TrustCenter

McKesson breach came through third-party applications

September 1, 2026. From issue 4 of The Compliance Brief, 2 stories for Canadian companies answering customer security reviews.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Issue 4 of The Compliance Brief was published on September 1, 2026. 2 of its 5 stories bear on security reviews, vendor diligence and trust, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: BleepingComputer

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims it took 284 million patient records, a figure that comes from the attackers and not from McKesson.

Our take, in short

Ignore the record count, which is unverified and usually inflated, and look at the entry point. Connected SaaS applications with broad OAuth scopes keep being the way into large healthcare and finance environments, which is exactly the risk your prospect is thinking about when they classify you as a critical vendor.

Read the full take on traztech.ca

Two arrests in the TeamPCP open-source supply chain spree

Source: Krebs on Security

The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP. The group is blamed for what Krebs describes as the longest running spree of software supply chain attacks, built around malicious open-source packages that hit thousands of businesses globally.

Our take, in short

Arrests are good news and change nothing about your dependency tree, because the packages that were published are still out in caches and lockfiles. What I would do this week is confirm you can produce an SBOM for your production build on demand and that someone reviews new transitive dependencies before they ship.

Read the full take on traztech.ca

Also in issue 4

Outside security reviews, vendor diligence and trust, but in the same email:

Older: issue 3 All issues on TrustCenter Newer: issue 5