Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2600 threat reports
Page 147 of 217

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 17531764 / 2600 reports
Former Insiders Launch ALPHV/BlackCat Ransomware Attacks in 2023
Impact· high

Former Insiders Launch ALPHV/BlackCat Ransomware Attacks in 2023

In 2023, two former cybersecurity professionals, Ryan Clifford Goldberg and Kevin Tyler Martin, exploited their trusted positions at incident response firms Sygnia and DigitalMint to perpetrate a series of targeted ransomware attacks. Acting in collusion with a third party and leveraging the ALPHV (BlackCat) ransomware variant, they compromised the networks of organizations across several critical sectors, including healthcare, engineering, and manufacturing. The group successfully extorted nearly $1.3 million from a Florida-based medical company and caused total damages exceeding $9.5 million across multiple states, before being apprehended and pleading guilty in federal court within months of indictment. This breach stands out for the attackers’ abuse of insider knowledge and privileged access, highlighting a new threat vector where trusted security personnel become adversaries. The case draws industry-wide attention to potential insider threats, the rising sophistication of ransomware groups, and the urgent need for enhanced monitoring and zero trust practices.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025
Impact· low

Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025

In December 2025, WatchGuard disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-14733) impacting numerous Firebox firewall models running Fireware OS versions 11.x and later. The flaw, stemming from an out-of-bounds write bug, allows unauthenticated attackers to deploy malicious code on unpatched devices via low-complexity attacks, without user interaction. Exploitation is linked to IKEv2 VPN configurations, including those previously deleted but with lingering branch office VPN settings, making many organizations vulnerable. Active exploitation was observed, prompting WatchGuard to provide urgent mitigation steps and indicators of compromise to aid detection and response. The incident poses serious risks to over 250,000 businesses worldwide, as Firebox devices are extensively used in SMBs and managed service environments. This breach highlights the ongoing escalation of attacks targeting network infrastructure, particularly security appliances that underpin VPN and edge services. With similar device vulnerabilities making headlines throughout 2025, attackers are increasingly exploiting remote access flaws to establish persistence, demonstrating a worrying trend for organizations that depend on always-on network security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit
Impact· medium

Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit

In December 2025, over 25,000 internet-exposed Fortinet devices with FortiCloud Single Sign-On (SSO) enabled were found vulnerable to an actively exploited authentication bypass flaw (CVE-2025-59718/CVE-2025-59719). Threat actors leveraged a malicious SAML message to compromise admin accounts via the SSO interface, gaining unauthorized access to system configuration files that revealed credentials, service details, network layouts, and firewall policies. The wide exposure was confirmed by independent scans, while U.S. government agencies were urgently mandated by CISA to patch within a week due to mounting exploitation. This incident highlights the persistent risk posed by poorly secured administrative interfaces, unpatched vulnerabilities, and credential-access techniques. Escalating regulatory pressure and attacker focus on identity-driven infrastructure demonstrate the need for robust segmentation and detection across all exposed assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
UEFI Firmware Vulnerability Leaves Major Motherboards Open to Early-Boot DMA Attacks
Impact· medium

UEFI Firmware Vulnerability Leaves Major Motherboards Open to Early-Boot DMA Attacks

In December 2025, researchers disclosed a critical hardware/firmware vulnerability impacting various ASRock, ASUS, GIGABYTE, and MSI motherboards. The flaw allows threat actors to launch direct memory access (DMA) attacks during the early boot process, bypassing typical Unified Extensible Firmware Interface (UEFI) and Input–Output Memory Management Unit (IOMMU) protections. Attackers can exploit this window to inject code or access sensitive memory before system defenses activate. The incident exposes endpoints to risk of credential theft, persistent malware implants, and lateral movement, with potential compromise of high-value IT and OT assets. This incident is highly relevant as firmware attacks and supply chain risks escalate, especially with the push towards Zero Trust security architectures. Hardware-level exposures pose challenges that traditional endpoint or network controls may not immediately mitigate, requiring urgent attention to firmware security and early-boot exploit detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Nigerian Authorities Arrest Raccoon0365 Phishing Platform Developer Linked to Microsoft 365 Attacks
Impact· high

Nigerian Authorities Arrest Raccoon0365 Phishing Platform Developer Linked to Microsoft 365 Attacks

In December 2025, Nigerian authorities arrested three individuals linked to the Raccoon0365 phishing platform, which was responsible for widespread credential theft targeting Microsoft 365 users. The service enabled cybercriminals to create convincing fake Microsoft login pages, facilitating business email compromise, data breaches, and significant financial losses across 94 countries. The investigation and arrests were made possible through intelligence provided by Microsoft via the FBI, leading to the apprehension of the platform's alleged developer and the recovery of digital evidence. Raccoon0365 operated via a Telegram channel with over 800 members, selling access to the phishing kits for cryptocurrency and leveraging Cloudflare infrastructure with compromised credentials. This incident is highly relevant as phishing-as-a-service (PhaaS) platforms continue to industrialize credential theft and make sophisticated attacks broadly accessible. The disruption of Raccoon0365 illustrates the importance of global collaboration, threat intelligence sharing, and proactive law enforcement action in curbing cybercrime.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
New DCOM Object Abuse Enables Lateral Movement via Control Panel (2024)
Impact· medium

New DCOM Object Abuse Enables Lateral Movement via Control Panel (2024)

In early 2024, new research revealed an undisclosed vulnerability in Microsoft Windows, where adversaries can abuse the Distributed Component Object Model (DCOM) to achieve lateral movement and persistence by exploiting Control Panel item registration. Attackers can remotely trigger the loading of malicious DLLs via the COpenControlPanel DCOM object, circumventing common defenses and security controls in enterprise environments. By registering rogue DLLs within specific Windows registry keys and leveraging remote registry manipulation, threat actors obtain both initial code execution and ongoing persistence, with minimal user interaction and limited detection from traditional endpoint defenses. This exposure highlights a shift toward advanced lateral movement techniques exploiting legitimate system components. With the rapid evolution of attacker TTPs, especially those bypassing modern endpoint protections and leveraging system internals, organizations face increased risk of undetected breaches and regulatory scrutiny. Proactive monitoring and refined segmentation are now essential to close these newly exposed attack paths.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Nigeria Arrests Developer Behind RaccoonO365 Phishing Attacks on Microsoft 365
Impact· low

Nigeria Arrests Developer Behind RaccoonO365 Phishing Attacks on Microsoft 365

In December 2025, Nigerian authorities arrested three high-profile cybercriminals, including the developer behind the notorious RaccoonO365 Phishing-as-a-Service (PhaaS) operation. RaccoonO365 enabled widespread Microsoft 365 phishing campaigns targeting large global corporations, facilitating credential theft and unauthorized access through sophisticated phishing kits and email lures. The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) led the investigation, collaborating with international law enforcement agencies to dismantle core elements of the PhaaS infrastructure. The disruption has limited the proliferation of phishing tools contributing to corporate account compromises and subsequent business email compromise (BEC) incidents. This case underscores the persistent evolution and professionalization of phishing-as-a-service marketplaces, often operated across borders. It highlights an increased law enforcement focus on targeting not only the end-users but also the developers and operators of cybercriminal toolkits enabling downstream attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025
Impact· low

Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025

In December 2025, WatchGuard disclosed a critical vulnerability (CVE-2025-14733, CVSS 9.3) impacting Fireware OS devices used for remote and branch office VPN connections via IKEv2. Remote unauthenticated attackers exploited an out-of-bounds write flaw in the iked process, allowing arbitrary code execution and potential compromise of security appliances. WatchGuard confirmed in-the-wild attacks linked to multiple malicious IPs, with over 117,000 internet-exposed devices at risk worldwide—over 35,000 in the U.S. alone. The vulnerability persisted in devices with previous IKEv2 configurations, even if settings were deleted. This incident exemplifies a broader threat trend as adversaries increasingly target edge networking infrastructure and VPN appliances through sophisticated exploits. The rapid addition of CVE-2025-14733 to CISA’s Known Exploited Vulnerabilities catalog underscores regulatory urgency and the need for vigilant patch management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus
Impact· low

CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus

In December 2025, CISA added CVE-2025-14733 affecting WatchGuard Firebox appliances to its Known Exploited Vulnerabilities Catalog after evidence of intensified in-the-wild exploitation. This out-of-bounds write vulnerability enables remote attackers to execute arbitrary code or disrupt device operations, threatening the integrity of network edge security. Organizations running unpatched Firebox devices are susceptible to threat actors leveraging this flaw for initial access, lateral movement, or persistent presence, with potential impact ranging from data compromise to operational downtime. Federal agencies were given a limited timeframe to remediate as mandated by Binding Operational Directive 22-01. The exploitation of CVE-2025-14733 underscores a trend where threat groups rapidly adopt edge infrastructure vulnerabilities into their toolkits. This incident reflects rising urgency for rigorous, proactive vulnerability management, as the window from disclosure to active exploitation continues to narrow.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cracked Software & YouTube Used to Deliver CountLoader and GachiLoader Malware in 2025
Impact· medium

Cracked Software & YouTube Used to Deliver CountLoader and GachiLoader Malware in 2025

In December 2025, researchers revealed a sophisticated dual-campaign where cracked software download sites and compromised YouTube videos were exploited to distribute the CountLoader and GachiLoader malware families. Users seeking pirated software were redirected to malicious downloads delivering CountLoader, a modular loader which enabled persistent access, evasion of antivirus tools, lateral movement, and ultimately delivered infostealer payloads such as ACR Stealer. In parallel, the YouTube Ghost Network used compromised accounts to distribute GachiLoader via fake installer videos, leveraging new techniques for stealth and privilege escalation, and dropping secondary threats such as Rhadamanthys stealer. These campaigns showcase rising innovation in malware loader design, particularly the use of signed-binary abuse, fileless execution, and exploitation of popular platforms to target unwary users. Such approach not only increases malware payload delivery rates but poses detection challenges for enterprises and individuals alike.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025
Impact· medium

How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025

In late 2025, a series of identity fraud cases within the home healthcare sector exposed substantial patient safety risks, as unqualified individuals impersonated registered caregivers to provide in-home care services. Attackers exploited weak identity and access management processes—primarily by sharing credentials and mobile devices, enabling false geolocation verification—to bypass patient safety protocols. Law enforcement and government reports highlighted multiple cases in the US and UK involving impersonation, altered electronic monitoring, and direct falsification of visit records. These incidents led to financial fraud against Medicaid, diminished quality of patient care, and, in some tragic cases, severe patient neglect or harm. This trend reflects a growing abuse of digital identity controls in healthcare, where rapid sector expansion and understaffed workforces create security gaps. The surge in similar impersonation tactics and the inadequacy of traditional geolocation or password-based controls underline the urgent need for advanced identity verification—such as biometrics—combined with device and contextual authentication, especially as regulatory scrutiny increases.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)
Impact· low

Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)

In late 2024, Cisco disclosed that a Chinese state-sponsored advanced persistent threat (APT) group, tracked as UAT-9686, exploited a critical zero-day vulnerability (CVE-2025-20393, CVSS 10) in Cisco AsyncOS software for Secure Email Gateway and Web Manager. Attackers gained unrestricted command execution by abusing non-standard, publicly exposed configurations of the spam quarantine feature, allowing them to implant persistent backdoors and fully compromise targeted environments. The campaign has been active since at least November 2024 and prompted rapid advisories following detection in early December. While the vulnerability remains unpatched, Cisco urged immediate risk mitigation steps for potentially affected customers. This incident highlights ongoing targeting of network appliances and email infrastructure by sophisticated Chinese APTs, leveraging zero-days and configuration weaknesses. It underscores the urgent need for better threat visibility, segmentation, and rapid incident response, especially as attackers increasingly weaponize supply chain and cloud service vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports