✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Cisco SD-WAN Authentication Bypass Vulnerability Exploited by UAT-8616
In February 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, exploited by the threat actor UAT-8616 since at least 2023. This flaw allowed unauthenticated remote attackers to gain administrative access, manipulate network configurations, and establish persistent control over affected systems. The exploitation involved downgrading software versions to exploit older vulnerabilities, further escalating privileges. The incident underscores the persistent targeting of network infrastructure by sophisticated actors, emphasizing the need for vigilant monitoring and timely patching of critical vulnerabilities.
5 months ago
Kill Chain
Critical Vulnerabilities in SolarWinds Serv-U: Immediate Action Required
In February 2026, SolarWinds addressed four critical vulnerabilities in its Serv-U file transfer software, identified as CVE-2025-40538 through CVE-2025-40541. These flaws, each with a CVSS score of 9.1, could allow attackers with administrative privileges to execute arbitrary code as root. The vulnerabilities include broken access control, type confusion, and insecure direct object reference issues. While no active exploitation has been reported, similar past vulnerabilities have been targeted by threat actors, notably the China-based group Storm-0322. Organizations using Serv-U are urged to update to version 15.5.4 promptly to mitigate potential risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=openai))
5 months ago
Kill Chain
Fake Next.js Job Interview Tests Backdoor Developers' Devices
In February 2026, a coordinated cyberattack targeted software developers through malicious repositories masquerading as legitimate Next.js projects. These repositories were shared during job interviews or technical assessments, leading developers to clone and execute the code. Upon execution, embedded JavaScript scripts initiated remote code execution (RCE), allowing attackers to deploy backdoors, exfiltrate sensitive data, and introduce additional payloads on compromised systems. The attack utilized multiple execution triggers, including VS Code tasks, development server commands, and backend startup scripts, to maximize infection rates. This incident underscores the evolving tactics of threat actors who exploit standard development workflows to infiltrate systems. The use of job-themed lures and the targeting of developers highlight a broader trend of sophisticated social engineering attacks aimed at the tech industry. Organizations must enhance their security protocols, particularly around code repositories and development tools, to mitigate such risks.
5 months ago
Kill Chain
UFP Technologies Cyberattack: A 2026 Data Theft Incident
In February 2026, UFP Technologies, a leading medical device manufacturer, detected unauthorized access to its IT systems. The breach, identified on February 14, led to the theft and potential destruction of company data, impacting critical functions such as billing and label creation for customer deliveries. Immediate containment measures were implemented, and external cybersecurity experts were engaged to investigate and remediate the incident. The company has since restored access to the affected information and believes the threat actor has been removed from its systems. This incident underscores the escalating cyber threats targeting the healthcare sector, emphasizing the need for robust cybersecurity measures. Organizations must remain vigilant against sophisticated attacks that can disrupt operations and compromise sensitive data, highlighting the importance of proactive defense strategies and incident response planning.
5 months ago
Kill Chain
SLH's Strategic Shift: Recruiting Women for Targeted Vishing Attacks in 2026
In February 2026, the cybercrime collective Scattered LAPSUS$ Hunters (SLH) initiated a campaign to recruit women for voice phishing (vishing) attacks targeting IT help desks. Offering financial incentives of $500 to $1,000 per call and providing pre-written scripts, SLH aims to enhance the effectiveness of their social engineering tactics by leveraging female voices to impersonate employees. This strategy is designed to manipulate help desk personnel into resetting passwords or installing remote monitoring tools, thereby granting unauthorized access to corporate networks. ([dataminr.com](https://www.dataminr.com/resources/intel-brief/slh-recruiting-women-for-vishing/?utm_source=openai)) This development underscores a significant evolution in cybercriminal methodologies, highlighting the increasing sophistication of social engineering attacks. Organizations must recognize the heightened risk posed by such targeted vishing campaigns and implement robust security measures to mitigate potential breaches.
5 months ago
Kill Chain
Malicious NuGet Packages Target ASP.NET Developers in 2026 Supply Chain Attack
In February 2026, cybersecurity researchers identified a supply chain attack involving four malicious NuGet packages—NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_—targeting ASP.NET developers. These packages, published between August 12 and 21, 2024, by a user named hamzazaheer, were downloaded over 4,500 times before removal. The attack exfiltrated ASP.NET Identity data, including user accounts and role assignments, and manipulated authorization rules to create persistent backdoors in victim applications. NCryptYo acted as a first-stage dropper, establishing a local proxy for command-and-control communication, while the other packages facilitated data theft and backdoor creation. This incident underscores the escalating threat of supply chain attacks targeting software developers. Similar campaigns have been observed in other ecosystems, such as the npm registry, where malicious packages like ambar-src have been used to deploy cross-platform malware. The increasing frequency and sophistication of these attacks highlight the critical need for developers to exercise caution when incorporating third-party packages and to implement robust security measures to protect their development environments and end-users.
5 months ago
Kill Chain
Critical Security Flaws Uncovered in Anthropic's Claude Code
In early 2026, multiple critical vulnerabilities were discovered in Anthropic's Claude Code, an AI-powered coding assistant. These flaws allowed attackers to execute arbitrary code and exfiltrate API keys by exploiting configuration mechanisms such as Hooks, Model Context Protocol (MCP) servers, and environment variables. Notably, CVE-2026-21852 enabled malicious repositories to leak Anthropic API keys before users confirmed trust, potentially compromising sensitive data and infrastructure. ([thehackernews.com](https://thehackernews.com/2026/02/claude-code-flaws-allow-remote-code.html?utm_source=openai)) The incident underscores the evolving threat landscape in AI-driven development environments, highlighting the need for robust security measures in automated tools. As AI integration in software development grows, ensuring the integrity of configuration files and implementing strict trust mechanisms become imperative to prevent similar vulnerabilities.
5 months ago
Kill Chain
Lazarus Group's Medusa Ransomware Assaults on U.S. Critical Infrastructure in 2025
In early 2025, the North Korean state-sponsored Lazarus Group launched a series of sophisticated ransomware attacks targeting critical infrastructure sectors, notably healthcare and education, in the United States. Utilizing the Medusa ransomware, the group employed advanced tactics such as exploiting unpatched software vulnerabilities and deploying custom malware tools like Comebacker backdoor and Blindingcan RAT. These attacks led to significant data breaches, operational disruptions, and substantial financial losses for the affected organizations. ([secure.com](https://www.secure.com/news/north-koreas-lazarus-group-is-running-medusa-ransomware-attacks-on-u-s-healthcare?utm_source=openai)) The Lazarus Group's adoption of Medusa ransomware underscores a concerning trend of state-sponsored actors leveraging ransomware-as-a-service platforms to conduct financially motivated cyberattacks. This evolution highlights the urgent need for organizations to enhance their cybersecurity defenses, particularly in sectors handling sensitive data, to mitigate the risks posed by such advanced persistent threats.
5 months ago
Kill Chain
AI-Accelerated Cyberattacks in 2025: A 65% Increase in Speed
In 2025, cyber adversaries significantly enhanced their capabilities by integrating artificial intelligence (AI) into their attack strategies, leading to an 89% increase in AI-enabled operations. This integration resulted in a dramatic reduction in the average breakout time—the period between initial network intrusion and lateral movement—to just 29 minutes, a 65% acceleration from the previous year. Notably, the fastest observed breakout occurred in a mere 27 seconds. Attackers exploited AI systems by injecting malicious prompts into generative AI tools across more than 90 organizations, facilitating credential and cryptocurrency theft. Additionally, vulnerabilities in AI development platforms were leveraged to establish persistence and deploy ransomware, while some adversaries set up malicious AI servers impersonating trusted services to intercept sensitive data. ([crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/?utm_source=openai)) This escalation underscores a critical shift in the cyber threat landscape, where AI serves both as an accelerant for adversarial operations and as a target for exploitation. The rapid adoption of AI by threat actors necessitates that organizations enhance their defensive measures to counteract these sophisticated, AI-driven attacks effectively. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/?utm_source=openai))
5 months ago
Kill Chain
Understanding TOAD Attacks: Bypassing Email Security Through Social Engineering
In early 2025, cybercriminals escalated the use of Telephone-Oriented Attack Delivery (TOAD) techniques to bypass traditional email security measures. These attacks involve sending emails that appear to be from legitimate services, such as Microsoft Entra, Zoom, or Hulu+, containing fake invoices or alerts with a phone number for recipients to call. Upon calling, victims are connected to fraudulent call centers where they are manipulated into downloading remote access software, granting attackers control over their systems. This method effectively circumvents email filters by excluding malicious links or attachments, relying instead on social engineering tactics to exploit human trust. ([cybernews.com](https://cybernews.com/security/new-toad-phishing-campaign-targets-microsoft-entra-invitees-with-fake-invoices/?utm_source=openai)) The prevalence of TOAD attacks underscores a significant shift in phishing strategies, emphasizing the need for organizations to enhance their security awareness training and adopt multi-layered defense mechanisms. As these attacks exploit trusted communication channels and human psychology, traditional technical defenses alone are insufficient, highlighting the urgency for comprehensive security approaches that address both technological and human factors. ([phishcloud.com](https://phishcloud.com/toad-phishing-attack-prevention/?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Soliton Systems' FileZen: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen file transfer appliance. This flaw allows authenticated users to execute arbitrary operating system commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Affected versions include FileZen V5.0.0 to V5.0.10 and V4.2.1 to V4.2.8. Exploitation of this vulnerability could lead to full system compromise, data theft, and unauthorized access to sensitive information. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25108?utm_source=openai)) The inclusion of CVE-2026-25108 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. With active exploitation observed, entities using vulnerable versions of FileZen are at heightened risk. Immediate patching to version V5.0.11 or later is strongly recommended to mitigate potential threats. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai))
5 months ago
Kill Chain
VulnCheck 2025 Exploit Intelligence Report: Key Findings
In 2025, VulnCheck identified over 40,000 newly published vulnerabilities, yet only 1% (approximately 422) were exploited in the wild. This highlights a significant challenge in vulnerability management, as defenders struggle to prioritize amidst the overwhelming volume of disclosed vulnerabilities. Notably, network edge devices accounted for 28% of the top targeted technologies, underscoring their critical role in organizational security. The rapid exploitation of vulnerabilities, with nearly a third being weaponized within 24 hours of disclosure, emphasizes the need for organizations to enhance their patch management processes and adopt proactive security measures to mitigate emerging threats effectively. ([vulncheck.com](https://www.vulncheck.com/blog/state-of-exploitation-2026?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports