10 min read

this week in security — august 30 2026 edition

Boston Scientific knocked offline in major hack, U.S. seizes Chinese botnet, Australia arrests PCPTeam hackers, U.S. water hacks broader than first disclosed, Grand Theft Auto VI hit by leaks, Russia warned not to attack NATO, and more.
~ ~

Medical device maker Boston Scientific was hacked, its network knocked offline, and some patients affected
Irish Examiner: Boston Scientific, a maker of medical and heart implants, was hacked and, by the sounds of it, its network largely destroyed after a bunch of its on-premise systems and servers were scrambled. Thousands of staff at its Cork locations were sent home on full pay after network links across the company were cut. In an 8-K filing, the company said it was hit by "global disruption" to its operations, including some of its medical monitoring tech, per the company's status page. Expect this ongoing incident to last potentially several weeks as details are still emerging. It's the latest in a series of major hacks targeting U.S. healthcare giants in recent weeks; including Stryker, in which Iranian hackers broke in and used its internal tools to remotely wipe thousands of devices. Also this week: Nutex Health, which operates dozens of hospitals across the U.S., says some "private" data may have been taken in a breach; and ShinyHunters says it hacked pharma distributor McKesson and stole millions of patient records… yikes.
More: Boston Scientific | TechCrunch ($) | Reuters ($) | MDDI Online | Bleeping Computer

DOJ seizes domains of hacking platform used by Chinese hackers to target the U.S.
U.S. Justice Department: U.S. prosecutors ran a victory lap for taking down a Chinese botnet that they say was used by Beijing and its proxies to launch cyberattacks against the U.S., including several federal government departments. By taking out the domains, which were hardcoded into the malware's code, the botnet stopped working and locked out its operators. But the DOJ walked back some of its claims, including that the botnet was used to hack the U.S. Senate in 2026, later saying that only a handful of departments were actually compromised over the years. As Reuters notes, the "distinction matters because it narrows the scope of confirmed breaches." Still, it's a win…-ish for prosecutors (albeit not for accuracy). Also: The ATF agency confirmed a "major incident" after a computer storing targets of investigations was hit with ransomware, triggering a mandatory notification to Congress.
More: Lumen | National Security Agency | Reuters ($) | Wired ($) | @FBICyberDiv

a screenshot of qtproxy[.]xyz, which currently displays an FBI seizure notice saying that the site was used by cyber threat actors known as QTFY, operating from China, to carry out cyber operations for the Chinese government.

Australian police arrest two alleged TeamPCP members accused of software supply chain hacks
Krebs on Security: You will not want to miss this breathtakingly good reporting from @briankrebs, who over the course of months identified then spoke with the alleged leader of TeamPCP, the hacking crew that caused carnage through a series of open-source hacks targeting the broader software supply chain. Australian national Ruben Thomson was one of the two people arrested this week for the hacks, which used self-propagating malware that relied on feeding it stolen passwords so that it would break into those services and steal more data. The hacks hit tons of downstream companies, from Trivy and LiteLLM, to Mercor, GitHub and OpenAI. Thomson was eventually caught after a trail of cat-themed profile photos used in his online accounts led police to his door.
More: Australian Federal Police | KELA | Flare | Risky Biz | Cyberscoop | GovInfoSecurity

John Hammond post on X: "Ruben Thomson, of Perth, Australia, was just arrested.   With an affinity for kitty cat profile pictures, it was a unique avatar that he left on a Steam profile for a decade that would be his undoing," followed by a photo of a person being arrested with their face blurred, and another photo of the person's alleged profile photo appearing as a cartoon cat.

Cybercrooks steal millions of customer records from U.K. airport group
BBC News ($): Hackers have stolen the records of at least 8.7 million people from Manchester Airport Group, which operates several U.K. airports, including Stansted and East Midlands. Most of the stolen data included email addresses, but also included car booking and Wi-Fi sign-up information (such as phone numbers, vehicle registrations, and postal codes). The airport group, which handled some 60+ million customers last year,  said it hasn't paid the hackers' ransom.
More: Manchester Airport Group | The Register | RTE

How journalists identified thousands of people conned by a scammer
NRK: A scammer set up a fake profile and website impersonating a well-known investment advice creator that was used to scam people. Norwegian media enlisted a security researcher to dig into the scammer's website and found 100 clone sites, most of which had the same glaring bug that exposed details about the thousands of victims who were tricked into sending money to the scammers. The reporters traced the scammer to Nigeria. Separately: Norway's government was hit by a DDoS over the past several days, knocking some of its websites offline. A pro-Russian group took credit for the disruption.

This 'Glassbox' tool lets you see how easily your browser can be uniquely identified
Glassbox: A new website lets you check to see how uniquely identifiable your web browser is to outside trackers, like advertisers, which can be used to track you across the web. The Register has a write-up, and Hacker News with some critique, but good for awareness. Personally a big fan of EFF's Cover Your Tracks, which functions similarly.

Health systems warn of phishing campaign spoofing Epic patient portals
Becker's Hospital Review: Dozens of health systems are warning patients to ignore phishing messages that purport to offer rewards relating to Epic MyChart, the popular electronic medical record system widely used by medical practices around the United States. If you see something by email relating to a "MyChart Medicare Kit," it's someone trying to steal your login information. (via DataBreaches.net

Hackers targeted over 100 water providers during July hacking spree
CISA: Last month's alarm over hacks on critical infrastructure targeted over 100 internet-connected water systems, according to CISA, revealing for the first time the scale of July's mass-hacks on water and wastewater providers across a dozen U.S. states. Disclosure alert: I wrote some words about this in TechCrunch ($). Meanwhile in slightly positive news: CISA published the results of a stress-test it was asked to carry out on a water provider with a pretty enlightening report into how its red-teamers got in, but what the provider did to nix the authorized hack. More from Cyberscoop.

OpenAI publishes report on how its unreleased AI model hacked Hugging Face
Axios: OpenAI dropped a new report detailing its hack into Hugging Face earlier this year, including how its autonomous agents exploited a known Linux vulnerability to escalate privileges on OpenAI's own network, allowing the unreleased AI model to move across the company's systems and onto the wider internet. Also, an interesting tidbit from @RyanGreenblatt, who was involved in Hugging Face's incident response, on why Greenblatt called the company's probe into the hack a "slop-vestigation." More also from Ars Technica and SecurityWeek

Cyber Command to brief House lawmakers after cluster of suicides
Bloomberg ($): U.S. Cyber Command officials are set to brief House Armed Services Committee lawmakers on September 3 following an unusually high number of deaths by suicide in the unit's secretive cyberwarfare unit. This follows really important and powerful reporting by @patrickhowelloneill and @JZBleiberg, who first brought this issue to light earlier this month.

Prepare for warfun times! The U.K.'s new prime minister reportedly chickened out of launching a long-planned national emergency preparedness campaign on grounds that it would send ~bad vibes~ for the first few weeks of his leadership. The Financial Times ($) reports that the plan aimed to launch a public awareness campaign against the backdrop of ongoing Russian threats and cyberattacks. It's not like there's much to be concerned abo...

U.S. warns Russia not to attack NATO: CIA director John Ratcliffe went on a secret* trip to Russia (*so secret we all know about it) to warn top Kremlin officials not to escalate their war in Ukraine or target NATO. This comes as U.S. intel suggests Russia is ramping up its offensive by way of cyberattacks on critical infrastructure). BBC's top natsec reporter Frank Gardner said the last time a CIA director visited Moscow was in late 2021 as Russia's President Putin was drawing up plans to invade Ukraine...

a screenshot showing a snippet from the BBC article, which reads: "Ratcliffe met Russian intelligence officials on Tuesday - notably his opposite number in Russia's overseas spy agency, Sergei Naryshkin - after arriving unannounced on a US military plane, the Kremlin confirmed. It's been nearly five years since his predecessor William Burns made this trip and that was at a similarly tense time, just as Russia was drawing up plans to invade Ukraine. So, this is probably serious."

Trump plots to plug power flaws: A new Trump executive order (and "fact" sheet) prohibits certain foreign-made equipment from being used in the U.S. bulk power grid, citing security flaws, backdoors, and sabotage risks. The order is seen as a response to China's growing dominance in this space. So that's power inverters and robots, Roombas, routers, and now energy grid components, in case you were keeping track of all the bans. (via SecurityWeek, Bloomberg ($), Utility Dive)

U.K. seeks to block risky tech: Meanwhile, London is looking to secretly block tech vendors that pose a national security risk to critical sectors. The move aims to get ahead of emerging threats, whereas currently a threat has to be declared first before a company can be blocked. The plan aims to expand on the rules that allowed the U.K. to previously ban Huawei gear in the U.K.'s 5G networks. (via Computer Weekly ($), The Record)

GTA 6 leaks are breaking the internet: A ton of leaks are hitting the upcoming release of Grand Theft Auto 6. The hack, leak, and extortion effort seems to suggest someone had privileged access to the gamemaker Rockstar's systems, or was given data by an insider. (via Cyberscoop, Vice, Kotaku, IGN)

Paylogix reports hack: Optional benefits provider Paylogix has now confirmed a 2025 data breach affecting thousands of people, including their credentials, electronic signature, health information, passport number and U.S. immigration numbers. (via Insurance Business, Paylogix [PDF])

What's that sound…? It's the sound of peace, quiet, and calm in the happy corner. Let's get started. 

A few weeks ago, Apple said it would change its Hide My Email privacy service, which some said would have made these private email addresses easier to block by moving them away from its iCloud domain. Apple changed its mind and reneged following "further consideration," reportedly after facing internal pressure from its own staff. 

Pour one out (each) for philanthropist and American icon Dolly Parton and actor Tim Curry, who both left us this week at the age of 80. Two absolutely incredible people who lived amazing lives and left profound legacies. My personal favorite memory of Curry is a throw back to the days of the video game Command and Conquer: Red Alert 3, which I played a ton as a kid with my brother. Curry plays one of the three conflicting world leaders, and can barely stay behind the fourth wall as he delivers this classic monologue about escaping to "SPACE!" 

an animated GIF of Tim Curry as a Soviet Leader in the video game Red Alert 3, he can be seen here dressed in uniform, trying not to laugh while in character, as he breaks out while looking upwards to say, "SPACE!"

And, lastly this week. Using these parkour cats as a security lesson… who needs to break in with a zero-day when "admin/pass" backdoor account was sitting right there?

an animated GIF of a cat jumping, parkour-style, over a child-proof gate with the caption, "zero day," while another cat simply walks through the flap in the gate with a caption that redas: "admin/pass," to indicate a very simple backdoor account.

Have good news to share? Get in touch! this@weekinsecurity.com.

This week's incredibly cuddly cyber cat tiger is Ahsher, who can be seen here hanging out with his mini-me friend Boomer and, of course, Gil. If there's anyone you'd want on your cyber defense team, it's this triforce of kick-ass security. Thanks so much to friend of the newsletter Gary R. for sending in!

Ahsher is a life-size stripy stuffed cuddly tiger who can be seen here on a sofa, hanging out with his cuddly stuffed toy friend Boomer and his other friend Gil, who is a white fluffy bear with a black nose.

🐈 Please send in your cyber cats! 🐈‍⬛ Keep that cyber-cat supply coming in! If you have a cat or a non-feline friend, please send me an email with their photo and name and they'll be featured in an upcoming newsletter! (If you've sent in before, I'd love an update!)

And that's all there is for this week — thanks so much for making it through, reading, subscribing, and supporting this newsletter! I'm so thankful for your readership, it means the world to me and I hope you enjoy this newsletter as much as I love writing it.

If you liked this newsletter, please share it on your social media, forward it to a friend, or suggest it to a colleague. And if you have anything you want to share for next week's edition (I love hearing from you, and you often share things I haven't seen!) please get in touch.

Thanks for making my Sunday a bit brighter. I'll be back next week as usual with the latest rundown from the week in cyber.

Until then,
@zackwhittaker