✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
How Attackers Exploit Windows Race Conditions with Path Lookups
In December 2025, security researchers identified a critical exploitation technique leveraging race conditions within the Windows Object Manager namespace. Attackers can use specially crafted path lookups, combining recursive directories, symbolic links, shadow directories, and hash collisions, to artificially inflate kernel resource lookup times—sometimes up to several minutes. By exploiting this behavior, an attacker could significantly increase the window to win race conditions, potentially bypassing security checks and securing unauthorized access or escalating privileges. The impact of this exploit affects modern Windows 11 systems and is especially relevant for environments relying heavily on object access protections. This exploitation method highlights an enduring structural weakness that remains open even in recent Windows releases. With a broader trend toward complex system attacks and system resource manipulation, awareness and mitigations for race-based vulnerabilities have become a growing priority for enterprises and regulators.
6 months ago
Kill Chain
VirtualBox Slirp Flaw Enables 2025 Virtualization Escape — What Enterprises Must Know
In late 2025, a critical vulnerability was disclosed in Oracle VirtualBox related to its use of a modified Slirp networking stack for NAT mode. Security researchers demonstrated a reliable virtualization escape technique by exploiting unsafe memory handling in the packet heap allocator. By manipulating packet headers from within a VM, attackers could achieve arbitrary code execution on the host, effectively breaching isolation and enabling full control over the underlying system. No authentication was required; only network access from the guest to the host's NAT interface. The incident prompted urgent patching and highlighted the continued risk of legacy code in hypervisor environments. This incident remains highly relevant as virtualization escape attacks are escalating, with attackers targeting cloud and data center hypervisor layers. Trends in lateral movement, advanced VM attacks, and increasing regulatory focus on workload security are intensifying the urgency for robust virtual infrastructure defenses.
6 months ago
Kill Chain
Hypervisors Under Fire: 2024 Ransomware Blitz Hits Virtualization Core
In early 2024, organizations across multiple sectors faced a wave of targeted ransomware attacks exploiting vulnerabilities in virtualization platforms' hypervisors. Threat actors used stolen administrative credentials and leveraged known and zero-day flaws in hypervisor management interfaces to bypass segmentation controls, moving laterally from corporate networks onto host environments. Once inside, attackers deployed ransomware payloads at the hypervisor level, simultaneously encrypting dozens of virtual machines and crippling key business operations for days or weeks. The impact included downtime cascading across critical workloads, increased ransom demands due to concentrated disruption, and challenges in restoring services due to the interlocked nature of virtualized systems. This incident spotlights the growing trend of ransomware groups shifting attacks from endpoint devices to virtualization infrastructure, exploiting weak visibility and east-west segmentation at the hypervisor layer. As businesses accelerate cloud and virtual adoption, the threat landscape is rapidly evolving, making hypervisor security an urgent priority for IT and security leaders.
6 months ago
Kill Chain
Fortinet 2024 Auth Bypass Exploited: Urgent Actions for Network Security
In early June 2024, threat actors actively exploited newly disclosed authentication bypass vulnerabilities in multiple Fortinet products, including FortiOS and FortiProxy. Attackers leveraged these flaws (notably CVE-2024-21762 and CVE-2024-23113) shortly after Fortinet's patch release, gaining unauthorized admin-level access to vulnerable devices. The intruders then extracted system configuration files, risking exposure of sensitive network data and credentials. Several organizations reported compromises and system disruptions, prompting urgent advisories from Fortinet and government agencies to patch immediately and review system integrity. This incident underscores a dangerous trend: rapid mass exploitation of zero-day vulnerabilities in network security devices. The high-profile breach highlights mounting risks to organizations that delay critical patching and demonstrates the persistent targeting of edge appliances by sophisticated attackers.
6 months ago
Kill Chain
GhostPoster: Malicious Firefox Addon Logos Expose Supply Chain Security Risks
In early 2024, a supply chain attack campaign known as 'GhostPoster' was uncovered targeting users of malicious Firefox browser extensions. Threat actors embedded obfuscated JavaScript payloads within the image logos of these add-ons, leveraging steganography to evade detection and distribute malware. Once installed, the trojanized extensions—with more than 50,000 downloads—granted actors persistent access to victims' browsers, allowing for activity monitoring and enabling backdoor capabilities. The campaign exploited the trust in official browser markets while circumventing traditional security measures. This breach illustrates the rising sophistication of supply chain attacks, particularly those leveraging legitimate software distribution channels. It highlights the necessity for stronger internal and external vetting of browser add-ons, as the technique is being replicated across other software ecosystems.
6 months ago
Kill Chain
APT Groups Leverage React2Shell to Plant Linux Backdoors in 2025
In December 2025, security researchers from Palo Alto Networks Unit 42 and NTT Security discovered active exploitation of the React2Shell vulnerability targeting Linux environments worldwide. The attackers leveraged this flaw in unpatched systems to deploy advanced remote access tools such as KSwapDoor and ZnDoor. These malware families provided persistent backdoor access, enabling lateral movement and data exfiltration. The campaign was characterized by sophisticated evasion techniques, stealthy command-and-control channels, and targeted critical infrastructure, raising the risk of operational disruption and regulatory exposure for affected organizations. The exploitation of React2Shell reflects a broader surge in advanced persistent threat (APT) activity focused on Linux workloads, with threat actors increasingly targeting vulnerabilities in remote access and open-source software. This trend underscores the urgent need for enhanced east-west traffic security, rapid patching, and anomaly detection to prevent organizational compromise.
6 months ago
Kill Chain
Active Attack: Fortinet FortiGate SAML SSO Authentication Bypass Exposes Networks
In December 2025, threat actors began exploiting two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719, both CVSS 9.8) in Fortinet FortiGate appliances. By targeting the FortiCloud SSO feature—enabled during FortiCare registration—they leveraged crafted SAML messages to gain unauthorized access to admin accounts. Once inside, attackers exported device configuration files, risking credential compromise and broader network infiltration. The U.S. CISA quickly classified the flaws as Known Exploited Vulnerabilities, urging immediate patching. This incident demonstrates the evolving risk of identity-driven network attacks and rapid exploitation following vulnerability disclosure. With opportunistic threat actors targeting edge infrastructure, similar authentication-based attacks are likely to increase, further incentivized by regulatory and industry pressure for swift vulnerability management.
6 months ago
Kill Chain
Cellik Android Malware: The New Frontier for Trojanized Google Play Apps
In December 2025, cybersecurity researchers identified a new Android malware-as-a-service (MaaS) dubbed Cellik that enables cybercriminals to create malicious variants of popular Google Play Store apps. Distributed via underground forums, Cellik’s service allows threat actors to select legitimate apps, inject sophisticated malware, and maintain original app functionality, thereby bypassing typical user suspicion and potentially evading Google Play Protect. Cellik's features include real-time screen streaming, notification interception, filesystem browsing, data exfiltration, device wiping, and encrypted command-and-control communications. Attackers can also overlay fake login screens, inject malicious payloads into trusted apps, and exploit a hidden browser to steal credentials using stored cookies from infected devices. The emergence of Cellik signals an evolution in Android threat tooling, where MaaS kits empower less skilled actors to launch advanced attacks. This development heightens risks for organizations subject to mobile threats as attackers embrace more modular and evasive tactics, underlining the urgent need for advanced mobile security controls and proactive user education.
6 months ago
Kill Chain
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.
6 months ago
Kill Chain
Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025
In November 2025, Amazon Web Services (AWS) became the target of a widespread cryptomining campaign exploiting compromised Identity and Access Management (IAM) credentials. The attackers used stolen keys to access AWS accounts, deploy cryptomining operations, and leverage persistence mechanisms to avoid detection and maintain access. Amazon’s GuardDuty threat detection tools were instrumental in uncovering the activity, which leveraged novel Tactics, Techniques, and Procedures (TTPs) including lateral movement and privilege escalation, putting customer cloud resources and budgets at risk through accelerated resource consumption and possible data exposure. This incident is emblematic of an escalating trend where threat actors exploit cloud identity weaknesses for financial gain. It underscores the urgent necessity for robust multi-factor authentication, real-time anomaly detection, and comprehensive cloud security strategies as identity-driven attacks proliferate in the cloud era.
6 months ago
Kill Chain
CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation
In December 2025, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation targeting Fortinet's multiple products. This vulnerability involves improper verification of cryptographic signatures, allowing attackers to bypass security controls, execute unauthorized code, or escalate privileges on affected devices. Federal agencies, per BOD 22-01, must remediate this critical issue by the mandated deadline to protect their networks. The flaw’s exploitation risks device compromise and potential lateral movement by sophisticated threat actors, with broad implications for data integrity and operational continuity across affected organizations. This alert reflects the escalating trend of attackers rapidly weaponizing supply chain or cryptographic flaws in core network infrastructure. As organizations increasingly rely on complex integrations and encrypted communications, such vulnerabilities underscore persistent challenges in managing risk and ensuring trust in critical systems.
6 months ago
Kill Chain
8 Million Users' AI Conversations Exposed: Urban VPN Browser Extension's Hidden Data Harvest
In December 2025, security researchers exposed that the popular Urban VPN Proxy browser extension—marketed for privacy—was actively harvesting and exfiltrating sensitive conversation data from over eight million users interacting with leading AI chatbot platforms such as ChatGPT, Claude, Gemini, and Copilot. The malicious behavior was introduced in versions released after July 2025, with the extension injecting scripts into browser sessions to intercept, package, and transmit users’ chatbot prompts, responses, and session metadata to servers operated by Urban VPN’s parent, BiScience, a known data broker. Users were not offered any meaningful way to disable this data collection besides uninstalling the extension, and the privacy disclosure was deeply buried within the setup process, leaving the majority unaware. This incident underscores the growing risk posed by privacy-violating browser extensions, especially those with elevated reputations and millions of installations. As AI assistants become repositories for sensitive personal and corporate data, the implications of such data leaks—from regulatory compliance to business confidentiality—are amplified, driving urgent reassessment of browser extension governance and AI data security controls.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports