✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Lazarus Group's Medusa Ransomware Attacks on Healthcare in 2026
In early 2026, the North Korean state-sponsored Lazarus Group initiated a series of cyberattacks targeting healthcare organizations in the United States and the Middle East using Medusa ransomware. These attacks involved deploying the ransomware to encrypt critical data, followed by ransom demands averaging $260,000. Notably, the group targeted a mental health nonprofit and an educational facility for autistic children in the U.S. ([theregister.com](https://www.theregister.com/2026/02/24/north_koreas_lazarus_group_healthcare_medusa_ransomware/?utm_source=openai)). The attackers utilized a suite of tools, including the Comebacker backdoor and Blindingcan remote access trojan, to infiltrate and compromise systems. ([scworld.com](https://www.scworld.com/news/north-koreas-lazarus-group-targets-us-middle-east-healthcare-sectors?utm_source=openai)) This incident underscores the Lazarus Group's continued evolution and adaptability in cyber warfare, highlighting the persistent threat posed by state-sponsored actors to critical infrastructure sectors. The healthcare industry's vulnerability to such attacks emphasizes the urgent need for enhanced cybersecurity measures and international cooperation to mitigate the risks associated with sophisticated ransomware campaigns.
5 months ago
Kill Chain
Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Attention
In February 2026, SolarWinds disclosed four critical vulnerabilities in its Serv-U file transfer software, including CVE-2025-40538, a broken access control flaw allowing attackers with administrative privileges to create system admin users and execute arbitrary code as root. These vulnerabilities, each assigned a CVSS score of 9.1, could lead to full system compromise if exploited. SolarWinds released version 15.5.4 to address these issues. The disclosure underscores the persistent targeting of file transfer solutions by threat actors due to their access to sensitive data. Organizations are urged to promptly apply patches and review access controls to mitigate potential exploitation risks.
5 months ago
Kill Chain
1Campaign: The Cloaking Service Fueling Malicious Google Ads
In February 2026, cybersecurity researchers uncovered '1Campaign,' a sophisticated cloaking service that enables threat actors to run malicious Google Ads while evading detection. Managed by a developer known as 'DuppyMeister,' 1Campaign has been active for at least three years. The platform allows attackers to display benign content to security researchers and automated scanners, while serving malicious content to real users. This technique prolongs the lifespan of malicious ads, facilitating phishing and crypto-draining campaigns. The service offers a user-friendly dashboard for real-time visitor filtering based on geography, ISP, and device characteristics, effectively blocking over 99% of non-targeted traffic. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/1campaign-platform-helps-malicious-google-ads-evade-detection/?utm_source=openai)) The emergence of 1Campaign highlights a growing trend in cybercrime where attackers leverage advanced cloaking techniques to bypass traditional security measures. This development underscores the need for enhanced detection capabilities and adaptive security strategies to counteract increasingly sophisticated malvertising campaigns.
5 months ago
Kill Chain
Lazarus Group's Medusa Ransomware Attacks on Healthcare in 2026
In early 2026, the North Korean state-sponsored Lazarus Group initiated ransomware attacks using the Medusa ransomware variant, targeting healthcare organizations in the Middle East and the United States. These attacks involved data encryption and exfiltration, with ransom demands averaging $260,000. The group employed tools such as RP_Proxy, Mimikatz, and BLINDINGCAN to facilitate their operations. The healthcare sector's critical role and sensitive data made it a prime target, leading to significant operational disruptions and potential patient data breaches. This incident underscores a concerning trend of state-sponsored actors leveraging ransomware-as-a-service platforms to conduct financially motivated attacks. The collaboration between nation-state groups and established cybercriminal infrastructures highlights the evolving threat landscape, necessitating enhanced cybersecurity measures and international cooperation to mitigate such risks.
5 months ago
Kill Chain
GitHub Codespaces 'RoguePilot' Vulnerability: A Wake-Up Call for AI Security
In February 2026, a critical vulnerability named 'RoguePilot' was discovered in GitHub Codespaces, allowing attackers to inject malicious instructions into GitHub issues. When developers launched a Codespace from such an issue, GitHub Copilot processed these hidden prompts, leading to unauthorized actions, including the exfiltration of sensitive data like the GITHUB_TOKEN. This flaw enabled potential repository takeovers and unauthorized code execution. Microsoft promptly patched the vulnerability following responsible disclosure. ([thehackernews.com](https://thehackernews.com/2026/02/roguepilot-flaw-in-github-codespaces.html?utm_source=openai)) This incident underscores the growing risks associated with integrating AI tools into development workflows, highlighting the need for robust security measures to prevent AI-driven supply chain attacks.
5 months ago
Kill Chain
Entra ID Applications Requesting Unexpected Permissions: A 2026 Security Alert
In early 2026, security researchers identified a significant vulnerability within Microsoft Entra ID, where certain applications were requesting unexpected and overly permissive access permissions. This issue arose due to misconfigurations in application consent settings, allowing applications to prompt users for extensive permissions without adequate oversight. Exploiting this flaw, threat actors could gain unauthorized access to sensitive organizational data, leading to potential data breaches and compliance violations. This incident underscores the critical importance of stringent application consent policies and regular audits of permission settings. As organizations increasingly adopt cloud-based identity solutions, ensuring that applications request only the necessary permissions is vital to maintaining security and compliance.
5 months ago
Kill Chain
AI-Powered Cyberattack Compromises 600 FortiGate Firewalls in 2026
Between January 11 and February 18, 2026, a Russian-speaking threat actor compromised over 600 FortiGate firewalls across 55 countries. Utilizing generative AI tools, the attacker scanned for exposed management interfaces on ports such as 443 and 10443, and employed brute-force methods to gain access using weak credentials. Once inside, AI-generated scripts were used to extract and decrypt sensitive data, including SSL-VPN and administrative credentials, firewall policies, and network architectures. The attacker further infiltrated networks using recovered credentials and deployed AI-generated reconnaissance tools. Analysis of these tools revealed signs of AI-assisted coding, such as poor error handling and inefficient code structures. ([techradar.com](https://www.techradar.com/pro/security/russian-hacker-uses-multiple-ai-tools-to-break-hundreds-of-firewalls?utm_source=openai)) This incident underscores the growing accessibility of sophisticated cyberattack capabilities through AI tools, enabling even low-skilled actors to execute large-scale breaches. The reliance on AI for various attack phases, from reconnaissance to exploitation, highlights a significant shift in the cyber threat landscape, emphasizing the need for robust security measures and continuous monitoring to mitigate such AI-assisted threats.
5 months ago
Kill Chain
CrowdStrike 2025 Global Threat Report: Attackers Moving Through Networks in Under 30 Minutes
In 2025, cyberattacks accelerated significantly, with the average breakout time—the duration for attackers to move from initial intrusion to other network systems—dropping to 29 minutes, a 65% increase in speed from the previous year. Notably, the fastest recorded breakout time was 27 seconds. This rapid progression was facilitated by attackers refining their techniques, leveraging social engineering to access high-privilege systems swiftly, and exploiting gaps across cloud, identity, enterprise, and unmanaged network devices. Consequently, defenders faced increased challenges, including burnout and stress, leading to potential mistakes. Additionally, CrowdStrike identified 281 threat groups by the end of 2025, including 24 new threats named throughout the year, highlighting the expanding and evolving threat landscape. The urgency of this issue is underscored by the 37% year-over-year increase in cloud-focused attacks, with a staggering 266% surge in such activities from nation-state threat groups. Furthermore, 82% of attacks detected in 2025 were malware-free, indicating a shift towards hands-on-keyboard operations and the abuse of legitimate tools and credentials. This trend emphasizes the need for organizations to enhance their security measures, focusing on rapid detection and response capabilities to mitigate the risks posed by increasingly sophisticated and swift cyber adversaries.
5 months ago
Kill Chain
Roundcube Webmail Vulnerabilities: Immediate Action Required
In June and December 2025, two critical vulnerabilities were identified in Roundcube Webmail: CVE-2025-49113, a remote code execution flaw, and CVE-2025-68461, a cross-site scripting vulnerability. These flaws allowed attackers to execute arbitrary code and inject malicious scripts, respectively, compromising the security of affected systems. Despite patches being released promptly, threat actors rapidly developed exploits, leading to active exploitation of these vulnerabilities. The exploitation of these vulnerabilities underscores the persistent threat posed by unpatched software in widely used applications. Organizations must prioritize timely updates and robust security measures to mitigate such risks. ([securityweek.com](https://www.securityweek.com/recent-roundcube-webmail-vulnerability-exploited-in-attacks/?utm_source=openai))
5 months ago
Kill Chain
Security Flaws in Android Mental Health Apps Put Millions at Risk
In February 2026, security researchers identified significant vulnerabilities in several Android mental health applications, collectively downloaded over 14.7 million times from Google Play. These apps, designed to assist users with conditions such as depression and anxiety, were found to contain a total of 1,575 security flaws, including 54 high-severity and 538 medium-severity issues. Exploiting these vulnerabilities could allow attackers to intercept sensitive user data, including therapy session transcripts and personal health information, thereby compromising user privacy and confidentiality. This incident underscores the critical need for rigorous security measures in applications handling sensitive health data. The discovery highlights the potential risks associated with inadequate app security, emphasizing the importance of regular security assessments and compliance with data protection regulations to safeguard user information.
5 months ago
Kill Chain
PromptSpy AI Malware: Unveiling the Future of Android Cyber Threats
In February 2026, cybersecurity researchers identified 'PromptSpy,' the first known Android malware leveraging generative AI at runtime. This sophisticated malware utilizes Google's Gemini model to adapt its persistence mechanisms across various devices, enhancing its ability to evade detection. PromptSpy's discovery marks a significant evolution in mobile threats, demonstrating the integration of AI to dynamically modify malicious behavior during execution. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/promptspy-is-the-first-android-malware-to-use-generative-ai-at-runtime/?utm_source=openai)) The emergence of AI-driven malware like PromptSpy underscores a critical shift in cyber threats, where adversaries harness advanced technologies to create more resilient and adaptive attack vectors. This development necessitates a reevaluation of current security measures to effectively counteract AI-enhanced malicious activities.
5 months ago
Kill Chain
Unveiling the Malicious JPEG Infostealer Campaign of February 2026
In February 2026, a sophisticated malware campaign was identified, leveraging steganographic techniques to embed malicious code within JPEG image files. Unsuspecting users were tricked into downloading these seemingly benign images, which, upon execution, initiated a multi-stage infection process. The primary payload was an infostealer designed to extract sensitive data, including browser credentials and system information, while maintaining communication with a command-and-control server. This method allowed attackers to exfiltrate data stealthily, minimizing detection by traditional security measures. This incident underscores the evolving tactics of cybercriminals, who are increasingly employing advanced obfuscation methods like steganography to bypass security defenses. The use of common file formats, such as JPEGs, as carriers for malware highlights the need for enhanced vigilance and the adoption of comprehensive security solutions capable of detecting such covert threats.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports