✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
AI Assistants Abused as Command-and-Control Proxies in Recent Cyberattacks
In February 2026, cybersecurity researchers disclosed a novel attack technique where AI assistants with web browsing capabilities, such as Microsoft Copilot and xAI Grok, were exploited as covert command-and-control (C2) proxies. This method, termed 'AI as a C2 proxy' by Check Point Research, allows attackers to blend malicious traffic with legitimate enterprise communications, thereby evading detection. The attack leverages anonymous web access combined with browsing and summarization prompts to create a bidirectional channel for data exfiltration and command execution. This development underscores the evolving threat landscape, where AI systems are not only tools for enhancing productivity but also potential vectors for sophisticated cyberattacks. The ability to abuse AI assistants as C2 proxies highlights the need for organizations to reassess their security postures, especially concerning the integration and use of AI technologies within their networks.
5 months ago
Kill Chain
Whisper Leak: Unveiling Side-Channel Vulnerabilities in LLMs
In November 2025, researchers Geoff McDonald and Jonathan Bar Or identified a side-channel vulnerability in Large Language Models (LLMs) termed 'Whisper Leak.' This attack exploits patterns in encrypted network traffic—specifically packet sizes and timing—to infer user prompt topics during LLM interactions. Despite TLS encryption, these metadata patterns allow adversaries to classify conversation topics with high accuracy, posing significant privacy risks. The study demonstrated the attack's effectiveness across 28 popular LLMs, achieving near-perfect classification rates and high precision even in scenarios with extreme class imbalance. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai)) The discovery of Whisper Leak underscores the urgent need for LLM providers to address metadata leakage vulnerabilities. As LLMs are increasingly deployed in sensitive domains such as healthcare and legal services, ensuring robust privacy protections is paramount. The researchers evaluated mitigation strategies like random padding, token batching, and packet injection; however, none provided complete protection, highlighting the complexity of securing LLM communications against side-channel attacks. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai))
5 months ago
Kill Chain
Salesloft Drift Breach 2025: A Wake-Up Call for SaaS Security
In August 2025, Salesloft's Drift application suffered a significant security breach when attackers exploited compromised OAuth tokens to access and exfiltrate data from over 700 organizations' Salesforce instances. The breach exposed sensitive information, including customer contact details, support case data, and, in some cases, credentials such as AWS access keys and passwords. Prominent companies like Cloudflare, Zscaler, and Palo Alto Networks were among those affected. The attackers, identified as the group "Scattered Lapsus$ Hunters," demanded nearly $1 billion in ransom to prevent the public release of the stolen data. This incident underscores the critical vulnerabilities associated with third-party integrations and the importance of robust security measures to protect against supply chain attacks.
5 months ago
Kill Chain
Understanding the 2026 ClickFix DNS PowerShell Attack
In February 2026, a new variant of the ClickFix social engineering attack emerged, exploiting DNS queries to deliver malicious payloads. Attackers deceived users into executing an 'nslookup' command via the Windows Run dialog, which queried an attacker-controlled DNS server. The server responded with a DNS record containing a malicious PowerShell script, leading to the installation of malware, including the remote access trojan ModeloRAT. This method allowed attackers to blend malicious activities within normal DNS traffic, evading traditional detection mechanisms. This incident underscores the evolving sophistication of social engineering attacks, highlighting the need for heightened awareness and advanced security measures. The use of DNS as a delivery mechanism signifies a shift in attacker tactics, emphasizing the importance of monitoring DNS traffic and educating users about the risks of executing unsolicited commands.
5 months ago
Kill Chain
Google Patches Actively Exploited Chrome Zero-Day Vulnerability CVE-2026-2441
In February 2026, Google addressed a high-severity zero-day vulnerability in Chrome, identified as CVE-2026-2441. This use-after-free flaw in the browser's CSS component allowed attackers to execute arbitrary code by enticing users to visit malicious websites. The vulnerability was actively exploited in the wild, prompting Google to release emergency updates for Windows, macOS, and Linux platforms. Users were urged to update their browsers immediately to mitigate potential risks. This incident underscores the persistent threat posed by zero-day vulnerabilities in widely used software. The rapid exploitation of such flaws highlights the need for continuous vigilance and prompt patching to protect against emerging cyber threats.
5 months ago
Kill Chain
BeyondTrust 2026 Remote Code Execution Vulnerability: Immediate Action Required
In February 2026, BeyondTrust disclosed a critical remote code execution (RCE) vulnerability, identified as CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. This flaw, with a CVSS score of 9.9, allows unauthenticated attackers to execute operating system commands remotely, potentially leading to full system compromise. The vulnerability impacts RS versions 25.3.1 and earlier, and PRA versions 24.3.4 and earlier. BeyondTrust issued patches on February 2, 2026, urging all customers, especially those with self-hosted instances not subscribed to automatic updates, to apply the patches promptly. ([beyondtrust.com](https://www.beyondtrust.com/trust-center/security-advisories/bt26-02?utm_source=openai)) The urgency of this situation is underscored by the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) directive for federal agencies to secure their BeyondTrust instances within three days, highlighting the active exploitation of this vulnerability in the wild. ([techradar.com](https://www.techradar.com/pro/security/cisa-tells-agencies-to-patch-beyondtrust-bug-now?utm_source=openai))
5 months ago
Kill Chain
Washington Hotel Japan Ransomware Attack: A 2026 Case Study
In February 2026, Washington Hotel, a prominent hospitality chain in Japan, experienced a ransomware attack that compromised its servers and exposed various business data. The breach occurred on February 13, 2026, at 22:00 local time. Upon detection, the IT staff promptly disconnected the affected servers from the internet to prevent further spread. An internal task force, along with external cybersecurity experts, was established to assess the impact and coordinate recovery efforts. While customer data is believed to be secure, as it is stored on separate servers managed by a different company, some operational disruptions, including temporary unavailability of credit card terminals, were reported. The financial impact is under review, and the company is collaborating with law enforcement and cybersecurity professionals to investigate the incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/washington-hotel-in-japan-discloses-ransomware-infection-incident/?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks targeting the hospitality industry, particularly in Japan. Recent data indicates a significant increase in such attacks, with small and medium-sized enterprises being primary targets. The Washington Hotel breach highlights the urgent need for robust cybersecurity measures and proactive strategies to mitigate the risks associated with ransomware and other cyber threats. ([linkedin.com](https://www.linkedin.com/pulse/ransomware-attacks-targeting-japanese-companies-increase-baek-glpcc?utm_source=openai))
5 months ago
Kill Chain
ZeroDayRAT: The New Mobile Spyware Threatening Device Security
In early February 2026, cybersecurity researchers identified ZeroDayRAT, a sophisticated mobile spyware platform being sold openly on Telegram. This malware grants attackers full remote control over Android (versions 5 through 16) and iOS devices (up to iOS 26, including the iPhone 17 Pro). Once installed via smishing, phishing emails, or malicious app stores, ZeroDayRAT enables comprehensive surveillance, including GPS tracking, message interception, live camera and microphone access, keylogging, and financial theft targeting banking and cryptocurrency applications. The spyware's user-friendly control panel allows even non-technical operators to exploit compromised devices effectively. ([securityweek.com](https://www.securityweek.com/new-zerodayrat-spyware-kit-enables-total-compromise-of-ios-android-devices/?utm_source=openai)) The emergence of ZeroDayRAT signifies a concerning trend where advanced surveillance tools, previously accessible only to nation-state actors, are now available to a broader range of cybercriminals. This development underscores the urgent need for enhanced mobile security measures and user vigilance to prevent unauthorized access and data breaches. ([securityweek.com](https://www.securityweek.com/new-zerodayrat-spyware-kit-enables-total-compromise-of-ios-android-devices/?utm_source=openai))
5 months ago
Kill Chain
Google Chrome Zero-Day Exploit CVE-2026-2441 Patched
In February 2026, Google addressed a high-severity vulnerability in its Chrome browser, identified as CVE-2026-2441. This use-after-free flaw in the CSS component allowed remote attackers to execute arbitrary code within the browser's sandbox via crafted HTML pages. Security researcher Shaheen Fazim reported the issue on February 11, 2026, and Google released patches for Windows, macOS, and Linux shortly thereafter. The vulnerability was actively exploited in the wild, though specific details about the attacks remain undisclosed. This incident underscores the persistent threat posed by zero-day vulnerabilities in widely used software. The exploitation of CVE-2026-2441 highlights the importance of timely software updates and robust security practices. Users are urged to ensure their browsers are updated to the latest versions to mitigate potential risks.
5 months ago
Kill Chain
Outlook Add-In Hijack Exposes 4,000 Microsoft Accounts
In early February 2026, a threat actor exploited an abandoned Microsoft Outlook add-in named AgreeTo, originally a meeting scheduling tool, to conduct a phishing campaign. By claiming the add-in's orphaned URL, the attacker replaced its content with a phishing kit that mimicked Microsoft's sign-in page, leading to the compromise of over 4,000 Microsoft account credentials. This incident underscores the risks associated with unmaintained third-party applications and highlights the need for rigorous oversight of software supply chains. The attack also demonstrates how adversaries can leverage trusted platforms to distribute malicious content, emphasizing the importance of continuous monitoring and validation of third-party integrations.
5 months ago
Kill Chain
OpenClaw 2026 Infostealer Vidar Breach: A Wake-Up Call for AI Security
In February 2026, cybersecurity researchers identified a significant security breach involving OpenClaw, an open-source AI agent platform. An infostealer malware, likely a variant of Vidar, infiltrated a user's system and exfiltrated sensitive OpenClaw configuration files. These files contained critical data, including API keys for AI services, OAuth tokens for platforms like Gmail and Slack, and detailed operational guidelines of the AI agent. The theft of these credentials enabled attackers to remotely access and control the victim's OpenClaw instance, potentially leading to unauthorized actions and data exfiltration. This incident underscores the evolving threat landscape where infostealer malware targets AI agent configurations, highlighting the urgent need for enhanced security measures in AI integrations. As AI agents become more embedded in professional workflows, they present attractive targets for cybercriminals aiming to exploit their access to sensitive data and systems.
5 months ago
Kill Chain
Major Password Managers Exposed: Critical Vulnerabilities Affect Millions
In February 2026, researchers from ETH Zurich and Università della Svizzera italiana identified critical vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. The study revealed 25 distinct attacks that could compromise user vaults, ranging from integrity violations to complete access to all stored passwords. These vulnerabilities exploit flaws in key escrow mechanisms, item-level encryption, sharing features, and backward compatibility with legacy code. Collectively, these password managers serve over 60 million users and nearly 125,000 businesses. ([thehackernews.com](https://thehackernews.com/2026/02/study-uncovers-25-password-recovery.html?utm_source=openai)) This incident underscores the importance of scrutinizing the security claims of widely-used password management solutions. As cyber threats evolve, organizations must ensure that their security tools are resilient against sophisticated attacks, especially those targeting foundational security mechanisms like zero-knowledge encryption.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports