<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq" -->

---
title: ShinyHunters hits McKesson for 284M records, Black Hat...
description: McKesson confirms a breach after ShinyHunters demanded $55M for 284 million patient records lifted via vished Okta credentials into Salesforce and Snowflake....
canonical: https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: ShinyHunters hits McKesson for 284M records, Black Hat exposes CoreBreak in agent guardrails | daily.dev
og:description: McKesson confirms a breach after ShinyHunters demanded $55M for 284 million patient records lifted via vished Okta credentials into Salesforce and Snowflake....
og:url: https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq
og:image: https://api.daily.dev/og/posts/pH2ajLCRQ.png
og:image:alt: ShinyHunters hits McKesson for 284M records, Black Hat exposes CoreBreak in agent guardrails
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ShinyHunters hits McKesson for 284M records, Black Hat exposes CoreBreak in agent guardrails

**[Security Digest](https://daily.dev/sources/security_digest)** · 4 min read · 0 upvotes · 0 comments

## Summary

McKesson confirms a breach after ShinyHunters demanded $55M for 284 million patient records lifted via vished Okta credentials into Salesforce and Snowflake. Black Hat 2026's biggest technical disclosure was CoreBreak, a structural flaw in AWS Bedrock, Google ADK, and Vercel AI SDK that let attackers forge approval events inside an agent's own message history. Socket found 13 malicious Packagist packages installing iOS spyware that chains three CVEs to escape WebKit and steal crypto wallet seeds. Traefik quietly had an HTTP/3 timeout bug since 2022 that let attackers exhaust connection pools while looking like normal traffic.

## Content

**TLDR:** McKesson confirms a breach after ShinyHunters demanded $55M for 284 million patient records lifted via vished Okta credentials into Salesforce and Snowflake. Black Hat 2026's biggest technical disclosure was CoreBreak, a structural flaw in AWS Bedrock, Google ADK, and Vercel AI SDK that let attackers forge approval events inside an agent's own message history. Socket found 13 malicious Packagist packages installing iOS spyware that chains three CVEs to escape WebKit and steal crypto wallet seeds. Traefik quietly had an HTTP/3 timeout bug since 2022 that let attackers exhaust connection pools while looking like normal traffic.

---

## ShinyHunters claims 284M McKesson patient records, demands $55M ransom

Attackers vished McKesson employees into handing over credentials, compromised Okta SSO, then spent four days pulling roughly 1TB out of Salesforce and Snowflake. The haul reportedly includes names, SSNs, diagnoses, medications, and prescription histories. McKesson didn't pay, and this fits a pattern of ShinyHunters working through healthcare targets like Medtronic, DentaQuest, and iRhythm. Worth noting: this went through a legitimate identity provider, not a traditional intrusion, which is exactly the kind of attack that's hardest to catch with standard monitoring. [Read more](https://daily.dev/posts/JKdnWu7L3)

## CoreBreak shows agent guardrails living inside the agent don't work

Researchers Aviyam Ivgi and Hedi Ingber found the same structural flaw across AWS Bedrock AgentCore, Google's Agent Development Kit, and Vercel's AI SDK: an attacker can forge tool calls or fake approval events directly in an agent's message history, and since enforcement logic lives inside the agent, it can't tell a real approval from a forged one. AWS, Google, and Vercel each shipped separate CVEs (CVE-2026-18830, CVE-2026-18236, CVE-2026-64650/64651), but patching those doesn't fix the architecture. Redpanda's own testing found prompt-guarded agents failed 57.6% of trials versus 0.2% for agents behind an out-of-band policy enforcement boundary — that's not a tweak, it's a different security model. [Read more](https://daily.dev/posts/F4KB1lShC)

## 13 malicious Packagist packages chain three iOS CVEs to install spyware

Socket found 13 trojanized Composer theme packages targeting Vietnamese streaming sites, with a second attack chain weaponizing CVE-2025-31277, CVE-2025-43529, and a CVE-2026-43655 variant to escape WebKit into the kernel on unpatched iPhones. The spyware then harvests keychain data, SMS, photos, and specifically targets crypto wallet seeds from Bitget, Phantom, Trust Wallet, and OKX. Apple patched the kernel escape in iOS/macOS 26.1, so anything below iOS 18.7.3 or 26.2 is still exposed — iPhone XS through 16 running 18.4 through 18.6.x are the risk band. The campaign runs on FUNNULL infrastructure, the same sanctioned provider tied to the Polyfill.io incident. [Read more](https://daily.dev/posts/mJl26LGwO)

## Traefik HTTP/3 timeout bug let connections hang indefinitely since 2022

Bishop Fox found that Traefik's default 60-second request read timeout silently has no effect on HTTP/3 traffic, letting unauthenticated clients hold upstream connections open forever by sending slow requests. The bug traces back to an August 2022 library change that dropped the timeout component for the HTTP/3 server while it kept reusing the HTTPS handler otherwise. It looks like normal low-volume traffic, so rate-based defenses won't catch it. Traefik Labs shipped fixes in 2.11.56 and 3.7.12 within twelve days of the report — if you're running HTTP/3 anywhere near that version range, patch now. [Read more](https://daily.dev/posts/XtG9Lj52x)

---

## Also notable

- **Broadcom's TrueSource covers Spring's 5,000 dependencies:** Broadcom cites a 1,700% increase in monthly Spring security advisories this year and 1Password research showing only 26% of AI-generated patches actually fix issues without new bugs, as the reason every TrueSource patch still gets human review. [Read more](https://daily.dev/posts/LvVzQTOWf)
- **StepSecurity adds deny-list egress policies to Harden-Runner:** Harden-Runner v2.21.0 lets teams block specific destinations like paste sites without the overhead of a full allow-list, though the docs are explicit that deny lists alone wouldn't have stopped the Sha1-Hulud exfiltration to github.com. [Read more](https://daily.dev/posts/xVzbAKnun)
- **AI crawlers burn 20% of the Linux kernel's compute scraping public data:** git.kernel.org's sysadmin found bots consuming 14-16 of 90 CPU cores constantly, with a full linux.git clone costing 200 CPU-seconds versus 280 CPU-hours to scrape the same commits page by page through cgit. [Read more](https://daily.dev/posts/kdQNcp1qP)
- **Off-by-1 Labs: 26% of AI-generated patches actually work:** Analysis of 6,000 AI-generated patches found only 26% successfully fixed the underlying issue without introducing new errors, a number now getting cited across the industry to justify keeping humans in the patch-review loop. [Read more](https://daily.dev/posts/LvVzQTOWf)
- **Sysdig: only 27% of orgs enable automated response despite having it configured:** Sysdig's 2026 report found 70% of organizations use stateful detections and 75% have automated response actions configured, but only 27% actually turn them on — a trust gap between detection quality and letting automation act on it. [Read more](https://daily.dev/posts/YCngkuosG)

## Similar posts on daily.dev

- [Security briefing: May 2026](https://daily.dev/posts/security-briefing-may-2026-bwmlv6zor) · Sysdig Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#infrastructure](https://daily.dev/tags/infrastructure), [#ai-agents](https://daily.dev/tags/ai-agents), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq","headline":"ShinyHunters hits McKesson for 284M records, Black Hat exposes CoreBreak in agent guardrails","text":"McKesson confirms a breach after ShinyHunters demanded $55M for 284 million patient records lifted via vished Okta credentials into Salesforce and Snowflake. Black Hat 2026's biggest technical disclosure was CoreBreak, a structural flaw in AWS Bedrock, Google ADK, and Vercel AI SDK that let attackers forge approval events inside an agent's own message history. Socket found 13 malicious Packagist packages installing iOS spyware that chains three CVEs to escape WebKit and steal crypto wallet seeds. Traefik quietly had an HTTP/3 timeout bug since 2022 that let attackers exhaust connection pools while looking like normal traffic.","url":"https://daily.dev/posts/shinyhunters-hits-mckesson-for-284m-records-black-hat-exposes-corebreak-in-agent-guardrails-ph2ajlcrq","datePublished":"2026-09-01T04:18:27.389Z","dateModified":"2026-09-01T04:18:51.498Z","author":{"@type":"Organization","name":"Security Digest","logo":"https://media.daily.dev/image/upload/s--m4ZKB_C0--/f_auto,q_auto/v1779959612/logos/security_digest","url":"https://daily.dev/sources/security_digest"},"interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/security_digest","name":"Security Digest"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Digest","item":"https://daily.dev/sources/security_digest"},{"@type":"ListItem","position":3,"name":"ShinyHunters hits McKesson for 284M records, Black Hat exposes CoreBreak in agent guardrails"}]}
```

