✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
SonicWall's 2025 Cloud Backup Data Breach: A Wake-Up Call for Cloud Security
In September 2025, SonicWall, a prominent cybersecurity firm, experienced a significant data breach affecting all customers utilizing its MySonicWall cloud backup service. Initially, the company reported that fewer than 5% of users were impacted; however, it was later confirmed that every customer using the cloud backup feature was affected. The breach exposed encrypted firewall configuration files containing sensitive data such as network rules, VPN settings, administrative credentials, and service authentication details. Although the files remained encrypted, their exposure heightened the risk of targeted cyberattacks due to the critical nature of the information. SonicWall promptly advised customers to delete existing cloud backups, reset credentials, rotate shared secrets, and transition to local backups to mitigate potential threats. This incident underscores the vulnerabilities inherent in cloud-based services and the importance of robust security measures to protect sensitive data. The breach also highlights the necessity for organizations to maintain vigilance and implement comprehensive security protocols to safeguard against evolving cyber threats.
5 months ago
Kill Chain
Salt Typhoon 2026 Telecom Breach: A Wake-Up Call for Cybersecurity
In early 2026, the Chinese state-sponsored hacking group known as Salt Typhoon executed a sophisticated cyber espionage campaign targeting major telecommunications providers, including AT&T and Verizon. The attackers exploited vulnerabilities in network devices to gain unauthorized access, allowing them to intercept private communications and exfiltrate sensitive data over an extended period. This breach compromised the personal information of millions of users and raised significant concerns about the security of critical infrastructure. The incident underscores the escalating threat posed by nation-state actors to global telecommunications networks. Despite previous sanctions and heightened security measures, Salt Typhoon's continued success highlights the need for more robust defenses and international cooperation to protect against such advanced persistent threats.
5 months ago
Kill Chain
Critical Vulnerability in Grandstream VoIP Phones Exposes Networks to Attack
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, allowing unauthenticated remote code execution with root privileges. The flaw, present in the devices' web-based API service, could be exploited by sending specially crafted HTTP requests to the /cgi-bin/api.values.get endpoint, enabling attackers to intercept calls, extract credentials, and potentially pivot into internal networks. Grandstream released firmware version 1.0.7.81 to address this issue. This incident underscores the importance of securing VoIP infrastructure, especially as such devices are often overlooked in security assessments. The availability of exploit code and the widespread use of these devices make immediate patching and network segmentation critical to prevent potential breaches.
5 months ago
Kill Chain
Microsoft 365 Copilot Bug Leads to Exposure of Confidential Emails
In early 2026, Microsoft identified a critical bug in its Microsoft 365 Copilot AI assistant, which allowed the system to process and summarize emails labeled as 'Confidential' despite existing Data Loss Prevention (DLP) policies designed to prevent such actions. This vulnerability, reported by customers on January 21, 2026, and acknowledged by Microsoft in early February, specifically affected emails stored in the Sent Items and Drafts folders. The flaw enabled Copilot Chat to access and summarize sensitive content, potentially exposing confidential information to unauthorized users. Microsoft has since rolled out a fix to address this issue. ([techcrunch.com](https://techcrunch.com/2026/02/18/microsoft-says-office-bug-exposed-customers-confidential-emails-to-copilot-ai/?utm_source=openai)) This incident underscores the challenges in securing AI-driven tools within enterprise environments. As organizations increasingly integrate AI assistants into their workflows, ensuring that these systems adhere to established data protection policies becomes paramount. The Copilot bug highlights the necessity for continuous monitoring and updating of security measures to prevent unintended data exposure.
5 months ago
Kill Chain
Critical SmarterMail Vulnerabilities Exploited in 2026
In January 2026, SmarterTools' SmarterMail software was found to have two critical vulnerabilities: CVE-2026-24423, an unauthenticated remote code execution flaw, and CVE-2026-23760, an authentication bypass issue. These vulnerabilities allowed attackers to execute arbitrary code and reset administrator passwords without authentication, leading to full system compromise. Exploitation began shortly after disclosure, with threat actors sharing exploit code and compromised credentials on underground forums. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai)) The rapid weaponization of these vulnerabilities underscores the increasing speed at which attackers exploit newly disclosed flaws. Organizations must prioritize timely patching and enhance monitoring of email infrastructure to prevent similar breaches. ([scworld.com](https://www.scworld.com/news/smartermail-vulnerabilities-exploited-in-ransomware-campaigns?utm_source=openai))
5 months ago
Kill Chain
CISA Adds Four Vulnerabilities to KEV Catalog - January 2026
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation evidence. The vulnerabilities include CVE-2025-68645 affecting Synacor Zimbra Collaboration Suite, CVE-2025-34026 in Versa Concerto SD-WAN platform, CVE-2025-31125 in Vite Vitejs, and CVE-2025-54313 in eslint-config-prettier. These flaws span email platforms, SD-WAN infrastructure, development tools, and package managers, posing significant risks across various sectors. ([isec.news](https://www.isec.news/2026/01/24/cisa-adds-four-vulnerabilities-to-kev-catalog-and-sets-federal-patch-deadline/?utm_source=openai)) The inclusion of these vulnerabilities underscores the escalating threat landscape, with attackers increasingly targeting diverse software components. Organizations are urged to prioritize patching by the February 12, 2026 deadline to mitigate potential breaches and maintain operational security. ([cyberpress.org](https://cyberpress.org/cisa-adds-four-critical-vulnerabilities-to-kev-catalog-following-active-exploitation/?utm_source=openai))
5 months ago
Kill Chain
AI Assistants: The New Frontier for Stealthy Malware Communication
In February 2026, cybersecurity researchers from Check Point Research identified a novel method by which AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI's Grok, can be exploited to facilitate covert command-and-control (C2) communications for malware. By manipulating these AI platforms to fetch attacker-controlled URLs, threat actors can establish stealthy communication channels that blend seamlessly into legitimate enterprise traffic, thereby evading traditional detection mechanisms. This technique underscores the evolving landscape of cyber threats, where everyday AI tools are repurposed for malicious activities. The discovery highlights a significant shift in cyberattack methodologies, emphasizing the need for organizations to reassess their security postures in the context of AI integration. As AI assistants become more prevalent in enterprise environments, the potential for their misuse in cyberattacks increases, necessitating enhanced monitoring and adaptive defense strategies to mitigate such risks.
5 months ago
Kill Chain
Dell RecoverPoint Zero-Day Exploited by UNC6201
In mid-2024, a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines was exploited by the China-linked cyberespionage group UNC6201. This flaw, involving hardcoded credentials, allowed unauthenticated remote attackers to gain root-level access, facilitating lateral movement, persistent access, and deployment of malware such as BRICKSTORM and the newer GRIMBOLT backdoor. The attackers also employed 'ghost NICs' to stealthily pivot within virtualized environments, complicating detection and response efforts. The exploitation of this vulnerability underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure. Organizations are urged to apply Dell's remediation measures promptly to mitigate potential risks associated with this exploit.
5 months ago
Kill Chain
Critical Vulnerability in Honeywell CCTV Products Exposes Unauthorized Access Risks
In February 2026, a critical vulnerability (CVE-2026-1670) was discovered in multiple Honeywell CCTV products, allowing unauthenticated attackers to remotely change the 'forgot password' recovery email address. This flaw enables unauthorized access to camera feeds and potential account hijacking. The affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3, PTZ WDR 2MP 32M, and 25M IPC, all running firmware version WDR_2MP_32M_PTZ_v2.0. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially those deployed in critical infrastructure. Organizations are advised to minimize network exposure of such devices, isolate them behind firewalls, and use secure remote access methods like updated VPN solutions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai))
5 months ago
Kill Chain
Critical Flaws in Popular VS Code Extensions Put Millions at Risk
In February 2026, critical vulnerabilities were discovered in four widely used Visual Studio Code (VS Code) extensions—Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview—collectively installed over 125 million times. These flaws could allow attackers to steal local files and execute remote code by exploiting weaknesses in the extensions' handling of web content and local server configurations. Notably, CVE-2025-65717 in Live Server enables file exfiltration via malicious websites, while CVE-2025-65716 in Markdown Preview Enhanced permits arbitrary code execution through crafted markdown files. Despite disclosure in June 2025, three of these vulnerabilities remained unpatched as of February 2026, leaving developers exposed to significant security risks. ([thehackernews.com](https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting development environments. The exploitation of trusted tools like VS Code extensions highlights the need for developers to exercise caution when installing and updating extensions, and for maintainers to prioritize timely security patches to mitigate potential compromises.
5 months ago
Kill Chain
Critical Vulnerability in Grandstream GXP1600 VoIP Phones: CVE-2026-2329
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, affecting models GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. This unauthenticated stack-based buffer overflow in the HTTP API endpoint "/cgi-bin/api.values.get" allows remote attackers to execute arbitrary code with root privileges. Exploitation could lead to unauthorized access, interception of VoIP communications, and potential eavesdropping on sensitive conversations. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai)) The incident underscores the importance of promptly applying security patches and monitoring VoIP infrastructure for vulnerabilities. Organizations using these devices should update to firmware version 1.0.7.81 to mitigate the risk. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai))
5 months ago
Kill Chain
KongTuke's CrashFix Campaign: Exploiting DNS to Deliver ModeloRAT
In early 2026, the threat actor known as KongTuke launched an evolved ClickFix campaign, dubbed 'CrashFix,' targeting corporate environments. The attack began with users installing a malicious Chrome extension named NexShield, masquerading as a legitimate ad blocker. After a delay, the extension deliberately crashed the browser, displaying a fake 'CrashFix' security warning. This prompt instructed users to run a command that executed a custom DNS lookup, leading to the download and execution of ModeloRAT, a Python-based remote access trojan. This sophisticated social engineering tactic exploited user trust and system utilities to gain unauthorized access to corporate systems. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/?utm_source=openai)) This incident underscores a growing trend of attackers leveraging social engineering combined with native system tools to bypass traditional security measures. The use of DNS queries for payload delivery highlights the need for enhanced monitoring of network traffic and user education to recognize and resist such deceptive tactics.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports