✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Sicarii Ransomware: The 2024 False-Flag Attack with Unbreakable Encryption
In early 2024, a new ransomware variant dubbed 'Sicarii' surfaced, reportedly leveraging poorly designed, obfuscated code and incorporating Hebrew language elements that may serve as a false flag to mislead investigators about its origin. The ransomware, first detected in late 2023, compromises victim environments, encrypts files, and delivers notes demanding payment in cryptocurrency for data recovery. Although initial analysis indicates programming weaknesses, security researchers confirmed that its encryption implementation is resilient, making recovery without payment infeasible. The malware also exhibits unique lateral movement and persistence behaviors before exfiltrating data to attacker-controlled infrastructure. This incident is reflective of a broader increase in ransomware operations deploying deceptive attribution techniques and leveraging unconventional languages or scripts. The emergence of ‘Sicarii’ underscores the persistent threat and ever-evolving tactics used by ransomware groups to evade detection and complicate response efforts for organizations worldwide.
6 months ago
Kill Chain
WinRAR Patch Delays Enable Nation-State Attackers in 2024
In early 2024, nation-state threat actors from Russia and China exploited a critical WinRAR vulnerability (CVE-2023-38831) well after a public patch became available in July 2023. Attackers leveraged the flaw via malicious archive files to gain initial access, with phishing lures targeting small- and medium-sized businesses (SMBs) and government targets. Despite availability of security updates and widespread coverage, a significant number of organizations remained unpatched, enabling cyber-espionage operations, data theft, and operational disruptions. This incident highlights the persistent risk posed by software supply chain vulnerabilities, especially when patch adoption is slow. The continued exploitation of a months-old flaw underscores how threat actors weaponize common utilities and rely on lagging defenses, driving urgency for improved vulnerability management and zero trust controls.
6 months ago
Kill Chain
Fortinet’s 2024 Zero-Day SSO Breach: Key Lessons in Cloud Identity Security
In June 2024, Fortinet disclosed a critical zero-day vulnerability that was actively exploited by threat actors to compromise FortiCloud single sign-on (SSO) authentication, enabling unauthorized access to customer devices. Attackers leveraged the flaw to perform malicious SSO logins, bypassing authentication controls and potentially moving laterally within affected network environments. In response, Fortinet took the unprecedented step of disabling FortiCloud SSO services temporarily for all users while investigating and developing a fix. This incident underscores significant risks associated with identity and access management in cloud-delivered network security platforms. This breach highlights the growing prevalence of zero-day exploitation targeting authentication mechanisms and cloud infrastructure. As attackers increasingly focus on SSO and federated identity systems, organizations must reassess their reliance on third-party authentication, strengthen monitoring, and accelerate adoption of zero trust strategies.
6 months ago
Kill Chain
Fortinet 2026 Breach: Authentication Bypass via FortiCloud SSO Drives Widespread Exploitation
In January 2026, Fortinet suffered a critical security incident when attackers exploited CVE-2026-24858, an authentication bypass vulnerability impacting FortiCloud SSO on key products like FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer. Malicious actors with valid FortiCloud accounts could access devices registered to other users, enabling unauthorized firewall changes, new privileged account creation, and illicit VPN reconfiguration, even on systems patched for earlier SSO flaws. Fortinet responded by temporarily disabling and then remediating FortiCloud SSO, and CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. This incident underscores the risks of centralized identity platforms and SSO misconfigurations, as well as the persistent attacker interest in cloud-managed network appliances. Growing exploitation of authentication bypass vulnerabilities has regulatory and operational implications for organizations reliant on integrated cloud services.
6 months ago
Kill Chain
Johnson Controls Metasys Vulnerability: 2026 SQL Exposure Threatens Critical Infrastructure
In January 2026, Johnson Controls disclosed a critical vulnerability (CVE-2025-26385) affecting multiple Metasys products including the Application and Data Server (ADS), Extended Application and Data Server (ADX), LCS8500, NAE8500, System Configuration Tool (SCT), and Controller Configuration Tool (CCT). The flaw, stemming from improper neutralization of special elements used in a command, could allow remote, unauthenticated attackers to execute arbitrary SQL statements, leading to potential alteration or loss of critical data. Attackers could exploit the issue remotely over network-exposed ports, causing high impact to confidentiality, integrity, and availability across critical infrastructure sectors worldwide. This incident underscores the increasing risks posed by vulnerabilities in operational technology and industrial control systems. As attackers continue to target widely deployed OT/ICS solutions, organizations must accelerate patch deployment, network segmentation, and adopt hardened security practices to protect essential services and meet evolving regulatory expectations.
6 months ago
Kill Chain
Oracle WebLogic Faces Automated Exploit Attempts Targeting CVE-2026-21962
In January 2026, organizations running Oracle WebLogic servers were targeted by a suspicious HTTP exploit attempt leveraging CVE-2026-21962—a recently patched vulnerability with potential for remote code execution. A series of probing requests, traced to a Russian IP address, used manipulated HTTP headers and base64-encoded payloads aiming for potential command injection via WebLogic’s ProxyServlet endpoint. While analysis suggests some exploit attempts may have involved AI-generated slop or automated scanners, reputable sources including detection from security monitors confirmed that real threats actively pursued the vulnerability, making it a high-priority concern for unpatched WebLogic deployments. No widespread compromise has yet been reported, but exposure left unaddressed might allow threat actors illicit server access or lateral movement. This incident is significant as it highlights the rapid weaponization and opportunistic scanning of newly disclosed vulnerabilities, including the use of automated tools and potentially generative AI to accelerate exploit development. The event demonstrates the need for organizations to apply patches promptly and to monitor for unusual web request patterns immediately after vulnerability disclosures.
6 months ago
Kill Chain
Fortinet’s 2026 Zero-Day: Attackers Bypass FortiCloud SSO to Compromise Firewalls
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) affecting FortiCloud’s single sign-on authentication, enabling attackers with a FortiCloud account and a registered device to bypass authentication controls and gain privileged access to FortiGate firewalls and other products. Malicious actors leveraged the flaw in the wild, making unauthorized configuration changes, creating unauthorized accounts, and manipulating VPN settings across exposed management interfaces. Fortinet responded by disabling FortiCloud SSO, blocking the known malicious accounts, and issuing mitigations, though patches for multiple affected products remained unavailable at disclosure. This incident highlights the persistent targeting of network infrastructure devices by threat actors seeking initial access and lateral movement. With thousands of Fortinet instances exposed globally and repeated inclusion of Fortinet CVEs in known exploited vulnerabilities catalogs, organizations face increased regulatory scrutiny and pressure to rapidly address vulnerabilities affecting critical network management infrastructure.
6 months ago
Kill Chain
SolarWinds Web Help Desk Flaws: Critical RCE and Authentication Bypass in 2024
In June 2024, SolarWinds disclosed and patched multiple critical vulnerabilities in its Web Help Desk software, including an authentication bypass (CVE-2024-28995) and a remote command execution (RCE) flaw. These security issues, if left unpatched, allow attackers to compromise systems with minimal or no authentication, granting them access to execute arbitrary commands and potentially control affected servers. SolarWinds urged its customers to update immediately and disclosed that no in-the-wild exploitation had been confirmed at the time of announcement, but the severity of the flaws warranted immediate action across enterprise environments. This incident is particularly relevant due to a surge in software supply chain and IT management platform attacks, where adversaries exploit widely used admin tools to gain privileged access. Critical RCE and authentication vulnerabilities present potent risks to organizations, intensifying regulatory scrutiny and heightening the importance of timely patch management and proactive security measures.
6 months ago
Kill Chain
New Sandbox Escape Flaws in n8n Expose Instances to Remote Code Execution
In January 2026, security researchers uncovered two critical sandbox escape vulnerabilities in the popular n8n workflow automation platform, identified as CVE-2026-1470 and CVE-2026-0863. The flaws allowed authenticated users to exploit weaknesses in JavaScript and Python sandboxing mechanisms, enabling remote code execution on affected self-hosted instances. Attackers with valid user credentials could abuse these vulnerabilities to gain control of underlying systems, access sensitive data, and potentially compromise integrated services. Despite requiring authentication, the ease of privilege escalation and potential for lateral movement made these vulnerabilities highly impactful. This incident is highly significant given the large number of exposed n8n instances and the growing reliance on workflow automation by organizations worldwide. The vulnerabilities underline persistent challenges in securely sandboxing dynamic scripting languages, a common risk in platforms that allow code-based automation or AI integrations. The slow patching pace also highlights the pressing need for improved vulnerability management across self-hosted cloud infrastructure.
6 months ago
Kill Chain
FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026
In January 2026, the FBI seized control of the notorious Russian-speaking RAMP cybercrime forum, widely used by ransomware gangs to promote operations, recruit affiliates, and trade access to compromised networks. Both its Tor and clearnet domains were confiscated, and a seizure notice was displayed in coordination with U.S. law enforcement agencies. As one of the last prominent ransomware-friendly forums, RAMP had become a hub for multiple groups, facilitated by threat actor Mikhail Matveev (aka Orange/Wazawaka). The FBI now possesses potentially incriminating data on user identities, logins, and private communications, increasing the risk of arrests for those with poor operational security. This takedown reflects a broader law enforcement crackdown on cybercrime infrastructure supporting ransomware attacks. The RAMP seizure is significant amid heightened regulatory and industry focus on disrupting the ransomware ecosystem and demonstrates the ongoing risk of exposure for those operating in or near dark web forums.
6 months ago
Kill Chain
MicroWorld eScan Update Server Breach Exposes Supply Chain Risks
In June 2024, MicroWorld Technologies, developers of eScan antivirus, experienced a breach where attackers compromised one of its update servers. The intruders leveraged this access to push a malicious software update to a limited subset of customers, effectively deploying unauthorized code via the trusted antivirus delivery mechanism. MicroWorld quickly detected the incident, notified impacted users, and began forensic analysis with assistance from cybersecurity experts. The compromised update posed potential risks including malware infection and lateral network movement. This incident is part of a growing trend of supply chain attacks, where adversaries exploit trusted update channels to infiltrate enterprise environments. As organizations increasingly rely on third-party software, vigilance and layered security controls around update infrastructures have become a pressing necessity.
6 months ago
Kill Chain
Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)
In early 2026, security researchers uncovered a supply chain attack involving two malicious packages—spellcheckerpy and spellcheckpy—distributed on the popular Python Package Index (PyPI). Masquerading as legitimate spellchecking tools, these packages were downloaded over 1,000 times before removal, each covertly containing a remote access trojan (RAT). When unsuspecting developers installed the packages, attackers could gain persistent access to compromised systems, enabling data exfiltration, lateral movement, and remote command execution. No specific organizational victims were named, but the risk extended globally to Python developers and projects that leveraged these components. This incident is emblematic of the growing trend of supply chain attacks targeting open source repositories, exploiting trust in widely used ecosystems like PyPI. As software supply chains become common attack vectors, organizations face heightened pressure to vet dependencies and implement controls to prevent compromise via upstream components.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports