✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
LeakyLooker Vulnerabilities: A Wake-Up Call for Cloud Security
In March 2026, Tenable Research disclosed nine critical cross-tenant vulnerabilities, collectively termed 'LeakyLooker,' in Google Looker Studio. These flaws allowed attackers to execute arbitrary SQL queries on victims' databases, leading to potential data exfiltration, insertion, and deletion across Google Cloud Platform (GCP) services. The vulnerabilities affected organizations utilizing connectors such as Google Sheets, BigQuery, Spanner, PostgreSQL, MySQL, and Cloud Storage. Google addressed these issues following responsible disclosure in June 2025. The 'LeakyLooker' vulnerabilities underscore the evolving threat landscape in cloud environments, highlighting the necessity for robust security measures and continuous monitoring. Organizations must remain vigilant against cross-tenant vulnerabilities to safeguard sensitive data and maintain compliance with industry standards.
4 months ago
Kill Chain
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
In early 2026, threat actors exploited vulnerabilities and weak credentials in FortiGate Next-Generation Firewall (NGFW) appliances to breach networks across healthcare, government, and managed service providers. By accessing these devices, attackers extracted configuration files containing service account credentials and network topology information, enabling unauthorized access to Active Directory environments and the enrollment of rogue workstations. The breaches were detected during lateral movement phases, preventing further escalation. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure devices, as their compromise can lead to significant data breaches and operational disruptions. The exploitation of such devices highlights the evolving tactics of threat actors targeting essential security appliances to gain deeper access into organizational networks. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai))
4 months ago
Kill Chain
Odido's 2026 Data Breach: A Case Study in Social Engineering Attacks
In February 2026, Dutch telecom provider Odido experienced a significant data breach affecting over 6 million customer accounts. Attackers employed social engineering tactics, including phishing emails and impersonation of IT staff, to gain unauthorized access to Odido's customer relationship management system. This breach exposed sensitive personal information such as names, addresses, telephone numbers, bank account details, dates of birth, and government-issued ID numbers. The incident underscores the critical need for robust employee training and advanced security measures to prevent similar attacks. ([cybernews.com](https://cybernews.com/security/odido-hackers-phishing-attack/?utm_source=openai)) This breach highlights a growing trend of cybercriminals leveraging sophisticated social engineering techniques to infiltrate organizations. As these methods become more prevalent, companies must enhance their security protocols and employee awareness programs to mitigate the risk of such attacks.
4 months ago
Kill Chain
Beware of 'InstallFix' Attacks: Fake Claude Code Sites Spreading Malware
In March 2026, a cyberattack campaign known as 'InstallFix' targeted developers by creating fake installation pages for Anthropic's Claude Code, an AI coding assistant. These counterfeit sites, promoted through Google-sponsored ads, closely mimicked legitimate pages and instructed users to execute malicious commands in their terminals. This led to the deployment of Amatera Stealer malware, which harvested sensitive information such as browser credentials and cryptocurrency wallets, potentially compromising enterprise development environments. This incident underscores the growing trend of attackers exploiting the widespread practice of copying and pasting commands from online sources. It highlights the urgent need for heightened vigilance and verification of software installation sources to prevent similar social engineering attacks.
4 months ago
Kill Chain
CISA Adds Three Known Exploited Vulnerabilities to Catalog
On March 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-22054, a Server-Side Request Forgery (SSRF) in VMware Workspace ONE UEM; CVE-2025-26399, an unauthenticated deserialization flaw in SolarWinds Web Help Desk's AjaxProxy component; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager (EPM). Each of these flaws presents significant risks, such as unauthorized access, remote code execution, and credential disclosure, potentially leading to full enterprise compromise. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate the risks associated with these actively exploited vulnerabilities.
4 months ago
Kill Chain
Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4
In February 2026, a critical SQL injection vulnerability (CVE-2026-21643) was discovered in Fortinet's FortiClient Endpoint Management Server (EMS) version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet promptly released version 7.4.5 to address this issue, urging all users to upgrade immediately. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21643?utm_source=openai)) This incident underscores the persistent threat posed by SQL injection vulnerabilities, especially in widely used enterprise security solutions. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate such risks.
4 months ago
Kill Chain
AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems
In March 2026, Palo Alto Networks' Unit 42 researchers unveiled a critical vulnerability in AI 'judge' systems, which are large language models (LLMs) employed to enforce security policies and evaluate outputs. Utilizing a tool named AdvJudge-Zero, the researchers demonstrated that these AI judges could be manipulated through stealthy input sequences, a form of prompt injection, to bypass security controls. The attack exploits the models' decision-making processes, allowing unauthorized actions without detection. This vulnerability underscores the need for robust defenses against adversarial manipulations in AI systems. The discovery highlights the growing sophistication of prompt injection attacks, emphasizing the urgency for organizations to reassess and fortify their AI security measures. As AI integration deepens across industries, understanding and mitigating such vulnerabilities becomes paramount to maintaining trust and operational integrity.
4 months ago
Kill Chain
ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security
In March 2026, the cybercriminal group ShinyHunters initiated a series of data theft attacks targeting misconfigured Salesforce Experience Cloud instances. By exploiting excessive permissions granted to guest user profiles, the attackers accessed sensitive data without authentication. Utilizing a modified version of the AuraInspector tool, they identified and exploited these vulnerabilities, compromising approximately 300 to 400 organizations, many within the cybersecurity sector. The breaches led to unauthorized access to vast amounts of customer and corporate data, raising significant concerns about data security and privacy. This incident underscores the critical importance of proper configuration and access control in cloud platforms. Organizations are urged to audit guest user permissions, adhere to the principle of least privilege, and monitor for unusual access patterns to mitigate such risks. The event highlights the evolving tactics of threat actors and the necessity for continuous vigilance in cybersecurity practices.
4 months ago
Kill Chain
Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study
In February 2026, two Google Chrome extensions, QuickLens and ShotBird, were compromised following ownership transfers. The new owners introduced malicious updates that stripped security headers from HTTP responses, enabling code injection and data theft. These updates allowed attackers to execute arbitrary JavaScript, leading to the exfiltration of sensitive user data, including credentials and browsing history. The incident underscores the risks associated with browser extension supply chains and the potential for legitimate tools to become vectors for malware distribution. This event highlights the growing trend of attackers exploiting trusted browser extensions to infiltrate systems, emphasizing the need for vigilant monitoring of software supply chains and the implementation of robust security measures to detect and prevent such compromises.
4 months ago
Kill Chain
AirSnitch: Unveiling the 2026 Wi-Fi Vulnerability
In February 2026, researchers from the University of California, Riverside, and KU Leuven's DistriNet lab unveiled 'AirSnitch,' a novel attack that exploits fundamental flaws in Wi-Fi client isolation mechanisms. By leveraging cross-layer identity desynchronization, AirSnitch enables attackers to perform full bidirectional man-in-the-middle (MitM) attacks, allowing them to intercept and modify data between clients on the same network. This vulnerability affects a wide range of devices, including consumer routers from Netgear, Tenda, D-Link, TP-Link, and Asus, as well as enterprise hardware from Ubiquiti and Cisco. The attack is particularly concerning as it bypasses existing Wi-Fi encryption protocols without the need to crack them, posing significant risks to both home and enterprise networks. ([arstechnica.com](https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/?utm_source=openai)) The discovery of AirSnitch underscores the urgent need for standardized and robust client isolation implementations in Wi-Fi networks. As the attack exploits architectural weaknesses rather than specific software flaws, addressing this vulnerability requires coordinated efforts from hardware manufacturers, software developers, and standards organizations to enhance the security of wireless communications. ([cyberkendra.com](https://www.cyberkendra.com/2026/02/new-airsnitch-attack-bypasses-wpa2-and.html?utm_source=openai))
4 months ago
Kill Chain
Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion
Between February 3 and 16, 2026, the threat group Velvet Tempest (also known as DEV-0504) conducted a sophisticated cyber intrusion targeting a U.S. non-profit organization with over 3,000 endpoints and 2,500 users. Utilizing a malvertising campaign, they employed the 'ClickFix' technique, deceiving victims into executing obfuscated commands via the Windows Run dialog. This led to the deployment of DonutLoader and the CastleRAT backdoor, facilitating credential harvesting and extensive reconnaissance. Notably, while Velvet Tempest is known for deploying various ransomware strains, including Ryuk, REvil, and Conti, the Termite ransomware was not executed in this particular incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/termite-ransomware-breaches-linked-to-clickfix-castlerat-attacks/?utm_source=openai)) This incident underscores the evolving tactics of ransomware affiliates, highlighting the use of social engineering techniques like 'ClickFix' to gain initial access. The absence of immediate ransomware deployment suggests a strategic shift towards prolonged network infiltration and data exfiltration, posing significant challenges for detection and mitigation.
4 months ago
Kill Chain
Microsoft Reports Surge in AI-Powered Cyberattacks in 2026
In March 2026, Microsoft reported a significant increase in cyberattacks leveraging artificial intelligence (AI) across all stages of the attack lifecycle. Threat actors utilized generative AI tools for tasks such as reconnaissance, phishing, infrastructure development, malware creation, and post-compromise activities. Notably, North Korean groups like Jasper Sleet (Storm-0287) and Coral Sleet (Storm-1877) employed AI to craft realistic digital personas, enabling them to infiltrate Western organizations under the guise of remote IT workers. This strategic use of AI allowed attackers to accelerate operations, scale malicious activities, and lower technical barriers, resulting in more sophisticated and efficient cyberattacks. The current relevance of this incident lies in the escalating trend of AI-powered cyber threats. As AI technologies become more accessible, both state-sponsored and financially motivated actors are increasingly integrating AI into their operations. This evolution necessitates that organizations enhance their cybersecurity measures to detect and mitigate AI-driven attacks effectively.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports