✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
MongoBleed 2025: Critical MongoDB Vulnerability Exposes Data on 87K Servers
In early June 2025, the MongoBleed vulnerability (CVE-2025-14847) was actively exploited against MongoDB servers worldwide, exposing sensitive database secrets and credentials on over 87,000 publicly accessible systems. Attackers exploited a flaw present in multiple MongoDB versions, allowing unauthorized access to in-transit data and internal database secrets without authentication. The exposure occurred as a result of inadequate encryption and misconfiguration, providing an entry point for lateral movement, data exfiltration, and potentially further compromise of enterprise networks. Organizations in finance, healthcare, SaaS, and retail sectors have been especially impacted by this incident, given their widespread MongoDB adoption for critical workloads. This breach highlights an increasingly common pattern of weaponizing newly disclosed database vulnerabilities at scale by sophisticated threat actors. The incident underscores the urgent need for robust encryption practices, Zero Trust segmentation, and vigilant patch management to protect highly sensitive data and prevent large-scale exposure as regulatory scrutiny and attacker sophistication intensify.
6 months ago
Kill Chain
CISA Alerts: Digiever NVR Botnet Exploitation via CVE-2023-52163
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited vulnerability (CVE-2023-52163, CVSS 8.8) in Digiever DS-2105 Pro network video recorders. Attackers exploited a missing authorization flaw to perform remote code execution via command injection, requiring authentication. Security researchers confirmed that this vulnerability enabled the deployment of IoT botnets such as Mirai and ShadowV2, allowing attackers to gain persistent control and leverage compromised devices for further attacks. The product’s end-of-life status means no patch is available, compounding organizational risk for operators of affected models. This incident is part of a broader trend of threat actors targeting unpatched and unsupported IoT devices for malware delivery and botnet growth. With critical infrastructure and surveillance systems at risk, timely mitigation is paramount amid surging exploitation and regulatory pressure for proactive defense.
6 months ago
Kill Chain
Active Exploitation of Fortinet SSL VPN 2FA Bypass Shows Criticality of Patch Hygiene
In December 2025, Fortinet disclosed ongoing, active exploitation of a previously known vulnerability (CVE-2020-12812) affecting FortiOS SSL VPN devices. The flaw allows attackers to bypass two-factor authentication (2FA) by manipulating the case sensitivity of usernames when certain configurations are in place, specifically when integrating local users with LDAP groups. This misconfiguration enables unauthorized access for administrative and VPN users, as attackers can skip required 2FA checks and authenticate directly via LDAP. The vulnerability, originally patched in 2020, has resurfaced due to a large number of unpatched and exposed Fortinet devices, with over 9,700 instances still vulnerable worldwide as of January 2026. This incident exemplifies the persistent risk of legacy vulnerabilities, particularly in Internet-facing VPN and perimeter security devices. Attackers are increasingly revisiting older weaknesses to target unpatched infrastructure, elevating the urgency for ongoing patch management and configuration reviews in enterprise environments.
6 months ago
Kill Chain
Critical Vulnerability in LangChain Core Exposes Secrets and Enables Prompt Injection
In December 2025, a critical vulnerability was disclosed in LangChain Core, a widely used Python package within the LangChain open-source ecosystem. Attackers were able to exploit a flaw in the serialization process, resulting in exposure of sensitive secrets and the ability to manipulate large language model (LLM) responses via prompt injection. The underlying vulnerability allowed threat actors to craft malicious payloads, leading to remote code execution in environments where untrusted input could be serialized, posing major risks to organizations relying on LangChain-powered AI workflows. This supply-chain attack path also opened the door for access to credentials and proprietary data. This incident highlights the expanding threat landscape targeting AI infrastructure and software supply chains. With the surge of enterprise adoption of AI and LLMs, vulnerabilities in core AI frameworks are increasingly attractive to threat actors, underscoring regulatory scrutiny and the need for robust code security practices within open-source dependencies.
6 months ago
Kill Chain
Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats
In December 2025, a critical security flaw (CVE-2025-14847) was publicly disclosed in multiple versions of MongoDB, exposing organizations to the risk of uninitialized memory disclosure by unauthenticated attackers. The flaw stems from improper handling of length parameter inconsistencies within zlib compressed protocol headers, allowing remote, unauthenticated clients to read uninitialized heap memory. Impacted versions span major MongoDB releases 3.6 through 8.2, potentially exposing sensitive data in server memory. MongoDB responded by releasing patches and advised urgent upgrades or the disabling of zlib compression. This incident gains heightened significance as memory disclosure vulnerabilities enable threat actors to harvest sensitive information without authentication. The vulnerability underscores the increasing importance of rigorous software supply chain security and timely patch management amid a growing landscape of data exposure risks in widely used open-source technologies.
6 months ago
Kill Chain
Typosquatted MAS Domain Delivers PowerShell Malware in 2024 Attack
In early 2024, cybersecurity researchers identified a campaign leveraging a typosquatted domain mimicking the legitimate Microsoft Activation Scripts (MAS) tool to distribute the 'Cosmali Loader' malware. Unsuspecting users seeking MAS utilities were tricked into downloading malicious PowerShell scripts, which silently loaded the Cosmali Loader onto Windows machines. The loader subsequently enabled additional payload delivery, providing attackers with persistent access and the ability to deploy further malware or conduct post-infection activities. The incident demonstrates the ongoing risks of social engineering via typosquatting and open-source tool impersonation, with users and organizations inadvertently compromising their systems. This campaign is particularly relevant as it highlights the resurgence of supply chain threats and the increasing sophistication of threat actors leveraging typosquatted domains to bypass conventional defenses. The incident signals a growing trend targeting both individual users and enterprise environments through deceptive domains and script-based malware.
6 months ago
Kill Chain
MacSync Stealer 2025: Notarized macOS Malware Defeats Gatekeeper Protections
In June 2025, security researchers uncovered a new campaign leveraging a variant of the MacSync information stealer, which specifically targets macOS devices. In this incident, attackers distributed malware using a digitally signed and Apple-notarized Swift-based application disguised as a messaging app installer. This approach allowed the threat to bypass Apple Gatekeeper security controls designed to prevent unauthorized software execution. Once executed, the stealer harvested sensitive user data—such as browser credentials, wallets, and system information—and exfiltrated it to remote attacker-controlled servers, posing significant operational and reputational risks to affected organizations and users. This incident highlights a growing trend wherein adversaries employ legitimate-looking, signed applications to circumvent platform defenses. With an uptick in sophisticated macOS attacks and abuse of code-signing, organizations need to bolster defenses and maintain heightened vigilance for notarized application threats in enterprise environments.
6 months ago
Kill Chain
WebRAT Infostealer Abuses GitHub: 2024 Supply Chain Attack Exposed
In June 2024, cybersecurity researchers observed a campaign distributing the WebRAT infostealer through malicious GitHub repositories. Threat actors uploaded repositories pretending to offer proof-of-concept exploits for recent vulnerabilities, luring security professionals and researchers to download and execute the malware. Once installed, WebRAT exfiltrates sensitive information, leverages encrypted channels to evade detection, and can facilitate follow-on attacks via credential or data theft. This campaign underscores the risks in sourcing security tools or code from unverified public repositories and demonstrates the sophistication of modern software supply chain attacks. The incident highlights the growing trend of cybercriminals abusing trusted platforms like GitHub to reach a wide audience. With infostealer malware evolving and developer-targeted attacks increasing, organizations must remain vigilant about supply chain security and implement controls to detect and block lateral movement or data exfiltration.
6 months ago
Kill Chain
Malicious Chrome Extensions Steal Credentials in 2024 Supply-Chain Attack
In June 2024, security researchers discovered two malicious Chrome extensions, 'Phantom Shuttle,' available in the official Web Store, that masqueraded as proxy service plugins but instead hijacked users’ browser sessions. Once installed, these extensions intercepted sensitive user data—including login credentials—by redirecting and manipulating network traffic. By deploying the extensions within the Chrome browser ecosystem, threat actors leveraged a trusted supply-chain vector to reach a broad user base without raising immediate suspicion, resulting in widespread data theft before the plugins were reported and removed. This incident highlights the persistent risks associated with supply-chain compromise in browser extension ecosystems. Attackers increasingly exploit official platforms like Chrome’s Web Store to distribute malicious tools, circumvent traditional network defenses, and exfiltrate credentials, underscoring the need for robust extension vetting, user education, and advanced detection capabilities.
6 months ago
Kill Chain
Urban VPN Proxy Secretly Harvests AI Chat Data in Major 2025 Breach
In December 2025, security researchers revealed that Urban VPN, a widely used proxy extension, was surreptitiously intercepting conversations across multiple major AI platforms including ChatGPT, Claude, Gemini, and others. The extension embedded specialized scripts to harvest every prompt, response, and session identifier, regardless of VPN connectivity, compromising the privacy of millions of users. This covert data collection occurred without user awareness or consent, and the only available mitigation was uninstalling the extension altogether. Widespread harvesting of AI chat data raised severe concerns over data confidentiality and regulatory non-compliance. This incident underscores the increasing exploitation of browser extensions as attack vectors, especially as user reliance on generative AI tools for sensitive communications grows. The lack of transparency and opt-out mechanisms amplifies exposure to data-harvesting malware and highlights urgent needs for enhanced supply-chain vetting and detective controls in both enterprise and consumer environments.
6 months ago
Kill Chain
Mitsubishi Electric ICS Flaw in 2025 Highlights Need for Encrypted Traffic
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory detailing a critical vulnerability affecting Mitsubishi Electric Air Conditioning Systems that are widely deployed in industrial environments. The issue, cataloged as ICSA-25-177-01, centers on insufficient encryption for industrial control system (ICS) communications, exposing unencrypted traffic that could be intercepted and manipulated by malicious actors. If exploited, this vulnerability could enable attackers to intercept sensitive data or issue unauthorized commands to affected ICS devices, putting essential infrastructure operations at risk. Immediate mitigation steps were recommended for organizations to safeguard operational technology environments and prevent exploitation. This incident draws attention to the persistent risks of unencrypted or poorly protected network traffic within legacy ICS deployments. As digital transformation accelerates and threat actors increasingly target critical infrastructure, robust encrypted traffic solutions and segmentation controls are vital to ensure compliance and operational resilience.
6 months ago
Kill Chain
Threat Actors Exploit Zero-Day Vulnerability in WatchGuard Firebox Devices
In early 2024, cybercriminals exploited a previously unknown zero-day vulnerability in WatchGuard Firebox firewall devices, enabling unauthorized remote access and control over affected appliances. Attackers leveraged this flaw to bypass authentication, deploy malware, and establish persistent footholds within targeted organizational networks. The campaign resulted in potential data breaches, service disruptions, and exposure of sensitive internal traffic due to compromised network perimeters. WatchGuard has since released urgent patches and guidance, while security teams raced to detect and remediate compromised devices. This incident highlights the persistent targeting of edge security appliances by advanced threat actors and the speed at which zero-day exploits are weaponized. As remote work and hybrid cloud adoption surge, organizations must prioritize rapid patching and enhanced detection to mitigate risks posed by critical perimeter vulnerabilities.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports