CYBER
THE WANG REPORT · Sunday, August 30, 2026 · HONG KONG
Cyber Intel | INDEX 54 ELEVATED | KEV 7D 5 | CRIT/HIGH 83% | APAC-FSI 22% | EPSS HEAT 46 | NVD + CISA KEV · 250 CVEs


From the desk · Daily take
KT
McKesson Breach Shows Third-Party Apps Still The Weak Point

McKesson disclosed unauthorized access to "third-party applications" that led to theft of patient data, with the ShinyHunters extortion group claiming credit. McKesson is the largest pharmaceutical distributor in the United States, moving roughly a third of the country's drug supply. The company has not named the applications, the access method, or the number of patients affected. What it has confirmed is that the breach did not require compromising McKesson's core network, only a connected application with a trust relationship to it.

That distinction matters for every hospital system and pharmacy chain that treats McKesson as a vendor rather than an attack surface. ShinyHunters has spent 2026 running the same play against Salesforce-linked instances at other major retailers and healthcare firms, harvesting OAuth tokens rather than breaking passwords. The open question for McKesson's downstream customers is which third-party integration touched their own patient records, and whether McKesson's incident response, not yet detailed publicly, will name it before regulators require the answer under HIPAA breach notification rules.

Permalink → All takes →
FROM THE CYBER DESK · WEEKLY COLUMN
KT
ATF Let A Ransomware Crew Set The Clock
ATF confirmed a cyber incident only after Qilin's ransomware crew posted the claim publicly, ceding its own disclosure timeline to the group that broke in.
The Watch-ListFull wire →
Fake Cloudflare Captchas Trick Users Into Installing BackdoorThe Hacker NewsAug 30 Tech Giants Warn AI Powered Attacks Are Outpacing Defensesbing newsAug 30 Five Critical WordPress Flaws Let Attackers Seize SitesThe Hacker NewsAug 30 AI Finds the Bugs Faster Than Anyone Can Fix Thembing newsAug 30
CVE SpotlightFull feed →
CRIT 9.8
JetBrains TeamCity Unsafe Deserialization
CVE-2026-63077 · KEV listed Aug 5 · EPSS 88%
CRIT 9.8
Gitea Code Injection
CVE-2026-60004 · KEV listed Aug 25 · EPSS 85%
CRIT 10.0
Metabase SQL injection via password reset endpoint
CVE-2026-72898 · KEV listed Aug 11 · EPSS 79%
Ranked by CISA KEV status, APAC financial-services and OT relevance, CVSS, and EPSS exploit probability. Source: NVD + CISA KEV, updated Aug 30. Updated daily.
Vendor WatchAll 16 vendors →
Okta Okta Raises 2027 Outlook as AI Agent Security Demand Fuels 23% Stock Jump Aug 29 SentinelOne SentinelOne Stock Drops 8% as Profit Forecast Cut Overshadows Revenue Beat Aug 28 CrowdStrike CrowdStrike AI Security ARR Nearly Triples as Falcon Flex Tops $2.29B Aug 28 AI Security Tools Okta Stock Jumps 23% As AI Agent Security Demand Fuels 2027 Guidance Raise Aug 30
On the Record
OPEN
ATF will issue a follow-up disclosure specifying which systems (NFA registry, eTrace, or case files) were affected by the Qilin intrusion.
Kai Tanner · made Aug 30 · In print →
OPEN
Qilin will publish a data sample from the ATF breach on its leak site to substantiate its claim.
Kai Tanner · made Aug 30 · In print →
OPEN
A future Entra ID vulnerability will score a perfect 10.0 CVSS again, following CVE-2026-69836 and September 2025's CVE-2025-55241.
Kai Tanner · made Aug 23 · In print →
OPEN
HKMA's Cyber Resilience Testing Framework pilot will reach selected institutions by late 2026.
Kai Tanner · made Aug 23 · horizon late 2026 · In print →
OPEN
HKMA's AI-Driven Cyber Risks task force will not publish guidance that regulates agentic AI toolkits and their operators directly, as opposed to the vendor-escalation channel, within 2026.
Kai Tanner · made Aug 16 · horizon 2026-12-31 · In print →
OPEN
Hong Kong's HKMA/SFC will not name specific institutions or attach deliverable dates to their AI cyber risk guidance before Singapore's ACT taskforce publishes its guidance
Kai Tanner · made Aug 2 · In print →
OPEN
MAS's Third-Party Risk Management and AI Risk Management guidelines will close consultation and one or both will become binding rules
Kai Tanner · made Aug 2 · In print →
OPEN
Large SFC-licensed internet brokerages will be required to comply with Circular 26EC35's OTP ban 'as soon as practicable,' effectively immediately, while smaller brokers and newer virtual asset platforms get a 12-month window from July 9, 2026.
Kai Tanner · made Jul 13 · horizon 2027-07-09 · In print →
Calls this desk has made in print, against a named horizon. Each is owned, confirmed, or eaten in print when the horizon arrives.
Cyber Scorecard | CVE Feed | Vendor Watch | Column Archive
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.