✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Critical Passkey Vulnerabilities Uncovered: Bypassing Phishing-Resistant MFA
In August 2026, researchers identified multiple vulnerabilities in passkey authentication systems, revealing methods to bypass phishing-resistant multi-factor authentication (MFA) without compromising underlying cryptographic protocols. These attacks exploited weaknesses in Windows Event Logging Service (CVE-2026-34348), Google Password Manager's synced passkeys, and Windows Hello for Business, allowing unauthorized access through replayed authentication materials and malware manipulation. The incidents underscore the necessity for organizations to reassess the security of passkey implementations and enhance endpoint protections to mitigate such sophisticated threats. As passkeys gain popularity as a passwordless authentication method, these findings highlight the importance of continuous vigilance and adaptation to emerging attack vectors targeting authentication mechanisms.
35 minutes ago
Kill Chain
Critical Security Flaws Uncovered in AI Agent Skills: Snyk's 2026 Audit Findings
In early 2026, Snyk conducted a comprehensive security audit of the AI Agent Skills ecosystem, analyzing 3,984 skills from platforms like ClawHub and skills.sh. The audit revealed that 13.4% of these skills contained critical security vulnerabilities, including malware distribution, prompt injection attacks, and exposed secrets. Notably, 36.82% of the skills had at least one security flaw, posing significant risks to users of AI agents such as OpenClaw, Claude Code, and Cursor. ([snyk.io](https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/?utm_source=openai)) This incident underscores the escalating threat landscape associated with AI agents, particularly as they become more integrated into development workflows. The prevalence of prompt injection attacks highlights the urgent need for robust security measures and continuous monitoring to safeguard against the exploitation of AI systems.
1 hour ago
Kill Chain
Critical Metabase Zero-Day Vulnerability Exploited in August 2026
In August 2026, Metabase, a business intelligence and data visualization platform, disclosed a critical zero-day vulnerability that allowed unauthenticated remote attackers to inject arbitrary SQL into the application database. This flaw enabled attackers to gain administrator access, modify configurations, steal stored credentials, and access connected databases. The vulnerability affected versions 1.58 and above, with patches released to address the issue. Organizations using self-hosted versions were urged to apply these patches immediately to mitigate potential exploitation. This incident underscores the persistent threat posed by zero-day vulnerabilities in widely used software platforms. It highlights the importance of proactive security measures, timely patch management, and continuous monitoring to detect and respond to unauthorized access attempts promptly.
2 days ago
Kill Chain
Urgent: Patch Critical Vulnerability in Progress Kemp LoadMaster Now
In June 2026, a critical vulnerability (CVE-2026-8037) was identified in Progress Kemp LoadMaster appliances, allowing unauthenticated attackers to execute arbitrary commands remotely. This command injection flaw, present in the 'escape_quotes()' function, enables attackers to gain root access without valid credentials. ([hackerposts.org](https://www.hackerposts.org/en/blog/progress-kemp-loadmaster-cve-2026-8037-preauth-rce?utm_source=openai)) Exploitation attempts began on June 29, 2026, following the public release of a proof-of-concept exploit. ([esentire.com](https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037?utm_source=openai)) The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the necessary patches promptly to mitigate potential threats. ([aha.org](https://www.aha.org/h-isac-white-reports/2026-07-01-h-isac-tlp-white-threat-bulletin-observed-exploitation-attempts-targeting-critical-progress?utm_source=openai))
2 days ago
Kill Chain
CISA Highlights Critical Vulnerability in Progress LoadMaster: CVE-2026-8037
In August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation of this critical command injection vulnerability in Progress Software's LoadMaster appliance. This flaw allows unauthenticated attackers to execute arbitrary commands via unsanitized input in multiple API endpoints, potentially leading to full system compromise. Organizations utilizing affected versions are urged to apply patches immediately to mitigate the risk of unauthorized access and data breaches. The inclusion of CVE-2026-8037 in the KEV Catalog underscores the persistent threat posed by command injection vulnerabilities, which remain a favored attack vector for cyber adversaries. This incident serves as a critical reminder for organizations to prioritize timely remediation of known vulnerabilities and to implement robust input validation mechanisms to prevent similar exploits.
2 days ago
Kill Chain
Atlassian Rovo Vulnerability: A Wake-Up Call for AI Security
In August 2026, security researchers identified vulnerabilities in Atlassian's Rovo AI assistant that could be exploited to exfiltrate data from Jira and Confluence. PromptArmor discovered that embedding malicious instructions within content processed by Rovo allowed unauthorized data collection and transmission to external servers. Separately, Varonis Threat Labs found that manipulating the 'rovoChatPrompt' URL parameter enabled attackers to execute commands with a user's privileges, leading to data exfiltration. Atlassian addressed the URL parameter issue on July 8, 2026, but the content-based vulnerability remained unpatched as of August 5, 2026. This incident underscores the growing security challenges associated with integrating AI assistants into enterprise environments. It highlights the necessity for organizations to implement stringent access controls, continuously monitor AI interactions, and promptly address vulnerabilities to prevent unauthorized data access and exfiltration.
2 days ago
Kill Chain
The Rise of Identity-Based Cyber Attacks in 2026
In 2026, the cybersecurity landscape witnessed a significant shift towards identity-based attacks, with nearly 90% of incidents involving compromised identities. Attackers increasingly utilized techniques such as credential theft, multifactor authentication (MFA) manipulation, session hijacking, and social engineering to gain unauthorized access. Once inside, they established persistence, escalated privileges, and moved laterally across environments, often mimicking legitimate administrative behavior, making detection challenging. This trend underscores the critical need for organizations to enhance identity security measures and adopt a zero-trust approach to mitigate such threats. The rise in identity-driven attacks highlights the evolving tactics of threat actors who exploit human factors and identity weaknesses rather than traditional technical vulnerabilities. This shift necessitates a reevaluation of security strategies, emphasizing robust identity and access management, continuous monitoring, and user education to prevent unauthorized access and potential data breaches.
2 days ago
Kill Chain
New CSS Attacks Expose Webmail Vulnerabilities: Protect Your Accounts
In August 2026, PortSwigger researcher Gareth Heyes unveiled a series of CSS-based attacks capable of breaching webmail defenses across platforms like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These techniques exploit vulnerabilities in HTML and CSS handling within webmail interfaces, allowing attackers to capture passwords, hijack third-party accounts, leak tokens, and manipulate AI tools that process emails. The research, presented at Black Hat USA 2026, demonstrated proof-of-concept attacks without evidence of malicious exploitation. Some providers have since addressed specific vulnerabilities, but others remain unpatched. This incident underscores the evolving nature of web-based threats, highlighting the need for continuous vigilance and proactive security measures. As attackers develop more sophisticated methods to exploit webmail platforms, organizations must prioritize regular security assessments and updates to protect sensitive user information.
2 days ago
Kill Chain
Unlimited Technology Systems Data Breach: A Wake-Up Call for Healthcare Cybersecurity
In October 2025, Unlimited Technology Systems, a healthcare software provider, detected unauthorized access within its commercial data center. Between October 5 and October 10, 2025, an unauthorized actor accessed files containing sensitive personal and health information of approximately 3.8 million individuals. The compromised data included names, Social Security numbers, dates of birth, contact details, government IDs, insurance information, and medical records. The breach was discovered on October 19, 2025, and the company initiated an investigation with a cybersecurity forensic firm. Notifications to affected individuals began on July 1, 2026, with offers of identity monitoring services through Kroll. No ransomware or data-extortion groups have publicly claimed responsibility, and the perpetrators remain unidentified. This incident underscores the critical importance of robust cybersecurity measures for third-party vendors handling sensitive healthcare data. The breach highlights the potential risks associated with vendor vulnerabilities and the cascading impact on healthcare providers and patients. Organizations must prioritize comprehensive security protocols and timely breach disclosures to mitigate such risks.
2 days ago
Kill Chain
July 2026 CVE Landscape: A 44% Surge in High-Impact Vulnerabilities
In July 2026, Insikt Group identified 85 high-impact vulnerabilities, with 36 rated as Very Critical. This marks a 44% increase from the previous month. Notably, 26 vulnerabilities were listed in CISA's Known Exploited Vulnerabilities catalog, 55 were reported by vendors, and four were discovered through honeypot data. The affected products spanned 61 vendors, including Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla. Of these vulnerabilities, 57 enabled remote code execution, posing significant risks to enterprise software, security products, network infrastructure, developer tools, and cloud platforms. ([hackmageddon.com](https://www.hackmageddon.com/?utm_source=openai)) This surge underscores the persistent exploitation of both new and longstanding vulnerabilities, emphasizing the critical need for organizations to prioritize timely patching and robust vulnerability management practices to mitigate potential threats.
2 days ago
Kill Chain
AI-Generated Patches: A 2026 Study Reveals High Failure Rates
In August 2026, 1Password's Off-By-1 research team evaluated the effectiveness of AI-generated patches by testing 6,080 patches created for six vulnerabilities using OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. The study revealed that only 46% of these patches successfully addressed the vulnerabilities, with many introducing new issues or being easily bypassed. This highlights significant challenges in relying on AI for automated vulnerability remediation. The findings underscore the current limitations of AI in generating reliable security patches, emphasizing the need for human oversight and validation in the patching process. As AI continues to evolve, organizations must remain vigilant and not solely depend on automated solutions for critical security tasks.
2 days ago
Kill Chain
Snowflake 2024 Data Breach: A Wake-Up Call for Cloud Security
In mid-2024, the threat actor group UNC5537 executed a large-scale cyberattack targeting approximately 165 organizations utilizing Snowflake's cloud data platform. By exploiting stolen credentials obtained through infostealer malware, the attackers accessed customer environments lacking multi-factor authentication (MFA). High-profile victims included AT&T, Ticketmaster, and Santander Bank, with sensitive data such as personally identifiable information and call records compromised. The breach underscored the critical importance of enforcing MFA and maintaining robust credential hygiene to prevent unauthorized access. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Snowflake_data_breach?utm_source=openai)) This incident highlights a growing trend of cybercriminals leveraging stolen credentials to infiltrate cloud services, emphasizing the need for organizations to implement stringent access controls and continuous monitoring to safeguard sensitive data.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports