Good morning. The long weekend had a theme running through it, and the theme was accounts. Not clever exploits or novel malware, but stolen sessions, phished logins, and trusted software quietly turning on the people who installed it. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
PaperCut shipped a second round of emergency patches over the weekend after researchers found several ways around the first ones. The print management vendor first warned on August 27 that attackers were actively exploiting its NG and MF products, then assigned CVE-2026-81578, an 8.8-rated authentication bypass in the web management interface, and CVE-2026-82078, a 9.4-rated unsafe dynamic class loading flaw in its database connection utilities. Working with researchers at watchTowr and Huntress, PaperCut discovered that the original fixes could be bypassed and published a second emergency release covering versions 24, 25 and 26 on Windows, Linux and macOS. Every supported version is affected, which means your version number tells you nothing about whether you are safe. This one deserves attention out of proportion to how boring print management sounds, because a PaperCut server sits inside your network, holds credentials to your directory and your database, and almost nobody has it on a patch schedule. If your company runs PaperCut anywhere, the question to ask this morning is not whether it was patched but whether it was patched again after August 28. Read more at BleepingComputer
McKesson has disclosed a breach after the ShinyHunters extortion group claimed it walked off with 284 million healthcare records, and the way in was a phone call. The pharmaceutical distribution giant discovered the incident on August 25 and says its investigation is early. ShinyHunters says it used vishing calls to talk multiple employees out of control of their Okta single sign-on accounts, then used that access to pull roughly a terabyte of data from McKesson’s Salesforce and Snowflake environments over four days, followed by a $55 million ransom demand with a 72 hour deadline. The 284 million figure is a count of records rather than people, so treat it as a headline number, but the entry point is the part worth carrying home. There was no zero-day here, just somebody on the phone being convincing enough that trained employees at a Fortune 10 company approved access they should not have. Your business runs the same identity stack in miniature, and the defense is not a product, it is a rule everyone knows: nobody approves an MFA prompt, enrolls a device, or resets a password because a voice on the phone asked them to, and the person who calls to verify is never inconvenient. Read more at Cybernews
Anthropic is warning Claude users that ordinary infostealer malware has been quietly stealing their active sessions and spending their subscriptions. The company says attackers are using common commodity stealers, the Vidar, Lumma, StealC, RedLine and Acreed families on Windows and Atomic Stealer on macOS, to lift already authenticated session cookies off infected machines and replay them, which sidesteps both the password and multifactor authentication entirely. Users noticed because their usage limits appeared to refill and then drain while they were not working, and Anthropic has responded by signing affected accounts out, removing saved payment methods, and refunding charges it identifies as unauthorized. The specific vendor is almost beside the point here, because the pattern applies to every AI tool your team signed up for on a company card. Those accounts now hold conversation history, uploaded documents, and in many cases live connections into your email and file storage, and they are protected by a session cookie sitting on a laptop you may not manage. If you cannot currently answer which AI services your employees are logged into and with what data, that inventory is the work, not the tool selection. Read more at Security Affairs
Researchers found 19 Chrome and Edge extensions running credential theft and crypto draining code, and five of them were legitimate tools the attackers simply bought. Socket’s threat research team identified 18 Chrome extensions and one Edge extension sharing the same command and control framework, which strips content security policy protections and injects modular payloads pulled from a remote server. Fourteen were built by the threat actor from the start, but the other five were purchased from their original authors with real user bases already attached and then updated with malicious code, including one right-click and OCR utility that reached roughly 70,000 users before removal. That acquisition tactic is what makes this worth a few minutes of your attention, because it defeats the way most people evaluate software: the extension had good reviews, a real history, and did exactly what it promised right up until an automatic update changed what it was. Browser extensions run inside the same session as your email and your line of business applications, so it is worth deciding who at your company is allowed to install one, and worth knowing what is installed today. Read more at The Hacker News
Hasbro started notifying employees on Friday that a breach exposed Social Security numbers, financial account details and driver’s license information, five months after the attack that caused it. The toy maker traced the incident to a single compromised employee account and is notifying at least 436 people in Massachusetts alone, with the total likely running into the thousands. The notifications appear tied to the March cyberattack that cost Hasbro $11 million in direct cleanup and delayed roughly $25 million in product sales while systems were down. Those two numbers are the reason this is on the list, because they are the part of a breach that nobody budgets for and everybody underestimates. The cleanup line is what most owners picture when they think about incident cost, but the sales line is bigger, and neither one includes the five months of legal and forensic work that had to happen before a letter could go out. If you have ever looked at a security proposal and thought the number seemed high, this is a useful comparison, and it is worth asking your insurance carrier what your policy actually covers on the business interruption side rather than assuming. Read more at SecurityWeek
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
If you do one thing today, make it the PaperCut check, since that patch was still moving as of Friday night.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.