Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2600 threat reports
Page 143 of 217

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 17051716 / 2600 reports
MongoBleed: Active Exploitation of MongoDB Memory Leak Puts Credentials at Risk in 2024
Impact· medium

MongoBleed: Active Exploitation of MongoDB Memory Leak Puts Credentials at Risk in 2024

In June 2024, a critical vulnerability nicknamed "MongoBleed" was discovered in MongoDB, exposing servers to a memory leak flaw that enables unauthenticated attackers to extract sensitive data such as passwords and authentication tokens. Threat actors are actively exploiting the flaw by sending specially crafted requests to exposed MongoDB endpoints, resulting in chunks of memory—including user credentials and potentially session information—being sent in response. Organizations running unpatched MongoDB instances faced increased risk of credential theft, lateral movement, and potential data breaches, with attacks escalating once public proof-of-concept exploits were released. The MongoBleed incident highlights a surge in opportunistic attacks against cloud-managed databases and underscores the crucial need for rapid patch deployment. The attack's simplicity, combined with the prevalence of cloud-exposed databases in hybrid environments, makes this vulnerability especially relevant as organizations transition to zero-trust and improved segmentation to defend against credential harvesting and related threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Corporate Cloud File-Sharing Sites Targeted in Major Zestix Data Theft (2024)
Impact· high

Corporate Cloud File-Sharing Sites Targeted in Major Zestix Data Theft (2024)

In early 2024, a threat actor identified as Zestix orchestrated a widespread campaign targeting corporate instances of popular cloud file-sharing services, including ShareFile, Nextcloud, and OwnCloud. By exploiting vulnerable configurations and access controls, Zestix infiltrated dozens of organizations, exfiltrating sensitive corporate data and offering it for sale on underground forums. Attackers leveraged cloud-native techniques to blend in with legitimate traffic, complicating detection and response efforts. The incident has resulted in operational disruption for several affected companies and increased scrutiny over cloud data management strategies. This breach highlights the growing sophistication of cybercriminals in targeting SaaS-based collaboration platforms, exploiting the accelerated shift to cloud storage. As data sovereignty and regulatory demands intensify, organizations must urgently address evolving cloud security gaps to counter both traditional and cloud-native threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Inside the ClickFix Hospitality Attack: How Fake BSOD Screens Delivered Malware in Europe
Impact· medium

Inside the ClickFix Hospitality Attack: How Fake BSOD Screens Delivered Malware in Europe

In early 2024, a social engineering campaign dubbed 'ClickFix' targeted hospitality sector organizations across Europe by deploying convincing fake Windows Blue Screen of Death (BSOD) screens. Threat actors lured hotel staff into believing their systems were compromised, instructing them to download and execute what appeared to be legitimate fixes. Instead, victims manually compiled and ran malware, granting attackers access to sensitive information and operational networks. The campaign highlights how attackers combine psychological manipulation with technical tactics to bypass traditional security and leverage low-privilege endpoints for initial access, risking data loss and downstream attacks on partners. This incident signals a shift toward increasingly sophisticated social engineering and blended attack methods targeting industries with high customer throughput. As phishing tactics evolve, organizations must bolster employee awareness and deploy proactive threat detection to counter these multifaceted threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
27 Malicious npm Packages Turn Dev Ecosystem Into Phishing Playground in 2025
Impact· medium

27 Malicious npm Packages Turn Dev Ecosystem Into Phishing Playground in 2025

In late 2025, security researchers uncovered a sophisticated supply chain attack leveraging the npm package ecosystem to execute a targeted spear-phishing campaign. Over a five-month period, attackers published 27 malicious npm packages via six aliases, using content delivery networks to host and serve browser-based phishing lures. These lures mimicked document-sharing and Microsoft sign-in portals to trick targeted sales and commercial staff at 25 organizations across manufacturing, industrial automation, healthcare, and allied sectors in the US and Europe. The campaign incorporated advanced anti-analysis checks, obfuscated JavaScript, and honeypot detection to evade security tooling, with hardcoded targets likely sourced from trade show and open-sourced company data. This incident exemplifies the growing abuse of public developer ecosystems and infrastructure in credential theft operations, highlighting an urgent need for organizations to monitor software supply chains and enforce modern, phishing-resistant controls. Attackers' use of legitimate distribution services as resilient hosting and focus on regional, non-IT staff illustrate shifting tactics in supply chain and social engineering threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026
Impact· medium

Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026

In early January 2026, it was revealed that over 10,000 Fortinet FortiGate firewalls remain exposed to a critical authentication bypass vulnerability (CVE-2020-12812) first patched by Fortinet in July 2020. Attackers exploit this flaw by manipulating username case sensitivity to bypass two-factor authentication (2FA) on SSL VPNs—allowing unauthorized access to devices with unpatched software and certain LDAP configurations. Despite years of vendor and government warnings, more than 1,300 vulnerable systems in the United States alone are still online, placing organizations at ongoing risk of compromise. The persistence of this five-year-old flaw’s exploitation highlights chronic issues in vulnerability management and patch adoption within network infrastructure. Active targeting by both cybercriminal and state-backed actors, combined with evidence of ransomware deployment, underscores the need for continuous configuration hardening, zero trust adoption, and rapid remediation of exposed security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack
Impact· medium

Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack

In early 2026, a sophisticated phishing campaign was uncovered in which cybercriminals leveraged Google Cloud’s Application Integration service to send deceptive emails that mimicked legitimate Google communications. By exploiting the inherent trust in Google’s cloud infrastructure, attackers generated emails from authentic Google addresses, increasing the likelihood of victims engaging with malicious links or sharing sensitive information. According to Check Point researchers, this multi-stage approach enabled attackers to bypass traditional email security measures, posing significant risks to organizations that rely heavily on cloud-based productivity suites for daily operations. This campaign highlights an emerging trend in the abuse of trusted SaaS and cloud platforms for targeted phishing attacks. As adversaries shift toward cloud-native TTPs and social engineering techniques, organizations must enhance detection, improve user awareness, and adapt inline controls to mitigate risks tied to trusted service abuse.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IBM API Connect Critical Authentication Bypass (2025): What You Must Know
Impact· low

IBM API Connect Critical Authentication Bypass (2025): What You Must Know

In December 2025, IBM disclosed a critical security vulnerability (CVE-2025-13915) in its API Connect platform, rated 9.8 on the CVSS scale. The flaw allowed remote attackers to bypass authentication mechanisms and gain unauthorized access to exposed applications. Exploitation could enable attackers to manipulate sensitive workloads, extract confidential data, or pivot deeper into network environments. The incident highlighted how a simple authentication bypass in widely deployed enterprise middleware presents major risks for organizations relying on API-enabled digital ecosystems. This breach underscores the escalating sophistication of identity-focused attacks and the necessity for robust authentication and segmentation controls. With API-driven architectures proliferating in nearly every sector, such vulnerabilities are increasingly targeted; urgency is amplified by regulatory pressure and the rising adoption of zero trust frameworks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
478,000 Patients Impacted: Covenant Health Suffers Major Qilin Ransomware Breach in 2025
Impact· high

478,000 Patients Impacted: Covenant Health Suffers Major Qilin Ransomware Breach in 2025

In May 2025, Covenant Health, a prominent Catholic healthcare provider in New England and Pennsylvania, experienced a significant ransomware attack by the Qilin group. The attackers breached the organization's systems on May 18, exfiltrated approximately 852GB of sensitive data—including names, addresses, social security numbers, medical records, and health insurance information—and subsequently encrypted essential files. Discovery of the breach occurred on May 26, with the scale initially underestimated, before forensic analysis revealed that nearly 478,000 patients were affected. The organization launched a comprehensive investigation, secured its systems, and is offering 12 months of free identity protection to impacted individuals. This breach highlights the continued targeting of healthcare organizations by sophisticated ransomware groups seeking to exploit large troves of sensitive personal and medical data. With ransomware tactics evolving and threat actors increasingly publishing stolen data for extortion, robust data protection and incident response have become critical priorities for healthcare providers.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative
Impact· high

2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative

In early 2025, a sophisticated multi-vector cyberattack struck a leading multinational cloud services provider. Threat actors leveraged a combination of zero-day exploits, lateral movement, and exploited east-west traffic weaknesses to progressively compromise internal workloads across hybrid and multicloud environments. Utilizing encrypted channels, they evaded detection and ultimately deployed pervasive ransomware, resulting in widespread data exfiltration, service disruptions, and significant financial and reputational damage. Despite existing controls, gaps in segmentation and egress policy enforcement were exploited, with the incident exposing vulnerabilities in both cloud-native and on-premise environments. This breach highlights an escalating trend: attackers using complex, multi-stage TTPs that blend cloud-native exploits with traditional ransomware vectors. Security leaders must prioritize zero trust segmentation, real-time east-west inspection, and enforceable multicloud security controls to address rapidly evolving threat landscapes.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
RondoDox Botnet Weaponizes Critical React2Shell Flaw: Lessons from a Global IoT Hijack
Impact· high

RondoDox Botnet Weaponizes Critical React2Shell Flaw: Lessons from a Global IoT Hijack

From March to December 2025, the RondoDox botnet orchestrated a widespread campaign by exploiting the critical React2Shell (CVE-2025-55182) vulnerability to compromise over 90,000 Internet of Things (IoT) devices and web servers globally, with a major concentration in the U.S. Attackers conducted phased operations, ranging from reconnaissance and mass scanning to the automated deployment of advanced Mirai-based payloads and cryptocurrency miners. Capable of remote code execution, RondoDox’s malware loader established persistence, eliminated rival threats, and enabled command-and-control operations for further lateral movement and resource hijacking. This breach highlights an alarming trend of botnets swiftly weaponizing zero-day vulnerabilities in widely used frameworks like React and Next.js, amplifying both organizational and regulatory risk across hybrid and IoT environments. Growing sophistication in persistence mechanisms and targeted east-west attacks underscores the urgent need for robust segmentation, continuous monitoring, and zero trust advances.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
GhostAd Drain 2026: How Multi-Vector Malware and Botnets Are Redefining Cyber Risk
Impact· medium

GhostAd Drain 2026: How Multi-Vector Malware and Botnets Are Redefining Cyber Risk

In early January 2026, a sophisticated cyber campaign dubbed "GhostAd Drain" targeted organizations across multiple sectors with a blend of malware, proxy botnets, and cloud service exploits. Attackers deployed malicious payloads primarily via phishing emails and poisoned advertisements, leveraging advanced evasion tactics such as encrypted east-west traffic, dynamic segmentation bypass, and multicloud movement. The campaign quickly compromised endpoint devices—including macOS systems—establishing proxy botnets for command-and-control while siphoning sensitive data through encrypted channels. As a result, affected organizations faced operational disruptions, data exfiltration, and heightened recovery costs. This incident underscores a marked escalation in threat actor capability, blending classic malware with adaptive, multi-vector Tactics, Techniques, and Procedures (TTPs) to evade traditional controls. The campaign’s success highlights the pressing need for organizations to adopt zero trust segmentation, enhance multicloud visibility, and enforce robust east-west traffic controls to mitigate modern, polymorphic attack patterns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign
Impact· low

Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign

In April and May 2024, thousands of organizations worldwide were compromised after a Chinese state-sponsored advanced persistent threat (APT) group exploited multiple previously unknown zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) platform. The attackers used these flaws as entry points to gain administrative control, move laterally, and deploy persistent malware, leading to widespread data exfiltration and operational disruption. The campaign targeted government, critical infrastructure, and private sector entities, exploiting unpatched systems at scale before public disclosure, prompting rapid security advisories and emergency patching. This Ivanti EPMM incident underscores the growing sophistication of nation-state campaigns leveraging zero-day vulnerabilities for large-scale compromise. It highlights the urgent industry need for rigorous vulnerability management, zero trust architectures, and rapid detection in light of escalating APT tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports