✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Fortinet Zero-Day SSO Bypass Targets Fully Patched Firewalls in 2026
In January 2026, Fortinet confirmed that attackers actively exploited a new authentication bypass vulnerability affecting FortiCloud SSO on fully patched FortiGate firewalls. Despite organizations applying the latest security updates, adversaries used an undisclosed flaw to circumvent authentication protections, gaining unauthorized administrative access to network infrastructure. The incidents were detected within 24 hours of the latest firmware deployment, leading to compromised management interfaces and potentially broad security implications for affected enterprises utilizing FortiCloud SSO for remote management and single sign-on. This breach underscores a persistent challenge in cloud-managed network security: even well-maintained, up-to-date systems may be vulnerable to zero-day exploits. The event highlights increased attacker focus on SSO and management plane weaknesses, as well as the importance of layered defenses, rapid detection, and coordinated response in modern enterprise security architecture.
6 months ago
Kill Chain
CISA Flags Four Actively Exploited Vulnerabilities: 2026 Software Risk Alert
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to include four new software flaws confirmed as actively exploited in the wild. Among these, CVE-2025-68645 in the Synacor Zimbra Collaboration Suite enables remote file inclusion through a PHP vulnerability, presenting severe risks of remote code execution and unauthorized access. Attackers have been leveraging these vulnerabilities to infiltrate enterprise and government infrastructures, resulting in the exposure of sensitive data and disruption of critical collaboration services. This incident exemplifies the accelerating pattern of opportunistic exploitation by cybercriminals and state-backed actors who quickly weaponize disclosed vulnerabilities. It highlights the urgent need for timely patching, robust segmentation, traffic monitoring controls, and adherence to regulatory frameworks such as HIPAA, PCI DSS, and NIST to effectively mitigate operational risk.
6 months ago
Kill Chain
How Stolen Credentials Enabled Stealthy LogMeIn RMM Attacks in 2026
In January 2026, researchers reported a campaign where attackers leveraged phishing emails to steal valid user credentials, allowing them to deploy legitimate LogMeIn Remote Monitoring and Management (RMM) software for covert, persistent access to corporate systems. By utilizing IT tools typically trusted by administrators rather than custom malware, the adversaries successfully bypassed traditional security measures and gained unrestricted access to sensitive business environments. The campaign underscores the increasing sophistication of credential-based attacks and the risks posed by the misuse of legitimate remote access tools. This incident is vital in the current cybersecurity landscape as it exemplifies the growing threat of identity-driven attacks and the exploitation of trusted IT software. Organizations face mounting regulatory and operational pressure to enforce zero trust principles and segment internal traffic, as traditional perimeter defenses and malware-centric detection are increasingly ineffective against modern attacker tactics.
6 months ago
Kill Chain
VMware vCenter Vulnerability (CVE-2024-37079) Actively Exploited—CISA Issues Immediate Directive
In January 2026, CISA added CVE-2024-37079, a critical out-of-bounds write vulnerability in Broadcom VMware vCenter Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to verified evidence of active exploitation. This flaw enables attackers to execute arbitrary code or cause denial-of-service on affected vCenter deployments, potentially leading to unauthorized access, lateral movement, or data exfiltration. The vulnerability presents a heightened risk to federal agencies and enterprises relying on VMware infrastructure, as attackers frequently target such foundational management servers. The incident underscores escalating threats against widely used virtual infrastructure platforms, with attackers exploiting newly disclosed vulnerabilities before patch adoption. CISA’s rapid update to the KEV Catalog reaffirms urgent regulatory expectations for vulnerability management and highlights the broader necessity for real-time patching and enhanced segmentation to mitigate exploitation risk.
6 months ago
Kill Chain
Kimwolf Botnet: How Residential Proxy Infections Fueled a 2025 IoT Crisis
In late 2025, the Kimwolf botnet rapidly infected over 2 million IoT devices—primarily unofficial Android TV streaming boxes—by exploiting insecure residential proxy networks, notably those operated by IPIDEA. Kimwolf used these proxies to scan and compromise additional devices on local networks, enabling attackers to conscript them for distributed denial-of-service (DDoS) attacks and other forms of malicious activity, such as ad fraud and data scraping. Investigations by Infoblox and other security firms found Kimwolf infections active across diverse industry sectors worldwide, including healthcare, finance, utilities, and notably, dozens of sensitive government networks. The Kimwolf incident highlights persistent weaknesses in IoT device security, the risks of unmanaged devices on enterprise networks, and the danger posed by residential proxy services abused for malicious purposes. As threat actors increasingly exploit lateral movement via proxy endpoints, organizations in all industries must strengthen segmentation, east-west traffic monitoring, and endpoint visibility to mitigate future outbreaks.
6 months ago
Kill Chain
Fortinet Firewalls Compromised: 2024 Malicious Configuration Attack Exposes Networks
In early 2024, threat actors exploited unpatched and even fully patched Fortinet FortiGate firewalls, deploying malicious automation to illicitly access and exfiltrate firewall configuration files. Attackers leveraged vulnerabilities or misconfigurations to automate the compromise of a significant number of devices globally, granting them access to sensitive internal network details, VPN credentials, and administrative information. The targeted manipulation of device configurations allowed for persistent access and posed a risk of lateral movement deeper into enterprise environments. Impacted organizations faced potential exposure of encrypted traffic configurations and gateway policies, undermining both security posture and compliance. This incident is especially relevant as network infrastructure compromises grow more frequent and sophisticated, with attackers rapidly shifting tactics to automate attacks and bypass traditional perimeter defenses. The breach highlights the ongoing challenges organizations face in protecting network infrastructure against highly motivated and well-resourced threat actors.
6 months ago
Kill Chain
AI Agents Breach Simulated Enterprise via Open-Source Tools: Claude Sonnet 4.5 Equifax-Style Attack
In January 2026, researchers demonstrated that the latest Anthropic Claude Sonnet 4.5 AI model could autonomously breach simulated enterprise networks using only standard, open-source tools without custom malware or frameworks. During testing, the AI model rapidly identified and exploited an unpatched, publicized vulnerability to exfiltrate sensitive (simulated) personal data, mimicking tactics similar to the original Equifax breach. This exercise revealed how advanced AI agents now lower the technical barriers for rapid, multistage cyberattacks, enabling them to recognize and exploit vulnerabilities far faster than manual attackers. This incident underscores the accelerating risk posed by AI-powered offensive cyber capabilities. The proliferation of autonomous cyber agents marks a turning point, driving urgent regulatory, corporate, and operational focus on timely patch management, zero trust architectures, and advanced detection to stay ahead of next-generation threats.
6 months ago
Kill Chain
Russian Ransomware Leader Brought to Justice: Lessons from the Antropenko Case
Between 2018 and August 2022, Ianis Aleksandrovich Antropenko led a prolific ransomware operation targeting at least 50 victims across various sectors, causing losses exceeding $1.5 million. Operating from both Russia and later the United States, Antropenko leveraged variants like Zeppelin and GlobeImposter, coordinating with co-conspirators—including his ex-wife—to deploy ransomware, extort victims, and launder proceeds through a network of global accounts and crypto wallets. His arrest and subsequent guilty plea follow a multi-year investigation by U.S. federal authorities, resulting in the seizure of more than $3 million in assets. This case highlights the growing trend of ransomware group leaders operating internationally and even within U.S. borders, challenging traditional law enforcement approaches. It underscores persistent ransomware risk, ongoing challenges in detecting coordinated laundering activity, and the critical need for comprehensive security controls and compliance vigilance.
6 months ago
Kill Chain
Fortinet 2026 Breach: Authentication Bypass Leads to Firewall Configuration Theft
In January 2026, Fortinet FortiGate devices became the target of a coordinated cyberattack exploiting an authentication bypass vulnerability (CVE-2025-59718) associated with the FortiCloud SSO feature. Attackers accessed vulnerable firewalls, created rogue administrative accounts, and swiftly exfiltrated firewall configuration data using automated tools, demonstrating significant threat actor sophistication. Reports indicated the campaign began on January 15, 2026, and quickly escalated as even patched devices were compromised—suggesting a patch bypass or incomplete remediation. Affected organizations faced exposure of sensitive security configurations and heightened risk of follow-on breaches or lateral movement within their networks. This incident spotlights the urgent challenges posed by cloud-exposed assets and incomplete vulnerability remediation. It emphasizes the criticality of rapid patch cycles, zero trust principles, and robust monitoring amid a trend of identity and configuration–focused attacks targeting enterprise infrastructure platforms.
6 months ago
Kill Chain
Okta SSO Targeted: 2024 Vishing Surge Exposes Credential Gaps
In early 2024, Okta Single Sign-On (SSO) user accounts became the target of sophisticated phishing campaigns leveraging custom voice-based social engineering (vishing) kits. Threat actors contacted employees via phone calls, impersonating IT staff and using convincing pretexts to direct users to phishing sites tailored to mimic Okta’s authentication workflow. By capturing the credentials and multi-factor authentication (MFA) tokens, attackers accessed sensitive enterprise environments, leading to data exfiltration, disruption of operations, and potential exposure of downstream customers relying on Okta SSO for access control. This incident highlights a broader escalation in the use of vishing tactics to bypass strong authentication, underscoring the ongoing shift toward highly targeted, voice-enabled phishing attacks. Enterprises must adapt security and training programs to confront increasingly sophisticated social engineering methods targeting identity infrastructures.
6 months ago
Kill Chain
INC Ransomware OpSec Fail Uncovers Data from 12 U.S. Organizations
In January 2026, an operational security lapse in the INC ransomware group's infrastructure enabled Cyber Centaurs researchers to recover encrypted data exfiltrated from twelve U.S. organizations. The investigation began after a RainINC ransomware attack on a client’s production SQL Server. Forensic analysis traced renamed binaries, PowerShell scripts, and usage of the Restic backup tool, revealing attacker scripts with hardcoded credentials and references to persistent cloud storage. By enumerating the attacker-controlled repositories, researchers identified encrypted data from healthcare, manufacturing, technology, and services firms, then decrypted and preserved it in coordination with law enforcement. This case highlights a rare opportunity where attacker mistakes allowed post-breach data retrieval for unrelated victim organizations. The incident underscores a growing trend in ransomware operations leveraging legitimate backup and exfiltration tools, persistent attacker infrastructure, and the importance of thorough incident response for uncovering wider impacts.
6 months ago
Kill Chain
SmarterMail Auth Bypass Allows Attackers to Reset Admin Accounts in Live Exploits
In January 2026, attackers began exploiting an authentication bypass vulnerability in SmarterTools’ SmarterMail email server platform, which enabled unauthenticated users to reset admin account passwords and seize full system control. The flaw, residing in a publicly-exposed API endpoint allowing forced resets with attacker-supplied JSON, let threat actors escalate privileges by resetting admin credentials, paving the way to remote code execution. The vulnerability was disclosed in early January, patched on January 15, and observed in active exploitation just days later as attackers reverse-engineered the fix to target unpatched servers globally. This incident draws attention to the criticality of prompt patch management and highlights the ongoing risk of API flaws being rapidly weaponized post-disclosure. It underscores a broader trend of attackers targeting authentication controls in business-critical SaaS and infrastructure applications, raising regulatory and operational pressure for stronger access security and rapid response procedures.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports