✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Former Insiders Launch ALPHV/BlackCat Ransomware Attacks in 2023
In 2023, two former cybersecurity professionals, Ryan Clifford Goldberg and Kevin Tyler Martin, exploited their trusted positions at incident response firms Sygnia and DigitalMint to perpetrate a series of targeted ransomware attacks. Acting in collusion with a third party and leveraging the ALPHV (BlackCat) ransomware variant, they compromised the networks of organizations across several critical sectors, including healthcare, engineering, and manufacturing. The group successfully extorted nearly $1.3 million from a Florida-based medical company and caused total damages exceeding $9.5 million across multiple states, before being apprehended and pleading guilty in federal court within months of indictment. This breach stands out for the attackers’ abuse of insider knowledge and privileged access, highlighting a new threat vector where trusted security personnel become adversaries. The case draws industry-wide attention to potential insider threats, the rising sophistication of ransomware groups, and the urgent need for enhanced monitoring and zero trust practices.
6 months ago
Kill Chain
Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025
In December 2025, WatchGuard disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-14733) impacting numerous Firebox firewall models running Fireware OS versions 11.x and later. The flaw, stemming from an out-of-bounds write bug, allows unauthenticated attackers to deploy malicious code on unpatched devices via low-complexity attacks, without user interaction. Exploitation is linked to IKEv2 VPN configurations, including those previously deleted but with lingering branch office VPN settings, making many organizations vulnerable. Active exploitation was observed, prompting WatchGuard to provide urgent mitigation steps and indicators of compromise to aid detection and response. The incident poses serious risks to over 250,000 businesses worldwide, as Firebox devices are extensively used in SMBs and managed service environments. This breach highlights the ongoing escalation of attacks targeting network infrastructure, particularly security appliances that underpin VPN and edge services. With similar device vulnerabilities making headlines throughout 2025, attackers are increasingly exploiting remote access flaws to establish persistence, demonstrating a worrying trend for organizations that depend on always-on network security.
6 months ago
Kill Chain
Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit
In December 2025, over 25,000 internet-exposed Fortinet devices with FortiCloud Single Sign-On (SSO) enabled were found vulnerable to an actively exploited authentication bypass flaw (CVE-2025-59718/CVE-2025-59719). Threat actors leveraged a malicious SAML message to compromise admin accounts via the SSO interface, gaining unauthorized access to system configuration files that revealed credentials, service details, network layouts, and firewall policies. The wide exposure was confirmed by independent scans, while U.S. government agencies were urgently mandated by CISA to patch within a week due to mounting exploitation. This incident highlights the persistent risk posed by poorly secured administrative interfaces, unpatched vulnerabilities, and credential-access techniques. Escalating regulatory pressure and attacker focus on identity-driven infrastructure demonstrate the need for robust segmentation and detection across all exposed assets.
6 months ago
Kill Chain
UEFI Firmware Vulnerability Leaves Major Motherboards Open to Early-Boot DMA Attacks
In December 2025, researchers disclosed a critical hardware/firmware vulnerability impacting various ASRock, ASUS, GIGABYTE, and MSI motherboards. The flaw allows threat actors to launch direct memory access (DMA) attacks during the early boot process, bypassing typical Unified Extensible Firmware Interface (UEFI) and Input–Output Memory Management Unit (IOMMU) protections. Attackers can exploit this window to inject code or access sensitive memory before system defenses activate. The incident exposes endpoints to risk of credential theft, persistent malware implants, and lateral movement, with potential compromise of high-value IT and OT assets. This incident is highly relevant as firmware attacks and supply chain risks escalate, especially with the push towards Zero Trust security architectures. Hardware-level exposures pose challenges that traditional endpoint or network controls may not immediately mitigate, requiring urgent attention to firmware security and early-boot exploit detection.
6 months ago
Kill Chain
Nigerian Authorities Arrest Raccoon0365 Phishing Platform Developer Linked to Microsoft 365 Attacks
In December 2025, Nigerian authorities arrested three individuals linked to the Raccoon0365 phishing platform, which was responsible for widespread credential theft targeting Microsoft 365 users. The service enabled cybercriminals to create convincing fake Microsoft login pages, facilitating business email compromise, data breaches, and significant financial losses across 94 countries. The investigation and arrests were made possible through intelligence provided by Microsoft via the FBI, leading to the apprehension of the platform's alleged developer and the recovery of digital evidence. Raccoon0365 operated via a Telegram channel with over 800 members, selling access to the phishing kits for cryptocurrency and leveraging Cloudflare infrastructure with compromised credentials. This incident is highly relevant as phishing-as-a-service (PhaaS) platforms continue to industrialize credential theft and make sophisticated attacks broadly accessible. The disruption of Raccoon0365 illustrates the importance of global collaboration, threat intelligence sharing, and proactive law enforcement action in curbing cybercrime.
6 months ago
Kill Chain
New DCOM Object Abuse Enables Lateral Movement via Control Panel (2024)
In early 2024, new research revealed an undisclosed vulnerability in Microsoft Windows, where adversaries can abuse the Distributed Component Object Model (DCOM) to achieve lateral movement and persistence by exploiting Control Panel item registration. Attackers can remotely trigger the loading of malicious DLLs via the COpenControlPanel DCOM object, circumventing common defenses and security controls in enterprise environments. By registering rogue DLLs within specific Windows registry keys and leveraging remote registry manipulation, threat actors obtain both initial code execution and ongoing persistence, with minimal user interaction and limited detection from traditional endpoint defenses. This exposure highlights a shift toward advanced lateral movement techniques exploiting legitimate system components. With the rapid evolution of attacker TTPs, especially those bypassing modern endpoint protections and leveraging system internals, organizations face increased risk of undetected breaches and regulatory scrutiny. Proactive monitoring and refined segmentation are now essential to close these newly exposed attack paths.
6 months ago
Kill Chain
Nigeria Arrests Developer Behind RaccoonO365 Phishing Attacks on Microsoft 365
In December 2025, Nigerian authorities arrested three high-profile cybercriminals, including the developer behind the notorious RaccoonO365 Phishing-as-a-Service (PhaaS) operation. RaccoonO365 enabled widespread Microsoft 365 phishing campaigns targeting large global corporations, facilitating credential theft and unauthorized access through sophisticated phishing kits and email lures. The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) led the investigation, collaborating with international law enforcement agencies to dismantle core elements of the PhaaS infrastructure. The disruption has limited the proliferation of phishing tools contributing to corporate account compromises and subsequent business email compromise (BEC) incidents. This case underscores the persistent evolution and professionalization of phishing-as-a-service marketplaces, often operated across borders. It highlights an increased law enforcement focus on targeting not only the end-users but also the developers and operators of cybercriminal toolkits enabling downstream attacks.
6 months ago
Kill Chain
Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025
In December 2025, WatchGuard disclosed a critical vulnerability (CVE-2025-14733, CVSS 9.3) impacting Fireware OS devices used for remote and branch office VPN connections via IKEv2. Remote unauthenticated attackers exploited an out-of-bounds write flaw in the iked process, allowing arbitrary code execution and potential compromise of security appliances. WatchGuard confirmed in-the-wild attacks linked to multiple malicious IPs, with over 117,000 internet-exposed devices at risk worldwide—over 35,000 in the U.S. alone. The vulnerability persisted in devices with previous IKEv2 configurations, even if settings were deleted. This incident exemplifies a broader threat trend as adversaries increasingly target edge networking infrastructure and VPN appliances through sophisticated exploits. The rapid addition of CVE-2025-14733 to CISA’s Known Exploited Vulnerabilities catalog underscores regulatory urgency and the need for vigilant patch management.
6 months ago
Kill Chain
CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus
In December 2025, CISA added CVE-2025-14733 affecting WatchGuard Firebox appliances to its Known Exploited Vulnerabilities Catalog after evidence of intensified in-the-wild exploitation. This out-of-bounds write vulnerability enables remote attackers to execute arbitrary code or disrupt device operations, threatening the integrity of network edge security. Organizations running unpatched Firebox devices are susceptible to threat actors leveraging this flaw for initial access, lateral movement, or persistent presence, with potential impact ranging from data compromise to operational downtime. Federal agencies were given a limited timeframe to remediate as mandated by Binding Operational Directive 22-01. The exploitation of CVE-2025-14733 underscores a trend where threat groups rapidly adopt edge infrastructure vulnerabilities into their toolkits. This incident reflects rising urgency for rigorous, proactive vulnerability management, as the window from disclosure to active exploitation continues to narrow.
6 months ago
Kill Chain
Cracked Software & YouTube Used to Deliver CountLoader and GachiLoader Malware in 2025
In December 2025, researchers revealed a sophisticated dual-campaign where cracked software download sites and compromised YouTube videos were exploited to distribute the CountLoader and GachiLoader malware families. Users seeking pirated software were redirected to malicious downloads delivering CountLoader, a modular loader which enabled persistent access, evasion of antivirus tools, lateral movement, and ultimately delivered infostealer payloads such as ACR Stealer. In parallel, the YouTube Ghost Network used compromised accounts to distribute GachiLoader via fake installer videos, leveraging new techniques for stealth and privilege escalation, and dropping secondary threats such as Rhadamanthys stealer. These campaigns showcase rising innovation in malware loader design, particularly the use of signed-binary abuse, fileless execution, and exploitation of popular platforms to target unwary users. Such approach not only increases malware payload delivery rates but poses detection challenges for enterprises and individuals alike.
6 months ago
Kill Chain
How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025
In late 2025, a series of identity fraud cases within the home healthcare sector exposed substantial patient safety risks, as unqualified individuals impersonated registered caregivers to provide in-home care services. Attackers exploited weak identity and access management processes—primarily by sharing credentials and mobile devices, enabling false geolocation verification—to bypass patient safety protocols. Law enforcement and government reports highlighted multiple cases in the US and UK involving impersonation, altered electronic monitoring, and direct falsification of visit records. These incidents led to financial fraud against Medicaid, diminished quality of patient care, and, in some tragic cases, severe patient neglect or harm. This trend reflects a growing abuse of digital identity controls in healthcare, where rapid sector expansion and understaffed workforces create security gaps. The surge in similar impersonation tactics and the inadequacy of traditional geolocation or password-based controls underline the urgent need for advanced identity verification—such as biometrics—combined with device and contextual authentication, especially as regulatory scrutiny increases.
6 months ago
Kill Chain
Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)
In late 2024, Cisco disclosed that a Chinese state-sponsored advanced persistent threat (APT) group, tracked as UAT-9686, exploited a critical zero-day vulnerability (CVE-2025-20393, CVSS 10) in Cisco AsyncOS software for Secure Email Gateway and Web Manager. Attackers gained unrestricted command execution by abusing non-standard, publicly exposed configurations of the spam quarantine feature, allowing them to implant persistent backdoors and fully compromise targeted environments. The campaign has been active since at least November 2024 and prompted rapid advisories following detection in early December. While the vulnerability remains unpatched, Cisco urged immediate risk mitigation steps for potentially affected customers. This incident highlights ongoing targeting of network appliances and email infrastructure by sophisticated Chinese APTs, leveraging zero-days and configuration weaknesses. It underscores the urgent need for better threat visibility, segmentation, and rapid incident response, especially as attackers increasingly weaponize supply chain and cloud service vulnerabilities.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports