✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Remote Code Execution Risk in Windows Imaging Component: Deep Dive into CVE-2025-50165
In November 2025, researchers exposed a critical vulnerability (CVE-2025-50165) in the Windows Imaging Component, specifically affecting WindowsCodecs.dll. The flaw arises from the mishandling of 12-bit and 16-bit JPG image encoding, where uninitialized function pointers could lead to a remote code execution (RCE) scenario. Attackers could theoretically trigger the vulnerability when a vulnerable application (such as Microsoft Photos or other image-processing tools) attempts to (re-)encode specially crafted JPG files. However, exploitation is complex and requires precise conditions—such as address leaks and heap control—making real-world attacks unlikely. Microsoft and library maintainers released patches to address the flaw by initializing pointers and adding error checks. This case highlights persistent risks in legacy image-processing libraries and the importance of timely patching. With software supply chains increasingly relying on third-party components, vulnerabilities in popular libraries can have broad implications, especially as adversaries probe for new entry points through common file formats.
6 months ago
Kill Chain
Ascension 2024 Breach: How RC4’s Legacy Left Millions Exposed
In May 2024, healthcare giant Ascension suffered a major data breach after threat actors exploited legacy support for the outdated RC4 encryption algorithm in Microsoft Windows environments. Attackers leveraged the well-known 'Kerberoasting' attack technique, enabled by RC4’s weak cryptography, to compromise credentials and move laterally between systems. This breach led to significant operational disruption across 140 hospitals, putting 5.6 million patient records at risk and critically impacting healthcare delivery. The incident highlighted the dangers of legacy cryptography persisting in critical infrastructure. The breach has brought renewed urgency to deprecate outdated cryptographic standards and accelerate upgrades within regulated industries. Regulatory scrutiny and increased attacker focus on cryptographic weaknesses make retiring end-of-life encryption technologies a top priority for all enterprises.
6 months ago
Kill Chain
WatchGuard 2025 RCE Breach Exposes 115,000+ Firebox Firewalls Globally
In December 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-14733, was disclosed impacting over 115,000 WatchGuard Firebox firewalls running Fireware OS. The flaw, residing in the OS iked process, allowed unauthenticated attackers to execute arbitrary code over the network when IKEv2 VPN was enabled. Actively exploited in the wild, the vulnerability placed thousands of organizations worldwide at risk of compromise. Shadowserver reported over 117,000 unpatched instances exposed online days after patches were released. U.S. federal agencies were ordered to patch affected firewalls within one week, with WatchGuard providing indicators of compromise, urgent mitigation steps, and guidance for customers unable to patch immediately. This incident underscores the persistent risk of edge device vulnerabilities and rapid attacker exploitation cycles. With federal mandates, ongoing zero-day disclosures, and increasingly sophisticated attack vectors targeting VPN and firewall infrastructure, organizations must prioritize timely patching and layered defenses to reduce exposure.
6 months ago
Kill Chain
Global Enterprises Breached: Ukrainian Nefilim Ransomware Affiliate Exposed in 2024
In December 2025, Ukrainian national Artem Aleksandrovych Stryzhak pleaded guilty to participating as an affiliate of the Nefilim ransomware gang, responsible for attacks on large enterprises across the U.S., Europe, and Australia between 2021 and 2022. Stryzhak and his accomplices, using custom-tailored ransomware, infiltrated businesses with revenues exceeding $100 million by exploiting online data gathering and targeting internal systems, leading to significant disruptions and ransom demands. Sensitive company data was threatened with public leaks to pressure victims into paying, amplifying both operational and reputational damage. U.S. authorities arrested Stryzhak in Spain in 2024, with sentencing scheduled for 2026. This incident exemplifies the continued operational sophistication and profitability of affiliate-based ransomware models. It also highlights evolving attacker methods that combine technical exploits with business intelligence gathering, and the increasing coordination among international law enforcement to counter cybercrime.
6 months ago
Kill Chain
Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse
In early 2024, Coupang, one of South Korea’s largest e-commerce platforms, suffered a data breach that went undetected for nearly five months, compromising the personal information of approximately 33.7 million users. The attacker, suspected to have leveraged compromised insider credentials, gained unauthorized access to databases containing user details including names, email addresses, and contact information. The breach highlights an extended dwell time during which the threat actor potentially exfiltrated significant data without detection, raising concerns over Coupang’s monitoring and response capabilities. Business impacts include reputational damage, regulatory scrutiny, and increased risk of fraud targeting affected users. This incident is highly relevant as it demonstrates the growing threat of credential and insider abuse, long dwell times, and the necessity for more rigorous data protection practices as regulatory pressure around personal data intensifies worldwide.
6 months ago
Kill Chain
University of Phoenix 2024 Clop Ransomware Breach Exposes Millions
In August 2023, the University of Phoenix suffered a significant data breach after the Clop ransomware gang exploited a vulnerability in the MOVEit file transfer software. Attackers gained unauthorized access to sensitive personal data belonging to nearly 3.5 million individuals, including current and former students, staff, and suppliers. The breach led to the theft of names, Social Security numbers, and other confidential records, severely impacting the institution’s ability to assure data privacy. Public disclosure came in June 2024 after investigation and notification procedures were completed. This incident underlines the escalating damage caused by ransomware groups leveraging supply chain vulnerabilities. Higher education institutions remain high-value targets due to large volumes of personal data and often fragmented security postures, highlighting an urgent need for proactive risk management and compliance with data protection regulations.
6 months ago
Kill Chain
npm Supply-Chain Breach: Malicious Package Steals WhatsApp Accounts and Messages
In June 2024, security researchers uncovered a malicious npm package masquerading as a legitimate WhatsApp Web API library. The package, downloaded from the Node Package Manager (NPM) registry, surreptitiously executed code to hijack WhatsApp accounts by stealing authentication credentials, intercepting messages, and exfiltrating contact information. Attackers leveraged this supply-chain compromise to gain unauthorized access to WhatsApp accounts, putting personal messages and sensitive user data at risk. The incident underscores growing threats targeting developer ecosystems and open-source repositories, demonstrating how a single compromised package can have widespread impact across organizations and individuals relying on shared libraries. This attack is particularly significant as adversaries increasingly exploit the software supply chain to distribute malware through trusted open-source ecosystems. Organizations face heightened regulatory scrutiny over software integrity, and similar tactics are quickly proliferating, prompting urgent calls for enhanced dependency management and real-time code vetting across the industry.
6 months ago
Kill Chain
INTERPOL Sparks Major 2024 Ransomware Takedown in Operation Sentinel
In May 2024, INTERPOL led a sweeping global cybercrime crackdown titled Operation Sentinel, targeting ransomware crews, business email compromise (BEC) groups, and extortion gangs. The coordinated action resulted in the arrest of 574 individuals across multiple countries. Six major ransomware strains were decrypted, and authorities seized over $3 million in illicit funds, effectively disrupting expansive international crime networks. Attackers leveraged a mix of phishing, malware, and lateral movement to infiltrate corporate and public-sector environments, lock critical data, and demand ransom payments. The impact was both substantial and international, affecting hundreds of organizations and drawing heavy collaboration among law enforcement agencies across continents. This case underscores the rise of global, cross-border law enforcement cooperation in tackling ransomware and financially motivated cybercrime. As threat actors become ever more sophisticated and resilient, multinational efforts and advanced decryption capabilities are now essential for effective disruption and victim support.
6 months ago
Kill Chain
MacSync Malware Bypasses macOS Gatekeeper with Notarized Infostealer in 2024
In June 2024, security researchers identified a new MacSync infostealer variant targeting macOS devices. The malware is delivered through a digitally signed and notarized Swift application that successfully evades Apple’s Gatekeeper checks, allowing it to run without typical security warnings. Once executed, MacSync exfiltrates sensitive user information including credentials, browser data, and files—leveraging encrypted command-and-control channels to avoid detection. The sophisticated dropper uses advanced evasion techniques to bypass standard macOS security controls, elevating risks for individuals and organizations running unpatched systems. This attack illustrates an evolving landscape where threat actors exploit trusted developer channels and novel evasion tactics to compromise macOS environments. With the growing adoption of macOS in enterprise and remote work settings, organizations are urged to review their controls, respond proactively, and address malware risks that legacy security tools may not detect.
6 months ago
Kill Chain
How Multi-Vector Attacks in 2025 Exposed Firewall and Internal Security Gaps
In December 2025, several global organizations faced a coordinated multi-vector cyber campaign in which threat actors leveraged recent vulnerabilities across enterprise firewalls, browser plugins, and connected devices. Attackers stealthily exploited zero-day flaws in network perimeter devices to access east-west traffic, deploy lateral movement, and exfiltrate sensitive data using encrypted channels. Both commercial and open-source threat detection struggled to identify activity quickly, resulting in significant operational disruptions, regulatory notification requirements, and data privacy liabilities affecting numerous sectors worldwide. This incident is indicative of a new threat paradigm in which attackers favor multi-tool, insider-style techniques, combining supply chain vulnerabilities with stealthy movements inside trusted IT environments. Security and compliance teams must now contend with adversaries who bypass traditional controls and exploit overlooked components, highlighting urgent needs for zero trust segmentation, improved traffic visibility, and robust egress monitoring.
6 months ago
Kill Chain
RansomHouse's 2025 Encryption Leap: The Rise of 'Mario' and Multi-Layered Ransomware
In December 2025, the RansomHouse ransomware-as-a-service (RaaS) group unveiled a major upgrade to its encryptor, dubbed ‘Mario’, shifting from a basic linear technique to a complex multi-layered encryption process. This variant leverages dynamic chunking, dual encryption keys, sophisticated memory organization, and non-linear file processing, making data recovery and reverse engineering significantly more challenging. Targeting environments such as VMware ESXi, the upgraded tooling enables attackers to encrypt large volumes of files efficiently, evidenced by attacks on organizations including Japanese e-commerce giant Askul, leading to substantial operational disruption and customer data compromise. RansomHouse’s encryption evolution underscores the continuing professionalization of RaaS groups, complicating detection and recovery for defenders. As multi-layered and adaptive ransomware proliferates, organizations face heightened risks, regulatory scrutiny, and the need to adopt advanced segmentation, visibility, and threat response controls.
6 months ago
Kill Chain
Cisco VPNs and Email Service Campaigns: How Multi-Vector Attacks Are Changing the Cyber Risk Landscape
In early 2024, Cisco VPN appliances and various enterprise email services were targeted in two distinct but nearly simultaneous cyber campaigns. The first, a highly coordinated attack, leveraged zero-day vulnerabilities and credential harvesting to infiltrate corporate VPNs, granting attackers lateral access to sensitive networks. Around the same period, a separate 'spray-and-pray' phishing wave indiscriminately targeted a wide swath of business email services, seeking to exploit weak authentication and unpatched systems. Combined, the incidents led to multiple business disruptions, credential leaks, and prompted extensive incident response efforts across affected organizations. This incident is part of a larger trend where cybercriminals simultaneously exploit both remote-access infrastructure and cloud-based email, reflecting a shift toward multi-vector, blended attacks. Organizations are facing heightened regulatory and operational pressure to defend against ever more sophisticated and opportunistic threats targeting identity, access points, and critical communications systems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports