Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2594 threat reports
Page 133 of 217

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 15851596 / 2594 reports
2026 JavaScript Secrets Leak: Tens of Thousands of API Tokens Exposed in Production Web App Bundles
Impact· medium

2026 JavaScript Secrets Leak: Tens of Thousands of API Tokens Exposed in Production Web App Bundles

In January 2026, a sweeping automated analysis uncovered the exposure of over 42,000 sensitive API tokens—including GitHub, GitLab, Slack, Linear, and other SaaS access keys—in JavaScript bundles of live, internet-facing web applications. The research, conducted at massive scale across 5 million applications, revealed that traditional infrastructure and application security scanners consistently missed these secrets, leaving organizations exposed to repository breaches, data leaks, and system compromise. Critical tokens found enabled attackers to access private code, internal projects, downstream services, and business-critical data, demonstrating broad gaps in application supply chain controls. This incident highlights persistent shortcomings in secrets detection across the application lifecycle. As businesses accelerate cloud adoption, CI/CD automation, and shift-left security, the failure of both automated scanners and static analysis to catch secrets in deployed JavaScript highlights urgent challenges. The trend will likely intensify with rising use of contemporary development pipelines and AI-generated code.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cloudflare ACME WAF Bypass: How a 2026 Edge Vulnerability Left Origins Exposed
Impact· low

Cloudflare ACME WAF Bypass: How a 2026 Edge Vulnerability Left Origins Exposed

In January 2026, Cloudflare disclosed and remediated a critical vulnerability in its ACME (Automatic Certificate Management Environment) HTTP-01 validation process. The flaw allowed attackers to craft requests that bypassed Cloudflare's Web Application Firewall (WAF), gaining unauthorized access to protected origin servers by exploiting the path handling for ACME challenges. There is no evidence of mass exploitation, but the vulnerability exposed the underlying infrastructure to potential attacks until it was patched. Cloudflare identified, investigated, and quickly deployed a fix to mitigate further risk to its global customer base. The incident highlights the ongoing importance of robust validation logic and continuous testing in security edge infrastructure. As attackers adapt to complex cloud architectures, bypass techniques targeting certificate management or internal authentication flows are increasingly relevant for organizations using shared security platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Exposing the Hidden Threat: Orphan Accounts and the Identity Dark Matter (2026)
Impact· medium

Exposing the Hidden Threat: Orphan Accounts and the Identity Dark Matter (2026)

In January 2026, the cybersecurity community highlighted mounting risks associated with orphaned accounts—dormant but still-active identities left behind after employee turnover, organizational change, or fragmented onboarding processes. Attackers have repeatedly leveraged these unattended, often highly privileged accounts as entry points, as seen in notable breaches such as Colonial Pipeline (2021) and a 2025 ransomware attack on a manufacturing firm. These accounts evade detection and deprovisioning, undermining traditional Identity and Access Management (IAM) controls and enabling credential-based attacks that can lead to regulatory violations, operational inefficiencies, and delayed incident response. Such orphaned identities are a growing concern amid expanding use of non-human and AI-driven service accounts, especially following M&A activity. Their proliferation reflects a macro trend in attacker tactics: exploiting visibility and lifecycle gaps in identity governance—putting critical compliance frameworks and business continuity at risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chainlit AI Framework Under Fire: 2024 Vulnerabilities Expose Multicloud Risk
Impact· low

Chainlit AI Framework Under Fire: 2024 Vulnerabilities Expose Multicloud Risk

In 2024, critical vulnerabilities were uncovered in the Chainlit open-source AI chatbot framework, enabling attackers to exploit flaws in authentication and traffic encryption protections. Malicious actors could intercept unencrypted traffic, manipulate east-west communications, and abuse privileged access across multicloud deployments, potentially leading to data exfiltration or advanced lateral movement within enterprise environments. The incident highlighted how insecure defaults and lack of robust segmentation in AI frameworks expose companies to elevated risk, demanding urgent attention from organizations relying on these technologies for customer-facing or sensitive operations. This breach underscores a broader trend of threat actors targeting open-source AI platforms, taking advantage of immature security practices inherent to many machine learning deployments. As regulatory scrutiny and supply chain attacks surge, securing AI development and deployment pipelines is increasingly essential to prevent business disruption or compliance violations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
Critical RCE Flaws in Microsoft & Anthropic MCP Servers Expose AI Workloads to Cloud Takeover
Impact· low

Critical RCE Flaws in Microsoft & Anthropic MCP Servers Expose AI Workloads to Cloud Takeover

In early June 2024, researchers disclosed critical remote code execution (RCE) vulnerabilities in the Model Context Protocol (MCP) servers operated by Microsoft and Anthropic, exposing integral AI infrastructure to severe cloud takeover risks. Threat actors could leverage these flaws to execute arbitrary code and potentially gain privileged access to sensitive data or underlying cloud platforms, risking widespread lateral movement and data exfiltration. The vulnerabilities arose from insufficient encryption and a lack of east-west segmentation controls, enabling potential attackers to compromise interconnected AI workloads and services. Both vendors moved quickly to deploy patches, but the initial exposure window highlighted deep-seated risks in shared AI service architectures. This incident highlights growing adversary focus on AI model supply chains and service interconnects, with attackers exploiting new protocol vulnerabilities. Rising adoption of AI-driven services across industries has amplified attack surfaces, urging enterprises to enhance zero trust segmentation, encrypted traffic controls, and multicloud observability to meet evolving compliance and operational challenges.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Google Gemini Exploited: Calendar Invites Become AI Attack Vector in 2024
Impact· medium

Google Gemini Exploited: Calendar Invites Become AI Attack Vector in 2024

In early 2024, researchers identified a critical indirect prompt injection vulnerability affecting Google Gemini, Google's flagship AI suite. Attackers exploited calendar invites as a covert vector to manipulate Gemini's AI context, successfully bypassing native privacy filters and accessing sensitive user data. The attack leveraged the insertion of malicious prompts within innocuous-looking calendar items, which Gemini processed automatically, leading to unauthorized access and data exposure. Google responded by issuing incremental updates, but the incident highlighted inherent risks in automated AI integrations with productivity platforms reliant on user-generated content. This incident underscores the growing prevalence of AI/ML abuse through indirect attack vectors such as prompt injection. With threat actors increasingly targeting large language models in enterprise environments, security programs must rapidly adapt to cover AI-specific exposures, ensure robust segmentation, and incorporate real-time anomaly detection to defend against evolving risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Jordanian Access Broker Case Exposes Credential Sales Across 50 Enterprises
Impact· medium

Jordanian Access Broker Case Exposes Credential Sales Across 50 Enterprises

In May 2023, law enforcement identified Feras Khalil Ahmad Albashiti—a Jordanian national—operating as an initial access broker, selling unauthorized access to over 50 corporate networks via an underground cybercrime forum. Acting under the handle "r1z," Albashiti exchanged credentials for cryptocurrency on at least one occasion with an undercover officer, exposing illicit sales tied to fraud and abuse of privileged network access. Arrested in Georgia and extradited to the US in July 2024, he pleaded guilty to charges of fraud involving access credentials. Sentencing is scheduled for May 2026, with potential penalties of up to 10 years imprisonment and substantial fines. This case highlights the increasingly organized role of initial access brokers in cybercrime, where privileged access is sold to facilitate ransomware, espionage, and data theft. The incident underscores ongoing risks posed by the thriving market for stolen credentials used to compromise enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Supreme Court and Agency Data Breached via Stolen Credentials: The 2023 Instagram Leak
Impact· high

Supreme Court and Agency Data Breached via Stolen Credentials: The 2023 Instagram Leak

In late 2023, a Tennessee man illicitly accessed the U.S. Supreme Court’s restricted electronic filing system, as well as accounts at AmeriCorps and the Department of Veterans Affairs, through the repeated use of stolen credentials. Over multiple months, Nicholas Moore gained unauthorized entry to sensitive government systems at least 25 times, collecting and exfiltrating personal, legal, and health data. He then publicized this sensitive information via his Instagram handle, @ihackedthegovernment, exposing government, AmeriCorps, and veteran data, including personal identifiers and privileged health information. This case underscores a rise in breaches involving compromised credentials, lateral movement, and public boasting on social media. With persistent attacker focus on governmental targets and data exfiltration, it exemplifies the ongoing risks of inadequate east-west and data-in-transit security, as well as the compliance pressure on federal agencies to shore up access controls and insider threat monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
NexShield Fake Ad Blocker & CrashFix: 2026's Browser Extension Malware
Impact· medium

NexShield Fake Ad Blocker & CrashFix: 2026's Browser Extension Malware

In January 2026, a sophisticated malvertising campaign leveraged a fake Chrome and Edge extension named NexShield to target corporate environments. Purported as a privacy-focused ad blocker, NexShield was distributed through the Chrome Web Store and social engineering tactics. Upon installation, the extension intentionally crashed browsers and subsequently displayed fake warnings instructing users to run malicious commands in Windows Command Prompt, thereby installing ModeloRAT—a Python-based remote access tool with extensive reconnaissance and persistence capabilities. The campaign, dubbed 'CrashFix' and attributed to threat actor KongTuke, demonstrated advanced evasion techniques, delayed payload execution, and targeted both corporate and individual users. This incident exemplifies the growing threat from malicious browser extensions and evolving malvertising techniques. Security experts note a marked increase in targeted, multi-stage attacks that exploit trusted distribution channels and leverage social engineering to compromise endpoints, underlining the urgent need for robust browser extension controls and ongoing user awareness.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
StackWarp: AMD’s Hardware Flaw Exposes Confidential Cloud VMs to Attack
Impact· medium

StackWarp: AMD’s Hardware Flaw Exposes Confidential Cloud VMs to Attack

In January 2026, researchers disclosed a vulnerability called StackWarp, affecting AMD’s Zen 1 through Zen 5 processor lines, including EPYC models widely used in cloud and enterprise environments. The flaw (CVE-2025-29943) enables privileged threat actors on host servers to manipulate the stack pointer of guest memory in confidential virtual machines (CVMs) secured with AMD SEV-SNP. By exploiting a previously undocumented control bit, attackers can redirect program flow inside targeted VMs, leading to remote code execution, privilege escalation, and exposure of sensitive assets such as cryptographic keys or kernel privileges. AMD published mitigations and microcode updates in July and October 2025, with additional firmware patches pending. This incident is a compelling example of the persistent risks stemming from microarchitectural attacks bypassing virtualization and memory encryption boundaries. As supply chain, multi-tenant cloud, and confidential computing adoption increases, organizations should regularly assess hardware-layer exposures and stay current on firmware updates to limit high-impact cascades.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CrashFix Chrome Extension Attack Delivers ModeloRAT in ClickFix-Style Campaign
Impact· low

CrashFix Chrome Extension Attack Delivers ModeloRAT in ClickFix-Style Campaign

In January 2026, security researchers uncovered the 'KongTuke' campaign, which weaponized a malicious Chrome extension named CrashFix, disguised as an ad blocker. Attackers exploited a faux browser crash workflow—imitating ClickFix lures—to trick victims into running malicious commands, delivering the new ModeloRAT remote access trojan (RAT). The campaign allowed threat actors to silently gain persistent, covert access, facilitating lateral movement and potential data exfiltration within corporate environments. The incident highlights the evolving sophistication of browser-based attack chains and underscores browser extension risk as a modern threat vector for organizations reliant on SaaS and web apps. This breach is emblematic of a surge in malicious browser extensions delivering advanced malware. It showcases a growing trend toward supply chain compromise and the abuse of user trust in widely used browser platforms, calling for improved extension vetting and proactive security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
How an XSS Bug in StealC Malware Panel Unmasked Threat Actors in 2026
Impact· medium

How an XSS Bug in StealC Malware Panel Unmasked Threat Actors in 2026

In January 2026, cybersecurity researchers exploited a cross-site scripting (XSS) vulnerability in the StealC information stealer's web-based control panel. By leveraging this flaw, they monitored active threat actor sessions, collected system fingerprints, and obtained critical intelligence on StealC's illicit operations. The StealC malware, known for targeting credentials and sensitive data from infected endpoints, was actively managed via this compromised control panel by cybercriminal operators. As a result of this research, defenders gained unprecedented visibility into threat actor workflow and TTPs, turning a malicious tool’s own infrastructure against its controllers. This incident highlights the growing focus on attacking the infrastructure of threat actors themselves, signifying a shift in defensive strategies. Vulnerabilities within criminal tooling and panels can be weaponized by blue teams to gain actionable threat intelligence, reflecting broader trends in intrusion analysis and adversary disruption.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports