✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Gootloader’s Stealth Upgrade: 1,000-Part ZIP Exploit Bypasses Detection in 2026
In January 2026, the Gootloader malware loader resurfaced with advanced evasion techniques, deploying highly obfuscated, malformed ZIP archives containing JScript payloads. By concatenating up to 1,000 archive parts and leveraging ZIP format irregularities, attackers successfully bypassed many security tools, causing them to crash or miss the threat. These ZIPs are unpackable by Windows' default utility but break common tools like 7-Zip and WinRAR. Once delivered via a decoded, XOR-encoded blob, the JScript establishes persistence through .LNK shortcuts and triggers PowerShell-based execution chains, facilitating initial access for ransomware and other malware campaigns. This incident highlights a shift toward highly customized, anti-analysis delivery methods and demonstrates how common file formats can be manipulated to evade detection. With Gootloader back in circulation, organizations face renewed threats from sophisticated malware loaders that exploit endpoint tool weaknesses and static signature limitations.
6 months ago
Kill Chain
Palo Alto Networks GlobalProtect DoS Flaw in 2026: What CISOs Need to Know
In January 2026, Palo Alto Networks disclosed a high-severity vulnerability (CVE-2026-0227, CVSS 7.7) in its GlobalProtect Gateway and Portal services for PAN-OS, exposing organizations to unauthenticated denial-of-service (DoS) attacks. The flaw, an improper handling of exceptional conditions, enables remote attackers to crash affected firewalls and force them into maintenance mode, disrupting business-critical network operations. Vulnerable PAN-OS versions include 12.1, 11.2, 11.1, 10.2, and 10.1, as well as Prisma Access 10.2/11.2 with GlobalProtect enabled. No workarounds are available, and Palo Alto released urgent patches following responsible disclosure by an external researcher. While exploitation in the wild wasn't confirmed at disclosure, ongoing threat actor scanning against GlobalProtect instances was reported in prior months. This vulnerability reinforces the ongoing risk to critical network infrastructure posed by service exposure and unauthenticated access paths. The incident follows a trend of increased attacks targeting VPN and remote access solutions as part of broader DoS and ransomware campaigns, placing heightened pressure on organizations to patch exposed perimeter devices rapidly.
6 months ago
Kill Chain
Microsoft & Law Enforcement Dismantle RedVDS Cybercrime Platform in 2026
In January 2026, Microsoft, in collaboration with U.S. and U.K. law enforcement, disrupted the RedVDS cybercrime infrastructure, dismantling a crimeware-as-a-service network that fueled millions in global fraud losses. Managed by the threat actor Storm-2470, RedVDS offered inexpensive, disposable Windows-based RDP servers with no logging, enabling cybercriminals to conduct mass phishing, business email compromise (BEC) schemes, account takeovers, and other online fraud at scale. RedVDS’s infrastructure was critical in facilitating over $40 million in reported fraud losses in the U.S. since March 2025, impacting at least 191,000 organizations across sectors like healthcare, legal, finance, manufacturing, and real estate. The incident underscores the rapidly growing risk posed by cybercrime subscription models that democratize access to sophisticated attack tools. As CaaS platforms pair with generative AI, threat actors are increasingly able to automate and scale targeted campaigns, elevating both regulatory risk and enterprise exposure across all industries.
6 months ago
Kill Chain
Reprompt Attack on Microsoft Copilot Unlocks Single-Click Data Exfiltration
In January 2026, cybersecurity researchers discovered a novel attack technique, dubbed 'Reprompt,' targeting Microsoft Copilot and similar enterprise AI chatbots. This method leverages legitimate Microsoft links requiring only a single user click to trigger silent, one-click exfiltration of sensitive corporate data – all while circumventing standard enterprise security controls. The attack exploits weaknesses in how Copilot processes prompts and allows threat actors to quickly access confidential information without needing additional malware or user authentication bypasses. This incident highlights the increasing risk posed by attacks on generative AI systems within enterprise environments. As the adoption of LLM-powered assistants accelerates, organizations must remain vigilant against rapidly evolving prompt-injection threats, and are under new regulatory, compliance, and reputational pressures to secure data in AI workflows.
6 months ago
Kill Chain
Salt Typhoon Exploits Redis Unauthenticated RCE: 2026 Lessons for Zero Trust
In early January 2026, a critical security flaw was discovered in Redis servers that allowed unauthenticated remote code execution (RCE). Exploited by a new threat group dubbed Salt Typhoon, the attackers leveraged unencrypted traffic and lack of east-west network controls to gain foothold via exposed Redis instances. The operation enabled lateral movement within affected organizations’ environments, resulting in rapid credential access and potential data exfiltration. Numerous enterprises faced service disruptions and urgent patching efforts, as exploitation spread quickly amidst widespread cloud and on-prem deployments. This incident highlights the resurgence of unauthenticated RCE exploits targeting core data store infrastructure, particularly where zero trust segmentation and encrypted traffic policies are not rigorously applied. Growing attacker interest in lateral movement, compounded by hybrid cloud complexity, has made traditional perimeter defenses insufficient.
6 months ago
Kill Chain
Chrome AI Extensions Breach: 900,000 Users’ Chat Data Stolen Through Infostealer Malware
In January 2026, two widely used Chrome extensions marketed as AI workflow assistants were discovered stealing ChatGPT and DeepSeek chat data from over 900,000 users. Threat actors leveraged the popularity of generative AI tools, distributing the malicious extensions through official and third-party repositories. Once installed, these extensions exfiltrated sensitive conversations and user data by intercepting traffic and bypassing standard browser security controls. The incident revealed significant vulnerabilities in the supply chain of browser add-ons and highlighted the ease with which infostealers can abuse trust in AI-powered productivity tools. Organizations and individuals relying on browser-based AI helpers were left exposed, with the compromised data raising regulatory and reputational concerns. This breach underscores a growing trend where attackers target the workflows and integrations surrounding AI, rather than the AI models themselves. The rise in infostealers embedded within productivity tools calls for urgent improvements to extension vetting, zero trust segmentation, and East-West traffic security.
6 months ago
Kill Chain
AWS CodeBuild Misconfiguration Put GitHub Supply Chain at Risk in 2025
In September 2025, a critical misconfiguration in AWS CodeBuild was discovered by cloud security firm Wiz, potentially allowing attackers to gain full control over AWS's own public GitHub repositories, including the widely-used AWS JavaScript SDK. This vulnerability, dubbed 'CodeBreach,' arose when certain IAM roles in CodeBuild pipelines were over-privileged and could access connected GitHub repository OAuth tokens without sufficiently restrictive permissions. If exploited, an attacker could have injected malicious code into key software supply chains, jeopardizing thousands of AWS customer environments globally. AWS promptly remediated the flaw following responsible disclosure, averting a major breach. This incident highlights the persistent risks posed by cloud misconfigurations and the growing focus of attackers on software supply chains. With rapid cloud adoption, organizations must remain vigilant to configuration drift and privilege escalation risks inherent in third-party integration, especially as regulatory scrutiny and supply chain attacks continue to escalate.
6 months ago
Kill Chain
Lumma Stealer 2026: Persistent Infostealer Escalates C2 Traffic Through Scheduled Tasks
In January 2026, an ongoing wave of Lumma Stealer infections demonstrated a distinctive post-infection pattern on Windows hosts. After initial data exfiltration, compromised machines retrieved a malicious PowerShell payload from Pastebin, which led to repeated execution of mshta commands against a .cc command and control (C2) domain—fileless-market[.]cc. The malware automatically created dozens of scheduled tasks, each triggering outbound HTTPS connections to the C2 infrastructure over many hours, elevating the risk of persistent infiltration and extended data leakage. This approach resulted in a marked increase in C2 traffic and operational risk for affected organizations. This case is relevant now as it highlights a trend of increasingly persistent infostealer operations leveraging fileless persistence, public paste sites, and escalated task creation for resilience. Security teams must be alert to novel automation and scripting techniques that facilitate stealthy C2 traffic and recurring infections, especially as infostealers like Lumma gain popularity in the cybercriminal ecosystem.
6 months ago
Kill Chain
2024 Outlaw Botnet: Cryptojacking Breach Exposes SSH Weaknesses
In early 2024, a DShield honeypot operated as part of the SANS.edu BACS program detected a sophisticated cryptojacking and botnet campaign leveraging SSH password spraying as the initial access vector. Attackers, suspected to be affiliated with the Outlaw cybercrime group, gained access to exposed Linux hosts and executed automated enumeration scripts to assess system viability for botnet or cryptomining operations. Subsequently, evidence of persistent SSH backdoors and the transfer of malware—identified as both a Trojan and a miner—was observed, suggesting the compromised servers were targeted for both resource abuse and brokering to other cybercriminals for further exploitation. This incident highlights the ongoing trend of cybercrime groups specializing in initial access brokerage and automation of lateral compromise using credential attacks and script-based post-exploitation. Organizations should remain vigilant as password-based SSH, exposed management interfaces, and unmonitored east-west traffic continue to enable rapid propagation of botnets focused on monetizing vulnerable cloud and on-prem workloads.
6 months ago
Kill Chain
Remote Hacking of WHILL Wheelchairs: Unsecured Bluetooth Puts Patient Safety at Risk
In January 2026, cybersecurity researchers revealed significant security flaws in WHILL's electric wheelchairs, which allowed attackers within Bluetooth range to remotely pair with the device due to the absence of authentication controls. This flaw enabled malicious actors to take control of the wheelchair, manipulating its movement, speed settings, and configuration profiles without requiring any credentials or user interaction. CISA subsequently issued an advisory highlighting the risk, underscoring that such vulnerabilities could result in dangerous, unauthorized maneuvers or override critical safety restrictions, potentially jeopardizing user safety and privacy. This incident exemplifies the escalating risk represented by insecure IoT medical devices, especially those operating in public or semi-public settings. With threat actors increasingly targeting Bluetooth-enabled endpoints and the medical IoT landscape expanding rapidly, similar vulnerabilities are likely to be discovered in other transportation and assistive devices, putting regulatory and patient pressures on device manufacturers and healthcare providers.
6 months ago
Kill Chain
2026 n8n Remote Code Execution Exposes Supply-Chain Security Gaps
In January 2026, a critical supply-chain vulnerability (CVE-2026-21858, CVSS 10.0) was disclosed in n8n, a widely used open-source workflow automation tool. This unauthenticated remote code execution flaw enables attackers to fully compromise vulnerable self-hosted instances, potentially taking control of exposed servers across an estimated 100,000 global installations. The vulnerability is present in n8n versions between 1.65.0 and 1.120.4. No official mitigations or workarounds exist; remediation requires upgrading to version 1.121.0 or later. Attackers exploiting this bug could gain persistent access, manipulate workflows, or use impacted servers for further lateral movement and supply-chain attacks. This incident highlights a growing trend of attackers targeting automation and orchestration platforms as initial entry points. The rapid exploitation window, lack of mitigations, and broad exposure emphasize the urgent need for organizations to prioritize patching and review their supply-chain and workflow application security.
6 months ago
Kill Chain
Monroe University 2024 Breach: 320,000 Impacted by Massive Data Exposure
In December 2024, Monroe University suffered a significant data breach during which threat actors gained unauthorized access to the institution's network for two weeks, from December 9 to December 23. Attackers exfiltrated sensitive personal, financial, and health information belonging to over 320,000 individuals—including faculty, students, and affiliates—after penetrating university systems. The breach, discovered after a review of stolen files in September 2025, exposed details such as names, Social Security numbers, medical and health insurance information, government IDs, and financial credentials, prompting the university to notify affected individuals and offer credit monitoring services. This incident underscores the persistent challenges higher education institutions face in defending against data theft, especially as ransomware and targeted attacks exploit legacy systems and limited segmentation. With higher ed continuing to be a lucrative target and similar breaches on the rise, Monroe’s experience highlights the critical need for enhanced east-west security, proactive monitoring, and compliance controls to protect sensitive student and institutional data.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports