<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Healthcare-Breach on CuraSec</title><link>https://curasec.metacog.co.kr/tags/healthcare-breach/</link><description>Recent content in Healthcare-Breach on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 29 Aug 2026 15:36:18 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/healthcare-breach/index.xml" rel="self" type="application/rss+xml"/><item><title>McKesson discloses breach; ShinyHunters claims 284M patient records</title><link>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</link><pubDate>Sat, 29 Aug 2026 15:36:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Breach was via unauthorized access to third-party applications, not a patchable CVE; reinforces the need to audit and restrict third-party SaaS access, but no concrete engineering action is available from this disclosure alone.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters attribution is a useful actor profile update, but no IOCs, TTPs, or detection-relevant technical detail are published yet; monitor for follow-on disclosures that include actionable indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> McKesson is a major healthcare and pharma supply chain vendor — if your organization has a relationship with them, confirm exposure scope this week and request their incident attestation; 284 million claimed patient records puts this in HIPAA notification and board-visibility territory.&lt;/li>
&lt;/ul></description></item></channel></rss>