The Containment Era is here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2585 threat reports
Page 106 of 216

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 12611272 / 2585 reports
Unveiling Critical Reverse Proxy Header Vulnerabilities in 2025
Impact· CRITICAL

Unveiling Critical Reverse Proxy Header Vulnerabilities in 2025

In 2025, critical vulnerabilities were identified in reverse proxy applications, notably Fabio and OAuth2-Proxy, exposing significant security risks. CVE-2025-48865 in Fabio allowed attackers to manipulate or remove security-critical headers like X-Forwarded-Host and X-Real-IP by exploiting the HTTP Connection header, potentially leading to access control bypasses. Similarly, CVE-2025-64484 in OAuth2-Proxy enabled authenticated users to inject underscore variants of X-Forwarded-* headers, bypassing the proxy's filtering logic and potentially escalating privileges in upstream applications. These vulnerabilities underscore the importance of stringent header validation and normalization practices in reverse proxy configurations. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48865?utm_source=openai)) The discovery of these vulnerabilities highlights a systemic issue in how reverse proxies handle HTTP headers, emphasizing the need for organizations to reassess and fortify their security measures to prevent similar exploits.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SolarWinds Web Help Desk 2025 AjaxProxy RCE Vulnerability
Impact· CRITICAL

SolarWinds Web Help Desk 2025 AjaxProxy RCE Vulnerability

In September 2025, a critical vulnerability (CVE-2025-26399) was identified in SolarWinds Web Help Desk, allowing unauthenticated remote attackers to execute arbitrary code on affected systems. This flaw, rooted in insecure deserialization within the AjaxProxy component, enables attackers to run commands on the host machine without authentication. Despite previous patches for related vulnerabilities (CVE-2024-28986 and CVE-2024-28988), this issue persisted, leading to active exploitation in the wild. Organizations using versions up to 12.8.7 are at significant risk and should apply the latest hotfix immediately. The recurrence of such vulnerabilities underscores the importance of comprehensive security reviews and prompt patch management. As attackers increasingly exploit deserialization flaws, organizations must prioritize securing their software supply chains and implementing robust monitoring to detect and respond to such threats promptly.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Authentication Bypass Vulnerability Discovered in pac4j-jwt Java Library
Impact· CRITICAL

Critical Authentication Bypass Vulnerability Discovered in pac4j-jwt Java Library

In March 2026, a critical authentication bypass vulnerability (CVE-2026-29000) was discovered in the pac4j-jwt Java library, affecting versions prior to 4.5.9, 5.7.9, and 6.3.3. This flaw allows remote attackers to forge authentication tokens by exploiting improper verification of cryptographic signatures in the JwtAuthenticator component when processing encrypted JSON Web Tokens (JWTs). By crafting a JWE-wrapped PlainJWT with arbitrary subject and role claims, attackers can bypass signature verification and authenticate as any user, including administrators. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai)) The vulnerability poses a significant risk due to the widespread use of pac4j-jwt in various Java applications and frameworks. Organizations utilizing affected versions are urged to upgrade to the latest fixed releases immediately to mitigate potential exploitation. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days
Impact· HIGH

Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days

In March 2026, Microsoft released its Patch Tuesday updates, addressing 83 vulnerabilities across its software portfolio, including Windows, Office, SQL Server, Azure, and .NET. Notably, this release included two publicly disclosed zero-day vulnerabilities: CVE-2026-21262, an elevation of privilege flaw in Microsoft SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Additionally, six vulnerabilities were identified as more likely to be exploited, emphasizing the importance of timely patch application. This update marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a positive trend in Microsoft's vulnerability management efforts. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-march-2026/?utm_source=openai)) The absence of actively exploited zero-day vulnerabilities in this release suggests improved security measures and proactive patching strategies. However, the presence of publicly disclosed vulnerabilities underscores the need for organizations to remain vigilant and prioritize the deployment of these updates to mitigate potential risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required
Impact· HIGH

Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required

In February 2026, a critical authentication bypass vulnerability (CVE-2026-1603) was identified in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU5. This flaw allows remote, unauthenticated attackers to access stored credential data by exploiting improper authentication mechanisms, specifically through malformed header concatenation in the WSAuth.dll component. Successful exploitation enables attackers to retrieve encrypted credential blobs for high-privilege accounts, potentially compromising the entire endpoint management trust model and facilitating lateral movement within networks. ([dbugs.ptsecurity.com](https://dbugs.ptsecurity.com/vulnerability/CVE-2026-1603?utm_source=openai)) The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1603 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. Organizations are urged to upgrade to Ivanti EPM 2024 SU5 immediately to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Understanding LummaC2: The 2025 Advanced Evasion Malware
Impact· MEDIUM

Understanding LummaC2: The 2025 Advanced Evasion Malware

In 2025, LummaC2 emerged as a highly sophisticated information-stealing malware targeting Windows systems. Distributed through phishing emails, malicious advertisements, and compromised software, LummaC2 exfiltrated sensitive data, including browser credentials and cryptocurrency wallets. Notably, its v4.0 introduced advanced evasion techniques, such as trigonometry-based anti-sandbox mechanisms that detect human-like mouse movements to avoid detection. This evolution underscores a significant shift towards stealthy, persistent cyber threats that can bypass traditional security measures. The rise of LummaC2 highlights the increasing sophistication of malware-as-a-service platforms, enabling even low-skilled threat actors to deploy advanced attacks. Organizations must enhance their security postures by adopting proactive threat detection and response strategies to mitigate such evolving threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
KadNap Botnet: A New Threat Targeting ASUS Routers in 2026
Impact· HIGH

KadNap Botnet: A New Threat Targeting ASUS Routers in 2026

In August 2025, cybersecurity researchers identified a new malware strain named KadNap, which primarily targets ASUS routers and other edge networking devices. The malware infiltrates these devices, transforming them into nodes within a botnet that proxies malicious traffic. KadNap employs a customized version of the Kademlia Distributed Hash Table (DHT) protocol, enabling decentralized communication and complicating efforts to detect and disrupt its command-and-control (C2) infrastructure. By March 2026, the botnet had expanded to over 14,000 infected devices, with approximately 60% located in the United States. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/?utm_source=openai)) The emergence of KadNap underscores a growing trend of sophisticated malware leveraging decentralized protocols to enhance resilience against traditional network monitoring and takedown efforts. This incident highlights the critical need for robust security measures in consumer-grade networking equipment, as such devices are increasingly exploited to facilitate large-scale cybercriminal operations.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities
Impact· HIGH

Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities

In March 2026, Microsoft released its Patch Tuesday updates, addressing 79 vulnerabilities across various products, including Windows, Office, Azure, SQL Server, and .NET. Notably, two zero-day vulnerabilities were publicly disclosed prior to the release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. While these vulnerabilities were publicly known, there was no evidence of active exploitation at the time of the update. Organizations are advised to prioritize patching these vulnerabilities to mitigate potential risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/?utm_source=openai)) The disclosure of these zero-day vulnerabilities underscores the critical importance of timely patch management. Even in the absence of active exploitation, publicly known vulnerabilities can quickly become targets for cybercriminals. This incident highlights the need for organizations to maintain robust vulnerability management practices to protect their systems and data.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog
Impact· CRITICAL

CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2021-22054, a server-side request forgery in Omnissa Workspace One UEM; CVE-2025-26399, a deserialization flaw in SolarWinds Web Help Desk; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager. Exploitation of these vulnerabilities allows unauthorized access to sensitive information and remote code execution on affected systems. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by unpatched software flaws. Organizations are urged to apply the necessary patches promptly to mitigate potential risks associated with these actively exploited vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Unveiling 'Zombie ZIP': A New Frontier in Malware Evasion
Impact· MEDIUM

Unveiling 'Zombie ZIP': A New Frontier in Malware Evasion

In March 2026, security researcher Chris Aziz unveiled a novel malware evasion technique termed 'Zombie ZIP.' This method involves manipulating ZIP file headers to mislead antivirus and endpoint detection systems into treating compressed malicious payloads as uncompressed data. Consequently, security tools scan the files without detecting the embedded threats. The technique proved effective against 50 out of 51 antivirus engines tested on VirusTotal. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/?utm_source=openai)) The emergence of 'Zombie ZIP' underscores the evolving sophistication of malware delivery methods, highlighting the need for enhanced detection mechanisms capable of identifying such deceptive techniques. Organizations must stay vigilant and update their security protocols to counteract these advanced evasion strategies.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Exploit Salesforce Experience Cloud Misconfigurations in 2026 Data Breach
Impact· MEDIUM

ShinyHunters Exploit Salesforce Experience Cloud Misconfigurations in 2026 Data Breach

In March 2026, Salesforce disclosed that the ShinyHunters cybercriminal group exploited misconfigured Experience Cloud sites to access sensitive data from approximately 100 high-profile companies. The attackers utilized a modified version of the open-source tool AuraInspector to identify and exploit overly permissive guest user configurations, enabling unauthorized data extraction. Salesforce emphasized that the breach resulted from customer misconfigurations rather than inherent platform vulnerabilities. This incident underscores the critical importance of adhering to security best practices when configuring cloud services. Misconfigurations can lead to significant data breaches, as demonstrated by the ShinyHunters' exploitation of Salesforce Experience Cloud sites. Organizations must regularly review and secure their cloud configurations to prevent unauthorized access and data exposure.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft SharePoint 2025 ToolShell Zero-Day Exploitation
Impact· CRITICAL

Microsoft SharePoint 2025 ToolShell Zero-Day Exploitation

In July 2025, a critical zero-day vulnerability, CVE-2025-53770, was discovered in Microsoft SharePoint, allowing unauthenticated remote code execution. Dubbed 'ToolShell,' this exploit enabled attackers to gain full control over affected servers, leading to data exfiltration and deployment of ransomware. The vulnerability stemmed from an incomplete fix of a 2020 issue, CVE-2020-1147, and was actively exploited by Chinese state-affiliated groups, including Storm-2603, Linen Typhoon, and Violet Typhoon. Over 400 organizations worldwide, including U.S. federal agencies and the National Nuclear Security Administration, were compromised. Microsoft released emergency patches for SharePoint Server 2019 and SharePoint Subscription Edition, but SharePoint Enterprise Server 2016 remained unpatched at the time. Organizations were urged to apply patches, rotate machine keys, and implement additional security measures to mitigate the threat. ([windowscentral.com](https://www.windowscentral.com/software-apps/were-witnessing-an-urgent-and-active-threat-microsoft-sharepoint-toolshell-vulnerability-is-being-attacked-globally?utm_source=openai)) This incident underscores the escalating risk of zero-day vulnerabilities and the rapid exploitation timelines by sophisticated threat actors. The 'ToolShell' attacks highlight the critical need for organizations to maintain vigilant patch management, continuous monitoring, and robust incident response strategies to defend against evolving cyber threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports