McKesson breach came through third-party applications
September 1, 2026. From issue 4 of The Compliance Brief, 3 stories for founders and executives who own security.
Issue 4 of The Compliance Brief was published on September 1, 2026. 3 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for founders and executives who own security.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: BleepingComputer
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims it took 284 million patient records, a figure that comes from the attackers and not from McKesson.
Our take, in short
Ignore the record count, which is unverified and usually inflated, and look at the entry point. Connected SaaS applications with broad OAuth scopes keep being the way into large healthcare and finance environments, which is exactly the risk your prospect is thinking about when they classify you as a critical vendor.
Read the full take on traztech.ca
Cyber claims are fewer and far more expensive
Source: Infosecurity
Chubb reported that average losses per cyber claim are rising even though the number of claims has fallen. Growing privacy litigation in the United States is a significant contributor to the increase in claim costs.
Our take, in short
This matters to you as a buyer of insurance, since your US contracts probably specify a cyber liability limit and renewal quotes are being priced off exactly this trend. Underwriters will ask harder questions about MFA coverage, backup isolation and incident response retainers, and the answers you give them are mostly the same evidence you already assembled for SOC 2.
Read the full take on traztech.ca
Two arrests in the TeamPCP open-source supply chain spree
Source: Krebs on Security
The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP. The group is blamed for what Krebs describes as the longest running spree of software supply chain attacks, built around malicious open-source packages that hit thousands of businesses globally.
Our take, in short
Arrests are good news and change nothing about your dependency tree, because the packages that were published are still out in caches and lockfiles. What I would do this week is confirm you can produce an SBOM for your production build on demand and that someone reviews new transitive dependencies before they ship.
Read the full take on traztech.ca
Related on HireACISO
- Security maturity assessment, seven domains
- Bringing in a vCISO after a breach
- Vendor risk management, done proportionately
- Board security report builder
Also in issue 4
Outside breaches, incidents and security leadership, but in the same email:
- CISA red-teamed two organizations and only one saw it coming
- JFrog Artifactory flaw lands in the KEV catalogue
Older: issue 3 All issues on HireACISO Newer: issue 5
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.