The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Biotechnology/Greentech

Breach intelligence, attack campaigns, and threat reports targeting the Biotechnology/Greentech sector.

36 threat reports
Page 1 of 3

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Biotechnology/Greentech Threat Reports

Showing 1–12 / 36 reports
How North Korea's Contagious Interview Campaign Stole $10.7M Through Fake Job Offers
Impact· CRITICAL

How North Korea's Contagious Interview Campaign Stole $10.7M Through Fake Job Offers

North Korean threat actors operating the Contagious Interview campaign have compromised over 30,000 devices across 100+ countries since 2022, stealing $10.71 million in cryptocurrency from 7,000+ wallets. The WaterPlum group targets web developers, engineers, and blockchain specialists through fake job offers on LinkedIn, delivering malware families including BeaverTail, InvisibleFerret, and FlexibleFerret via malicious coding assessments. The campaign enables persistent access for data exfiltration, corporate espionage, and facilitates North Korean IT worker infiltration schemes. This incident highlights the evolving sophistication of state-sponsored social engineering attacks targeting the growing cryptocurrency and Web3 workforce. The campaign's integration with North Korean IT worker programs demonstrates how threat actors are weaponizing legitimate remote work trends to bypass sanctions and establish persistent corporate access for long-term espionage operations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GPUThor Rowhammer Attack Defeats NVIDIA ECC Protection in AI Infrastructure
Impact· HIGH

GPUThor Rowhammer Attack Defeats NVIDIA ECC Protection in AI Infrastructure

University of Toronto researchers disclosed GPUThor, a sophisticated Rowhammer attack that bypasses NVIDIA's Error-Correcting Code (ECC) protections on Ampere-class workstation GPUs including RTX A4000, A4500, A5000, and A6000 models. The attack exploits undocumented GPU behaviors to avoid Target Row Refresh mitigations, achieving bit-flip rates up to 377,000 flips per GB and enabling denial-of-service conditions and root-level privilege escalation within 1.1 minutes. GPUThor demonstrates 4,548 to 23,597 times higher effectiveness than previous GPU Rowhammer attacks, posing significant risks to AI infrastructure and cloud environments relying on these widely deployed GPU models for machine learning workloads. This vulnerability highlights the growing sophistication of hardware-level attacks targeting AI infrastructure as organizations increasingly depend on GPU-accelerated computing for critical business operations and model training.

4 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Supply-Chain Attack: Hackers Poison Popular Rust Crate arrayref
Impact· HIGH

Critical Supply-Chain Attack: Hackers Poison Popular Rust Crate arrayref

On August 20, 2026, attackers compromised the maintainer account of the widely-used Rust crate arrayref, injecting malware that executed during compilation on developers' systems. Within a 23-minute window, the attackers also poisoned two additional crates (append-only-vec and internment) in this sophisticated supply-chain attack. The malicious code introduced a dependency on proc-macro1, a typosquat of the legitimate proc-macro2 crate, which deployed cross-platform infostealer malware targeting credentials from Chrome, Brave, and Edge browsers. With arrayref having over 245 million lifetime downloads and being used in critical blockchain and cryptography projects, the potential impact was substantial before the malicious packages were removed within 1.5 hours. This incident highlights the growing sophistication of supply-chain attacks targeting developer ecosystems, with security researchers noting infrastructure overlaps with recent North Korean state-sponsored campaigns. As organizations increasingly rely on open-source dependencies and automated build processes, these attacks represent a critical threat vector that can bypass traditional perimeter defenses.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Highlights Active Exploitation of Ray Vulnerability (CVE-2025-62593)
Impact· HIGH

CISA Highlights Active Exploitation of Ray Vulnerability (CVE-2025-62593)

In November 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-62593, was identified in Ray, an open-source AI compute engine. This flaw allowed attackers to execute arbitrary code on systems running Ray versions prior to 2.52.0 through browser-based attacks, specifically targeting Firefox and Safari via DNS rebinding techniques. The vulnerability stemmed from inadequate defenses against browser-originated requests, relying solely on the User-Agent header, which could be manipulated. Exploitation could occur when developers using Ray visited malicious websites or encountered malicious advertisements, potentially compromising development environments and sensitive data. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-62593?utm_source=openai)) The urgency of addressing this vulnerability has escalated due to its active exploitation in the wild. Notably, the RondoDox DDoS botnet incorporated this flaw into its arsenal shortly after its disclosure, and unpatched Ray instances have been targeted in campaigns like ShadowRay 2.0, aiming to convert infected clusters into cryptocurrency mining botnets.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
StubMaker Typosquatting Attack Targets RubyGems Users
Impact· HIGH

StubMaker Typosquatting Attack Targets RubyGems Users

In August 2026, a typosquatting campaign named StubMaker targeted RubyGems users by publishing 16 malicious packages with names resembling popular Ruby dependencies. These packages, once installed, executed a multi-stage attack that involved downloading a Rust-based loader from GitHub, which then launched a Go-based information stealer. This malware harvested sensitive data, including browser credentials, cryptocurrency wallets, seed phrases, and Telegram data, from infected Windows machines. The stolen information was subsequently uploaded to an external server controlled by the attackers. This incident underscores the persistent threat of supply chain attacks within open-source ecosystems. It highlights the critical need for developers and organizations to implement stringent security measures, such as verifying package authenticity and monitoring for anomalous behaviors, to safeguard against similar threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Flaw in Flow Neuroscience FL-100: CVE-2026-18164
Impact· HIGH

Critical Security Flaw in Flow Neuroscience FL-100: CVE-2026-18164

In August 2026, a critical vulnerability (CVE-2026-18164) was identified in Flow Neuroscience's FL-100 device, a transcranial direct current stimulation headset used for treating major depressive disorder. The flaw involved hard-coded credentials that allowed attackers within Bluetooth range to bypass authentication and manipulate brain stimulation parameters, potentially overriding safety limits. This vulnerability affected all FL-100 devices manufactured before July 2026. Flow Neuroscience promptly released firmware updates to address the issue, urging users to update their devices via the Flow app. This incident underscores the persistent risks associated with hard-coded credentials in medical devices, a known issue in industrial control systems. The exploitation of such vulnerabilities can lead to unauthorized control over critical device functions, posing significant safety hazards. The healthcare sector must prioritize robust security measures to prevent similar threats, especially as medical devices increasingly incorporate wireless technologies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844
Impact· HIGH

Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844

In August 2026, a critical vulnerability (CVE-2026-18844) was identified in the Pulsetto Vagus Nerve Stimulator, a device widely used for non-invasive wellness applications. The flaw allows unauthenticated commands to be sent over its Bluetooth Low Energy (BLE) interface, enabling attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not responded to mitigation requests, leaving users exposed to potential exploitation. This incident underscores the growing security risks associated with IoT medical devices, emphasizing the need for robust security measures and prompt vendor responses to vulnerabilities to protect patient safety and device integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Malicious 'Solidity Pro' VS Code Extensions Compromise Developer Security
Impact· HIGH

Malicious 'Solidity Pro' VS Code Extensions Compromise Developer Security

In August 2026, cybersecurity researchers identified malicious Visual Studio Code (VS Code) extensions named 'Solidity Pro' that targeted developers by stealing sensitive information. These extensions, including 'helper-beeps.solidity-pro' and 'web3devtoolsx.solidity-pro,' were distributed through the Open VSX registry and GitHub repositories. Early versions (1.0.0 to 2.4.x) retrieved encrypted Python payloads from Cloudflare Workers, while versions from 3.0.0 onwards evolved into full-fledged information stealers. The malware exfiltrated data such as browser profiles, cryptocurrency wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens via a Telegram bot upload. The attackers employed obfuscation techniques and delayed activation to evade detection, allowing the malicious code to execute hours or days after installation. This campaign shares similarities with the 'WhiteCobra' threat actor, known for distributing Lumma Stealer through malicious VS Code extensions in September 2025. The incident underscores the persistent threat posed by supply chain attacks targeting developer tools and the need for enhanced vigilance in extension marketplaces.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Thermo Fisher Genetic Analyzers: CVE-2026-17583
Impact· HIGH

Critical Vulnerability in Thermo Fisher Genetic Analyzers: CVE-2026-17583

In August 2026, Thermo Fisher Scientific disclosed a critical vulnerability (CVE-2026-17583) in their Applied Biosystems Genetic Analyzers. The flaw allowed unauthorized modification of .fsa and .hid output files, potentially leading to inaccurate DNA test results. Affected products included various versions of the 3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, GeneMapper ID-X, 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software. Thermo Fisher released security updates to address the issue, implementing digital signatures to verify data file integrity. This incident underscores the critical importance of data integrity in medical devices, especially those used in genetic analysis. The vulnerability highlights the need for robust security measures to prevent unauthorized data manipulation, which can have significant implications for patient care and research outcomes.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Unveiling TeamPCP's Extensive Supply Chain Attacks on Open-Source Software
Impact· CRITICAL

Unveiling TeamPCP's Extensive Supply Chain Attacks on Open-Source Software

TeamPCP, a sophisticated threat actor, has been actively compromising open-source software supply chains since at least 2020. Their operations involve injecting malicious code into widely-used software packages, leading to unauthorized access and control over numerous systems. In late 2025, they exploited the ShadowRay vulnerability (CVE-2023-48022) in the Ray AI framework, creating a self-propagating botnet that hijacked AI infrastructure globally. ([oligo.security](https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet?utm_source=openai)) The rapid evolution of TeamPCP's attack methods, facilitated by AI, underscores the growing threat to open-source ecosystems. Their ability to adapt and scale attacks highlights the urgent need for enhanced security measures in software development and deployment processes.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious npm Packages Target Alibaba Tools with Cross-Platform RAT
Impact· HIGH

Malicious npm Packages Target Alibaba Tools with Cross-Platform RAT

In August 2026, cybersecurity researchers identified a sophisticated supply chain attack targeting users of Alibaba developer tools. Malicious npm packages, including 'lib-mtop' and others, were published to impersonate legitimate private Alibaba packages. These packages contained loaders designed to fetch and execute remote JavaScript payloads, ultimately deploying a cross-platform remote access trojan (RAT). The RAT exhibited capabilities such as command execution, file manipulation, host reconnaissance, and lateral movement. The attack leveraged a multi-stage dependency chain to deliver the payload, with the final stage tailored to the victim's operating system: replacing core code in Windows applications, executing detached processes on Linux, and inserting malicious scripts on macOS. The malicious packages were published by a user named 'ch4ce,' whose account has since been deactivated. The campaign appears to be targeted at Chinese-speaking developers within the Alibaba ecosystem, suggesting a motive of industrial espionage. This incident underscores the growing threat of software supply chain attacks, where malicious actors infiltrate trusted development tools to distribute malware. The use of sophisticated techniques, such as impersonating private packages and employing multi-stage payload delivery, highlights the need for enhanced vigilance and security measures within the developer community.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Amgen's 2026 Cloud Data Breach: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

Amgen's 2026 Cloud Data Breach: A Wake-Up Call for Healthcare Cybersecurity

In July 2026, Amgen, a leading biotechnology company, detected unauthorized access to its cloud environments managed by third-party service providers. The breach resulted in the exfiltration of proprietary data and patient protected health information. Amgen promptly activated its cybersecurity response plan, implemented containment measures, and engaged independent forensic experts to investigate the incident. The company is assessing the full scope of the breach, including potential exposure of confidential business information, intellectual property, and additional patient data. This incident underscores the escalating risks associated with third-party cloud services in the healthcare sector. Organizations must enhance their security postures by implementing robust access controls, continuous monitoring, and comprehensive incident response strategies to mitigate potential threats.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports