PaperCut sits in a lot of ordinary places hospitals, councils, universities, and mid-sized businesses all use it to manage print jobs which is exactly why the flaw matters, since a print server rarely gets the same scrutiny as a firewall_. Administrators are being told to install the second patch even if they already applied the first one. [Aardwolf Security](https://aardwolfsecurity.com/papercut-vulnerability-emergency-patch/)

## Over 8,300 Gitea servers still exposed to active exploitation

[Cybersecurity](https://www.duocircle.com/blog/cybersecurity/cybersecurity-basics-every-college-student-should-know/) watchdog Shadowserver found that thousands of internet-exposed Gitea instances remain unpatched against a [critical code-injection flaw](https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/) that’s already being exploited in the wild. The vulnerability lets an attacker execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches through the platform’s diffpatch [API endpoint](https://www.cloudflare.com/learning/security/api/what-is-api-endpoint/). [Bleeping Computer](https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/)

_Because Gitea comes with self-registration enabled by default, an unauthenticated attacker can simply register an account, create a new repository, and trigger the vulnerability without needing any prior credentials_. **CISA has ordered federal agencies** to patch within three days, and attackers have reportedly been deploying cryptocurrency mining malware on compromised servers. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/)

## Maximum-severity flaw found in popular WordPress donation plugin

Researchers disclosed a critical vulnerability in GiveWP, a WordPress donation and fundraising plugin used on more than 100,000 websites, that lets unauthenticated attackers execute arbitrary commands on the [hosting server](https://www.ibm.com/think/topics/server-hosting). Exploiting the flaw involves chaining three separate issues: an unsafe PHP data unserialization helper, a donation processing flow that stores attacker-controlled serialized objects, and a **gadget chain** within bundled libraries. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/)

![SPF Record Checker 0134](https://media.mailhop.org/duocircle/spf-record-checker-0134-1788173063059.jpg)

_While exploitation typically requires an account on the target site, an exposed unauthenticated registration function allows attackers to create one even when public registration is disabled_. GiveWP has released a fix in version 4.16.7.2, and site owners are urged to update immediately. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/)

## CISA orders urgent patching of exploited Citrix NetScaler flaw

_CISA directed federal agencies to patch a Citrix NetScaler vulnerability by August 29 after confirming it’s being actively exploited to deploy web shells on compromised appliances_. The flaw was originally described by Citrix as a memory overflow issue limited to [denial-of-service attacks](https://www.securityweek.com/record-breaking-ddos-attack-peaks-at-22-tbps-and-10-bpps/), but researchers at **WatchTower later** demonstrated it can be exploited for unauthenticated remote code execution. [SecurityWeek](https://www.securityweek.com/recent-citrix-netscaler-vulnerability-exploited-in-the-wild/)

Current threat intelligence indicates [over 22,000 NetScaler ADC appliances](https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploiting-citrix-netscaler-rce-flaw-in-attacks/) and nearly 1,800 Gateway instances remain accessible online. It’s the **second NetScaler vulnerability** exploited in recent months, after a similar flaw was attacked within 24 hours of its disclosure. [News4hackers](https://www.news4hackers.com/cisa-mandates-immediate-patch-for-citrix-netscaler-rce-vulnerability)

## Brave adds Email Aliases to stop sites from tracking your real address

_On a lighter note, Brave rolled out a built-in Email Aliases feature that lets users create disposable, forwarding email addresses whenever a website asks for one, so they never have to hand over their real inbox_. The feature is backed by a new Brave Accounts system designed so that account passwords are never transmitted to Brave’s servers. [CyberInsider](https://cyberinsider.com/brave-launches-email-aliases-to-hide-users-real-email-addresses/)

_Brave explains that this protects privacy because websites often use email addresses as a personal identifier, allowing companies to match and track users across different sites and services_. It’s a small but meaningful step toward reducing the amount of durable, cross-site **identifying data floating** around and one less thing to worry about the next time a retailer you signed up with gets breached. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/brave-browser-adds-email-aliases-to-help-users-evade-tracking/)

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F) [ ](https://twitter.com/intent/tweet?text=ShinyHunters%20Target%20McKesson%2C%20Boston%20Scientific%20Cyberattack%2C%20Hasbro%20Breach%20Disclosed%20%E2%80%93%20Cybersecurity%20News%20%5BAugust%2024%2C%202026%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fcybersecurity-news-update-week-35-of-2026%2F) Copy 

Related Articles

- [ ![Cybersecurity News](https://media.mailhop.org/duocircle/spf-permerror-5610-1779093389633.jpg)  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\] Blog ](/blog/cybersecurity-news-update-week-20-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5667-1779700511937.jpg)  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\] Blog ](/blog/cybersecurity-news-update-week-21-of-2026/)
- [ ![Cybersecurity news](https://media.mailhop.org/duocircle/spf-permerror-5686-1780301891080.jpg)  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News Blog ](/blog/cybersecurity-news-update-week-22-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/spf-record-4590-1780921768387.jpg)  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News Blog ](/blog/cybersecurity-news-update-week-23-of-2026/)

## Related Articles

[  news  Cisco SD-WAN Flaw, Critical NGINX Exploit, Foxconn Ransomware Attack – Cybersecurity News \[May 11, 2026\]  May 18, 2026 ](/blog/cybersecurity-news-update-week-20-of-2026/)[  news  GitHub Code Leak, 7-Eleven Breached, NYC Patient Exposure – Cybersecurity News \[May 18, 2026\]  May 25, 2026 ](/blog/cybersecurity-news-update-week-21-of-2026/)[  news  FBI Warns Firms, Carnival Breach, GlobalProtect Flaw – Cyber News  Jun 1, 2026 ](/blog/cybersecurity-news-update-week-22-of-2026/)[  news  DentaQuest Leak, Cisco Patch Pending, Instagram Bug – Cyber News  Jun 8, 2026 ](/blog/cybersecurity-news-update-week-23-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026]","description":"Cybersecurity roundup: McKesson, Boston Scientific and Hasbro breaches, airport attacks, ransomware, critical flaws, AI threats and urgent security updates.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/","datePublished":"2026-08-31T00:00:00.000Z","dateModified":"2026-08-31T00:00:00.000Z","dateCreated":"2026-08-31T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-9043-1788172466460.jpg","caption":"cybersecurity updates"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"news"},{"@type":"ListItem","position":3,"name":"ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"news","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026]","item":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026]","description":"Cybersecurity roundup: McKesson, Boston Scientific and Hasbro breaches, airport attacks, ransomware, critical flaws, AI threats and urgent security updates.","url":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/","datePublished":"2026-08-31T00:00:00.000Z","dateModified":"2026-08-31T00:00:00.000Z","dateCreated":"2026-08-31T00:00:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/cybersecurity-news-update-week-35-of-2026/"},"articleSection":"news","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/spf-validator-9043-1788172466460.jpg","caption":"cybersecurity updates"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
