✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
GCP Cloud SQL Vulnerability 2023: A Wake-Up Call for Cloud Security
In April 2023, a critical security vulnerability was discovered in Google Cloud Platform's (GCP) Cloud SQL service, potentially allowing unauthorized access to sensitive data. The flaw enabled attackers to escalate privileges from a basic user to a sysadmin role, granting access to internal GCP data, customer information, secrets, sensitive files, and passwords. By exploiting this misconfiguration, attackers could gain full control over the database server, posing significant risks to data integrity and confidentiality. Google addressed the issue promptly upon disclosure, mitigating the potential impact on affected systems. This incident underscores the persistent challenges associated with cloud service misconfigurations and the importance of continuous monitoring and timely remediation. As cloud adoption accelerates, organizations must prioritize robust security practices to prevent similar vulnerabilities from being exploited in the future.
5 months ago
Kill Chain
Jaguar Land Rover 2025 Cyberattack: Lessons in Industrial Cybersecurity
In August 2025, Jaguar Land Rover (JLR) experienced a significant cyberattack that led to a complete halt in vehicle production across its global facilities, including those in the UK, Slovakia, China, India, and Brazil. The attack, attributed to the hacking group 'Scattered Lapsus$ Hunters,' resulted in the shutdown of production lines starting August 31, 2025, with operations remaining suspended until at least October 1, 2025. This disruption caused substantial financial losses, with JLR reporting a pre-tax loss of £485 million for the quarter ending September 30, 2025, marking a stark contrast to the £398 million profit recorded in the same period the previous year. The incident also had a ripple effect on the UK automotive industry, impacting JLR's extensive supply chain and leading to significant economic repercussions. ([theguardian.com](https://www.theguardian.com/business/2025/nov/14/jaguar-land-rover-loss-cyber-attack?utm_source=openai)) The JLR cyberattack underscores the escalating threat of sophisticated cyber incidents targeting critical infrastructure and major corporations. The involvement of 'Scattered Lapsus$ Hunters,' a group comprising elements from notorious hacking collectives like Scattered Spider, Lapsus$, and ShinyHunters, highlights the evolving tactics of cybercriminals who exploit social engineering and known vulnerabilities to infiltrate organizations. This incident serves as a stark reminder for industries worldwide to bolster their cybersecurity measures, enhance incident response strategies, and ensure robust supply chain security to mitigate the risks posed by such advanced persistent threats. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/jaguar-land-rover-shuts-down-production-due-to-ransomware-attack-scattered-lapsus-usd-hunters-takes-responsibility?utm_source=openai))
5 months ago
Kill Chain
Google API Keys Expose Gemini AI Data in 2026
In February 2026, security researchers discovered that previously non-sensitive Google API keys embedded in client-side code could be exploited to access Google's Gemini AI services, leading to potential unauthorized data access and financial implications. This vulnerability arose when developers enabled the Gemini API in existing projects, inadvertently granting these exposed keys access to sensitive endpoints without any alerts or notifications. The issue affected numerous organizations, including major financial institutions and even Google's own infrastructure, with over 2,800 live API keys found publicly exposed. In response, Google implemented measures to detect and block leaked API keys attempting to access the Gemini API and advised developers to audit and rotate any exposed keys immediately. This incident underscores the critical importance of secure API key management and the need for developers to regularly review and update their security practices to prevent unauthorized access and potential data breaches.
5 months ago
Kill Chain
Trend Micro Apex One 2026 Critical RCE Vulnerabilities
In February 2026, Trend Micro identified and patched two critical vulnerabilities (CVE-2025-71210 and CVE-2025-71211) in its Apex One endpoint security platform. These flaws, both with a CVSS score of 9.8, allowed unauthenticated remote attackers to execute arbitrary code via path traversal weaknesses in the management console. Exploitation required access to the console, posing significant risks to organizations with externally exposed management interfaces. Trend Micro released Critical Patch Build 14136 to address these issues and advised customers to update promptly. This incident underscores the persistent threat posed by vulnerabilities in security management consoles, emphasizing the need for organizations to implement stringent access controls and maintain up-to-date systems to mitigate potential exploitation.
5 months ago
Kill Chain
Harvest Now, Decrypt Later: The Quantum Computing Threat
The 'Harvest Now, Decrypt Later' (HNDL) strategy involves adversaries collecting encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current cryptographic algorithms. This approach poses a significant threat to sensitive information with long-term confidentiality requirements, such as financial records, healthcare data, and intellectual property. Organizations must proactively transition to post-quantum cryptographic (PQC) algorithms to safeguard their data against future quantum-enabled decryption attacks. ([prnewswire.com](https://www.prnewswire.com/news-releases/harvest-now-decrypt-later-attacks-pose-a-security-concern-as-organizations-consider-implications-of-quantum-computing-301628445.html?utm_source=openai)) The urgency to address HNDL threats is underscored by the rapid advancements in quantum computing. Experts predict that cryptographically relevant quantum computers could emerge within the next decade, rendering existing encryption methods obsolete. ([docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/the-quantum-computing-threat?utm_source=openai))
5 months ago
Kill Chain
UAT-10027's Dohdoor Backdoor: A New Threat to U.S. Education and Healthcare
In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai)) This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai))
5 months ago
Kill Chain
Anthropic's Claude Code Vulnerabilities Expose Developers to Security Risks
In late 2025, security researchers identified critical vulnerabilities in Anthropic's AI-powered development tool, Claude Code. These flaws, specifically CVE-2025-59536 and CVE-2026-21852, allowed attackers to execute arbitrary code and steal API keys by exploiting project configuration files. By manipulating these files, malicious actors could trigger unauthorized actions when developers opened compromised repositories, potentially compromising developer machines and enterprise resources. Anthropic promptly addressed these issues by releasing patches to mitigate the risks. This incident underscores the evolving threat landscape as AI tools become integral to software development workflows. The exploitation of AI-driven tools for supply chain attacks highlights the need for enhanced security measures and vigilance in managing development environments. Organizations must adapt their security protocols to address the unique challenges posed by AI integration in their software supply chains.
5 months ago
Kill Chain
FBI Seizes RAMP Cybercrime Forum, Disrupting Ransomware Operations
In January 2026, the FBI, in coordination with the U.S. Attorney’s Office for the Southern District of Florida and the Department of Justice’s Computer Crime and Intellectual Property Section, seized the RAMP cybercrime forum. Established in July 2021, RAMP was a Russian-language platform that openly permitted ransomware-as-a-service (RaaS) operations, serving as a hub for ransomware groups like LockBit, ALPHV/BlackCat, and RansomHub. The forum facilitated the promotion of RaaS activities, recruitment of affiliates, and trading of initial network access. The seizure disrupted a significant coordination point for ransomware operators, potentially leading to a short-term decline in ransomware attacks. However, the long-term impact remains uncertain as cybercriminals may migrate to alternative platforms or establish new forums. Law enforcement's access to RAMP's user data could lead to further investigations and arrests, underscoring the ongoing efforts to combat cybercrime.
5 months ago
Kill Chain
Critical Cisco Catalyst SD-WAN Vulnerability Exploited in the Wild
In February 2026, a critical vulnerability (CVE-2026-20127) was discovered in Cisco Catalyst SD-WAN Controller and Manager, allowing unauthenticated remote attackers to bypass authentication and gain administrative privileges. Exploitation involves sending crafted requests to the affected systems, enabling attackers to manipulate network configurations via NETCONF. This vulnerability has been actively exploited since at least 2023 by a sophisticated threat actor identified as UAT-8616. ([socradar.io](https://socradar.io/blog/cve-2026-20127-cisco-catalyst-sd-wan-auth-bypass/?utm_source=openai)) The incident underscores the persistent threat posed by vulnerabilities in widely used network infrastructure. Organizations must prioritize timely patching and implement robust access controls to mitigate such risks. ([fortra.com](https://www.fortra.com/security/emerging-threats/critical-vulnerability-affecting-cisco-catalyst-sd-wan?utm_source=openai))
5 months ago
Kill Chain
Critical Zyxel Router Vulnerability (CVE-2025-13942) Exposes Networks to Remote Attacks
In February 2026, Zyxel identified a critical command injection vulnerability (CVE-2025-13942) in the UPnP function of several router models, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders. This flaw allows unauthenticated remote attackers to execute operating system commands on affected devices by sending specially crafted UPnP SOAP requests. While the vulnerability has a CVSS score of 9.8, its exploitation is contingent upon both UPnP and WAN access being enabled, with the latter disabled by default. Zyxel has released security patches to address this issue and strongly advises users to update their firmware promptly. The significance of this vulnerability is underscored by the widespread deployment of Zyxel devices, often provided by internet service providers as default equipment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is monitoring multiple Zyxel vulnerabilities, highlighting the ongoing risk to network security.
5 months ago
Kill Chain
OpenClaw Supply Chain Attack 2026: Lessons Learned
In February 2026, the OpenClaw AI assistant platform faced a significant supply chain attack. Malicious actors uploaded over 230 compromised 'skills' to ClawHub, OpenClaw's skill repository, between January 27 and 29. These skills, often disguised as crypto trading tools, were designed to exfiltrate sensitive user data, including cryptocurrency wallets and browser information. The attack exploited OpenClaw's extensive system permissions, allowing unauthorized access to users' local files and networks. Additionally, a vulnerability in the Cline CLI tool led to the unintended installation of OpenClaw on approximately 4,000 developer systems, further expanding the attack's reach. ([cyware.com](https://www.cyware.com/resources/threat-briefings/daily-threat-briefing/cyware-daily-threat-intelligence-february-03-2026?utm_source=openai)) This incident underscores the escalating risks associated with AI-powered automation tools and their plugin ecosystems. The rapid adoption of such platforms, combined with insufficient security vetting of third-party extensions, has created new avenues for supply chain attacks. Organizations must prioritize stringent security measures, including thorough code reviews and robust authentication protocols, to mitigate these emerging threats.
5 months ago
Kill Chain
Critical FileZen Vulnerability Exploited: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen, a secure file transfer solution. This flaw allows authenticated users to execute arbitrary commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Exploitation requires valid user credentials, potentially obtained through phishing or credential stuffing. The vulnerability affects FileZen versions 4.2.1 to 4.2.8 and 5.0.0 to 5.0.10. Soliton Systems has released version 5.0.11 to address this issue. Organizations are urged to update immediately and review logs for unauthorized access. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by command injection flaws, emphasizing the need for robust input validation and timely patch management. The incident highlights the importance of monitoring for unauthorized access and maintaining strict access controls to mitigate potential breaches.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports