✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Schneider Electric's 2026 Hard-Coded Credentials Vulnerability: What You Need to Know
In March 2026, Schneider Electric disclosed a critical vulnerability in its EcoStruxure IT Data Center Expert software, identified as CVE-2025-13957. This flaw involves hard-coded credentials that, if exploited, could lead to information disclosure and remote code execution, particularly when the SOCKS Proxy feature is enabled. The affected versions include EcoStruxure IT Data Center Expert v9.0 and prior. Schneider Electric has released version 9.1 to address this issue and recommends users update promptly to mitigate potential risks. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-schneider-electric-security-advisory-av26-210?utm_source=openai)) This incident underscores the persistent threat posed by hard-coded credentials in critical infrastructure software. Organizations are urged to review their systems for similar vulnerabilities and implement robust credential management practices to prevent unauthorized access and potential operational disruptions.
4 months ago
Kill Chain
Interlock Ransomware's 2026 Exploitation of Cisco Firewall Vulnerability
In early 2026, the Interlock ransomware group exploited a zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote code execution as root. This critical flaw, due to insecure deserialization of user-supplied Java byte streams, enabled attackers to gain full control over affected devices. The exploitation began on January 26, 2026, 36 days prior to Cisco's public disclosure on March 4, 2026. Interlock's campaign involved deploying custom remote access trojans, reconnaissance scripts, and evasion techniques, leading to significant operational disruptions for targeted organizations. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching, implement defense-in-depth strategies, and maintain continuous threat monitoring to mitigate such risks.
4 months ago
Kill Chain
Claude Code's 2026 Security Flaw: A Wake-Up Call for Agentic AI
In February 2026, a critical vulnerability (CVE-2026-24052) was identified in Claude Code, an agentic coding tool developed by Anthropic. The flaw involved insufficient URL validation in the trusted domain verification mechanism for WebFetch requests. Specifically, the application used the `startsWith()` function to validate trusted domains, allowing attackers to register subdomains that could bypass this validation. This vulnerability enabled automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. Anthropic addressed this issue by releasing a patch in version 1.0.111. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-24052?utm_source=openai)) This incident underscores the growing security challenges associated with agentic AI systems, which operate autonomously and can interact with external resources. The exploitation of such vulnerabilities highlights the need for robust validation mechanisms and comprehensive security assessments in AI-driven tools to prevent unauthorized data access and exfiltration.
4 months ago
Kill Chain
LeakNet Ransomware's Innovative Use of ClickFix and Deno Runtime in 2026 Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated attack campaign leveraging the ClickFix social engineering technique and the Deno JavaScript runtime. By presenting fake prompts, they tricked users into executing malicious commands, leading to the deployment of a Deno-based loader that executed JavaScript payloads directly in system memory. This method minimized forensic evidence and enhanced evasion of traditional security measures. The adoption of legitimate tools like Deno for malicious purposes underscores a growing trend among threat actors to evade detection. Organizations must remain vigilant against such evolving tactics, emphasizing the need for comprehensive security awareness training and advanced threat detection mechanisms.
4 months ago
Kill Chain
Critical Wing FTP Server Vulnerability Exploited: Immediate Action Required
In July 2025, a critical vulnerability (CVE-2025-47812) was discovered in Wing FTP Server, allowing unauthenticated attackers to execute arbitrary Lua code via null byte injection in the username parameter. This flaw enables remote code execution with elevated privileges, potentially leading to full system compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 14, 2025, with a remediation deadline of August 4, 2025. Organizations are urged to update to Wing FTP Server version 7.4.4 or later to mitigate this risk. ([gbhackers.com](https://gbhackers.com/cisa-issues-alert-on-wing-ftp-server-vulnerability/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by unpatched software vulnerabilities. It highlights the importance of timely patch management and continuous monitoring to prevent potential system compromises and data breaches.
4 months ago
Kill Chain
Amazon Bedrock AgentCore 2026 DNS Exfiltration Vulnerability
In March 2026, cybersecurity researchers identified a vulnerability in Amazon Bedrock AgentCore's Code Interpreter, allowing attackers to exfiltrate sensitive data via DNS queries. The flaw permitted outbound DNS requests from the sandbox environment, enabling unauthorized data transmission. This vulnerability underscores the critical need for robust security measures in AI code execution platforms to prevent data breaches. Organizations utilizing AI agents must implement stringent controls to mitigate such risks.
4 months ago
Kill Chain
LeakNet Ransomware's 2026 Campaign: Exploiting ClickFix and Deno Runtime for Stealthy Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated campaign leveraging the ClickFix social engineering technique to gain initial access to target systems. By compromising legitimate websites, they presented users with deceptive prompts instructing them to execute malicious PowerShell commands under the guise of resolving non-existent errors. This method effectively bypassed traditional security measures, leading to the deployment of an in-memory loader utilizing the Deno JavaScript runtime. This loader facilitated the execution of the CastleRAT malware directly in memory, thereby evading detection by conventional endpoint security solutions. The campaign resulted in significant data breaches and operational disruptions across multiple sectors. This incident underscores a concerning evolution in ransomware tactics, highlighting the increasing sophistication of social engineering methods and the exploitation of novel technologies like the Deno runtime for stealthy malware deployment. The use of in-memory execution techniques poses a substantial challenge to traditional security defenses, emphasizing the need for advanced detection mechanisms and comprehensive user education to mitigate such threats.
4 months ago
Kill Chain
Wing FTP Server 2025 Information Disclosure Vulnerability: What You Need to Know
In July 2025, a medium-severity information disclosure vulnerability, identified as CVE-2025-47813, was discovered in Wing FTP Server versions 7.4.3 and earlier. This flaw allowed unauthenticated attackers to obtain sensitive information about the server's local file system by exploiting the 'loginok.html' page with a specially crafted UID cookie. The vulnerability was addressed in version 7.4.4, released on May 14, 2025. Despite the availability of a patch, many systems remained unpatched, leaving them susceptible to potential exploitation. The incident underscores the critical importance of timely software updates and robust vulnerability management practices. Organizations are urged to prioritize the remediation of known vulnerabilities to mitigate the risk of unauthorized access and data breaches.
4 months ago
Kill Chain
Introducing Augustus: Praetorian's Open-Source LLM Vulnerability Scanner
In February 2026, Praetorian released Augustus, an open-source vulnerability scanner designed to test Large Language Models (LLMs) against a comprehensive suite of adversarial attacks. Augustus automates over 210 distinct attack vectors, including prompt injections and jailbreaks, across 28 LLM providers. This tool addresses the growing need for robust security testing as enterprises rapidly integrate generative AI into their products. By providing a portable, single-binary solution, Augustus facilitates seamless integration into continuous integration/continuous deployment (CI/CD) pipelines, enabling security teams to identify and mitigate vulnerabilities efficiently. The release of Augustus underscores the escalating threats targeting LLMs, as adversaries increasingly exploit these models for malicious purposes. The tool's comprehensive testing capabilities highlight the necessity for organizations to proactively assess and fortify their AI systems against evolving attack methodologies.
4 months ago
Kill Chain
ClickFix Campaigns Exploit AI Tool Installers to Deploy MacSync Infostealer
In late 2025 and early 2026, multiple ClickFix campaigns emerged, targeting macOS users with the MacSync infostealer. These campaigns utilized malicious Google Ads and AI-generated content to lure users into executing terminal commands that installed the malware. The MacSync infostealer is capable of exfiltrating credentials, browser data, and cryptocurrency wallet information. ([cybernews.com](https://cybernews.com/security/hackers-spread-mac-infostealer-using-google-ads/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit user trust in AI tools and search engine results. The increasing prevalence of such tactics highlights the need for heightened vigilance and user education to prevent similar breaches. ([techmonk.economictimes.indiatimes.com](https://techmonk.economictimes.indiatimes.com/news/security-alert/security-alert-clickfix-campaign-abuses-claude-artifacts-and-google-ads-to-drop-macos-infostealer/128334810?utm_source=openai))
4 months ago
Kill Chain
GlassWorm Attack 2026: A Wake-Up Call for Open-Source Security
In early 2026, the GlassWorm malware campaign exploited stolen GitHub tokens to inject malicious code into numerous Python repositories. Attackers targeted projects such as Django applications, machine learning research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to files like setup.py, main.py, and app.py. This code, often concealed using invisible Unicode characters, enabled the exfiltration of sensitive data, including SSH keys, cloud credentials, and cryptocurrency wallet information. The malware's command-and-control infrastructure leveraged the Solana blockchain, complicating detection and mitigation efforts. The resurgence of GlassWorm highlights the persistent vulnerabilities within software supply chains, emphasizing the need for robust security measures in open-source ecosystems. The attack underscores the importance of vigilant monitoring and the implementation of stringent access controls to prevent unauthorized code modifications and protect sensitive information.
4 months ago
Kill Chain
Critical Chrome Zero-Day Vulnerability CVE-2026-2441 Patched
In February 2026, Google identified and patched a high-severity zero-day vulnerability in its Chrome browser, designated as CVE-2026-2441. This use-after-free flaw in the CSS component allowed attackers to execute arbitrary code by enticing users to visit maliciously crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to mitigate the risk. Users were urged to update their browsers immediately to versions 145.0.7632.75/76 for Windows and macOS, and 144.0.7559.75 for Linux. ([securityweek.com](https://www.securityweek.com/google-patches-first-actively-exploited-chrome-zero-day-of-2026/?utm_source=openai)) The exploitation of CVE-2026-2441 underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely software updates. This incident highlights the need for organizations and individuals to maintain vigilant cybersecurity practices, including regular patching and monitoring for emerging threats.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports