✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
How Google's 2024 Research Uncovered Chinese APT Exploitation of React2Shell
In June 2024, Google's Threat Analysis Group expanded the attribution of recent attacks exploiting the critical "React2Shell" remote code execution vulnerability to at least five more Chinese nation-state hacking groups. These attackers leveraged the unpatched React2Shell flaw to gain unauthorized access to systems across multiple sectors, using sophisticated spear-phishing and lateral movement techniques to deploy malware and establish persistence. The affected organizations experienced potential data exposure, operational interruptions, and increased remediation costs while scrambling to patch impacted environments. This incident highlights the evolving capabilities and coordination among multiple Chinese APTs targeting software supply chain weaknesses. The React2Shell exploitation surge demonstrates a significant escalation in the speed and scale of zero-day abuse by coordinated state-affiliated groups. Organizations face heightened urgency to accelerate vulnerability management and enhance east-west traffic monitoring as attackers rapidly weaponize public vulnerabilities.
6 months ago
Kill Chain
VolkLocker Ransomware Thwarted by Leaked Master Key: Lessons from the CyberVolk 2025 Attack
In August 2025, the pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) launched VolkLocker, a new ransomware-as-a-service aimed at both Windows and Linux systems. SentinelOne researchers discovered that VolkLocker suffered a critical security flaw: a hard-coded master key was inadvertently left in test artifacts, enabling anyone to decrypt files encrypted by the ransomware, bypassing ransom payments. Attackers used typical RaaS deployment methods, leveraging phishing and malicious attachments for initial access. While the group attempted to extort victims, the encryption flaw significantly undermined their efforts. The incident highlights the increased frequency and complexity of ransomware-as-a-service offerings, while underscoring the role of sloppy operator security in containing damage. As similar attacks proliferate, organizations must prioritize incident response and security validation against emerging threats.
6 months ago
Kill Chain
Critical Apple 0-Days and WinRAR Exploits: How Multi-Vector Threats Changed 2025
In December 2025, a wave of critical zero-day vulnerabilities targeting Apple devices, WinRAR, OAuth implementations, and the .NET framework was actively exploited by various cybercriminal groups. Attackers leveraged these flaws to bypass authentication mechanisms, execute remote code, and escalate privileges across both consumer and enterprise environments. Notably, some exploits were weaponized in the wild before official patches became available, resulting in widespread exposure of unencrypted traffic, unauthorized access to internal networks, and large-scale credential theft. Organizations experienced data breaches, ransomware infections, and regulatory scrutiny, particularly where weak segmentation or inadequate traffic visibility allowed lateral movement. This incident highlights the persistent threat posed by simultaneous multi-vector exploits, especially as attackers rapidly adopt new vulnerabilities in mainstream software. Increased regulatory focus on immediate patching and advanced segmentation underscores the necessity for robust, real-time threat detection and zero trust enforcement across hybrid and multi-cloud ecosystems.
6 months ago
Kill Chain
Urban VPN Chrome Extension Found Harvesting AI Chat Prompts from Millions
In late 2025, the "Urban VPN Proxy" Chrome extension—prominently labeled 'Featured' in the Chrome Web Store and boasting over six million users—was discovered silently harvesting all prompts users entered into popular AI chatbots such as ChatGPT, Anthropic Claude, Microsoft Copilot, Google Gemini, and others. Security researchers found the extension covertly intercepted and exfiltrated sensitive data in real time, leveraging its widespread user base and the inherent trust of its browser privileges. The extension’s activity amounted to a massive privacy breach, putting both individuals and enterprises at risk of data exposure. This breach highlights a surge in supply chain and third-party risks posed by browser extensions in the modern SaaS ecosystem. Enterprise security teams face heightened challenges as unregulated extensions become vectors for data harvesting, especially as reliance on AI tools increases. Privacy expectations, compliance obligations, and trust in official app marketplaces are now under renewed scrutiny.
6 months ago
Kill Chain
CISA Adds Apple & Gladinet Vulnerabilities to Known Exploited List (2025)
In December 2025, the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2025-14611 (Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability) and CVE-2025-43529 (Apple Multiple Products Use-After-Free WebKit Vulnerability) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active exploitation. These flaws allow attackers to gain unauthorized access, execute arbitrary code, and compromise sensitive data by leveraging weaknesses in encryption and browser components. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities by the stipulated deadlines to mitigate risks to critical government infrastructure. These additions reflect an ongoing surge in sophisticated vulnerability exploitation targeting both proprietary business platforms and widely used consumer products. Emerging attacker tactics and the regulatory environment reinforce the importance of robust, timely vulnerability management—underscoring that prioritizing patching of KEV-listed CVEs is now a best practice for all organizations.
6 months ago
Kill Chain
FreePBX 2025: Critical SQL Injection & Authentication Bypass Threatens Telecom Security
In September 2025, researchers from Horizon3.ai disclosed multiple severe vulnerabilities in FreePBX, an open-source private branch exchange (PBX) platform. These flaws, notably including a critical authentication bypass (CVE-2025-61675) and SQL injection issues, enabled remote code execution under certain configurations. Attackers could exploit these weaknesses to upload malicious files, bypass authentication controls, and potentially gain full system access. The vulnerabilities were responsibly reported to project maintainers, prompting urgent security patches and advisories to all FreePBX users. Organizations using affected versions faced significant risks, ranging from service disruption to compromise of sensitive communications and voicemail data. This incident highlights the persistent threat posed by application-layer vulnerabilities in widely deployed open-source communications platforms. The rise of telephony-based attacks and increasingly sophisticated exploitation tactics underscore the need for proactive patch management, rigorous code auditing, and supply chain security in telecom infrastructure.
6 months ago
Kill Chain
React2Shell CVE-2025-55182: Remote Code Execution Attacks Surge in 2025
In December 2025, active exploitation of a critical vulnerability in React2Shell (CVE-2025-55182) was detected, enabling remote code execution on unpatched servers. Attackers deployed a sequence of crafted HTTP requests to download and write malicious binaries onto world-writable Linux directories, such as /dev/shm and /tmp, then modified permissions to prepare for subsequent execution. The threat was identified by security researchers monitoring exploit payloads, which often leveraged ambiguous malware—classified as either adware or crypto miners—resulting in the compromise of affected servers and potentially unauthorized resource usage or data exfiltration. This campaign exemplifies the ongoing risk posed by delayed patch management, with adversaries swiftly evolving their payloads and exploiting widespread attack surfaces. The frequency of similar incidents underscores the importance of timely security updates and hardened configurations, particularly for widely deployed web services.
6 months ago
Kill Chain
VolkLocker 2025: Flaw in CyberVolk Ransomware Lets Victims Self-Decrpyt
In December 2025, the pro-Russia hacktivist group CyberVolk launched a new version of its VolkLocker ransomware-as-a-service (RaaS), targeting public sector and government organizations. The attackers leveraged Telegram automation for command-and-control, and conducted attacks on both Windows and Linux systems. However, investigators discovered a critical flaw: the ransomware stored its master encryption key in plaintext in the %TEMP% directory, allowing victims to recover encrypted files independently without paying ransom. This lapse likely resulted from debug functionality inadvertently left in production, significantly weakening the group's operations and credibility. This incident is highly relevant as ransomware groups are modernizing with advanced automation—but basic operational mistakes can undermine even sophisticated threat actors. For blue teams, it offers a real-world example of why continuous code auditing and rapid incident response are crucial, while for attackers, it’s a cautionary tale regarding quality control in criminal tooling.
6 months ago
Kill Chain
Critical React & Next.js Deserialization Bug Leads to RCE: What You Need to Know
In April 2025, security researchers disclosed critical vulnerabilities (CVE-2025-55182 and CVE-2025-66478) affecting the React and Next.js frameworks, specifically tied to unsafe data serialization and deserialization mechanisms in the Server Actions and Flight protocol. Attackers exploited the flaw to achieve remote code execution (RCE), enabling credential harvesting, lateral movement, and persistent access across affected environments. Within days of the CVEs’ disclosures, weaponized public exploit scripts proliferated on GitHub, compressing defenders’ reaction times and raising the risk of widespread attacks on applications running modern web stacks. This incident highlights the persistent danger of insecure serialization across software ecosystems, a threat pattern seen across at least a decade and multiple development languages. As AI-augmented coding accelerates release cycles, the lessons of past serialization flaws remain vital to protect emerging cloud-native applications from rapidly evolving threats.
6 months ago
Kill Chain
10 Critical November 2025 CVEs: Quality Over Quantity in Exploitation Trends
In November 2025, a sharp 69% drop in reported critical vulnerabilities masked a surge in the intensity of exploitation campaigns. Threat intelligence from Recorded Future revealed 10 high-risk CVEs—including two critical Fortinet FortiWeb flaws—actively targeted by threat actors. Notably, the LANDFALL spyware campaign weaponized Samsung's image processing vulnerability for zero-click remote attacks, while seven of ten vulnerabilities had public proof-of-concept code released. Vulnerabilities included OS command injection, out-of-bounds writes, access control failures, and issues affecting major vendors such as Microsoft, Oracle, and Google. This incident highlights how attackers are shifting to fewer but far more impactful vulnerabilities, emphasizing quality over quantity in their exploitation. Security teams must adapt, maintaining vigilance even during perceived lulls and prioritizing fast patching, advanced monitoring, and comprehensive exposure management to counter rapidly evolving threats.
6 months ago
Kill Chain
ClickFix Attackers Get Creative: Finger Protocol Exploitation in Ongoing Social Engineering Campaigns (2025)
In December 2025, ongoing ClickFix social engineering campaigns, notably KongTuke and SmartApeSG, exploited the legacy finger protocol to deliver malicious payloads to Windows hosts. Attackers enticed users to interact with fake CAPTCHA pages, triggering finger.exe commands that retrieved further instructions—such as encoded PowerShell commands or direct downloads of malware—from attacker-controlled servers over TCP port 79. These techniques allowed adversaries to bypass conventional detection and deliver remote access tools or additional scripts, posing operational threats to unprotected enterprise environments. This campaign highlights the resurgence of creative use of legacy or overlooked network protocols in modern attack chains. The persistence of ClickFix-driven social engineering and the reuse of finger.exe underline the importance for organizations to reassess traffic filtering strategies, as attackers are diversifying their initial access and payload delivery vectors.
6 months ago
Kill Chain
Ransomware Gets Hacked: CyberVolk’s VolkLocker Crumbles Under Weak Crypto
In June 2024, the pro-Russia hacktivist group CyberVolk introduced its VolkLocker ransomware-as-a-service (RaaS) platform, targeting organizations with file-encrypting malware. However, security researchers quickly discovered significant cryptographic vulnerabilities in its implementation, allowing many victims to recover encrypted files without paying the ransom. The flawed encryption methods meant attackers’ efforts to monetize were largely ineffective, reducing financial impact for most affected organizations but still causing temporary operational disruption and alarm. This incident highlights the persistent evolution of ransomware delivery via RaaS models, even by newly emerging threat actors with insufficient technical sophistication. As ransomware groups proliferate and adapt, businesses face the dual challenges of staying current on new threats and maintaining fundamental security practices, including robust encryption and incident response readiness.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports