✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Active Command Injection Attacks Hit Array AG Series Gateways in 2025
In mid-2025, JPCERT/CC reported that a command injection vulnerability in Array Networks AG Series secure access gateways had been actively exploited in the wild since at least August of that year. The flaw, residing in the DesktopDirect remote desktop access feature, allowed unauthenticated attackers to execute arbitrary commands on targeted devices. The vulnerability, lacking a CVE at the time of disclosure, was patched by Array Networks in May 2025, but unpatched systems remained exposed to attacks that could lead to further compromise and unauthorized network access. This incident underscores the persistent risks of unpatched infrastructure and weak segmentation in network environments. The rise of zero-day exploits targeting remote access solutions combined with increased regulatory scrutiny makes rapid detection, patching, and least privilege policy enforcement more critical than ever.
6 months ago
Kill Chain
Supply-Chain Emergency: Critical XXE Bug (CVE-2025-66516) in Apache Tika Imperils Enterprises
In December 2025, a critical XML External Entity (XXE) vulnerability, CVE-2025-66516, with a maximum CVSS score of 10.0, was discovered in multiple core Apache Tika modules. This flaw enables unauthenticated attackers to exploit XXE processing to remotely access sensitive files, exfiltrate data, and launch further attacks through maliciously crafted XML payloads. Because Apache Tika is widely employed in data extraction and content analysis across enterprise, cloud, and supply-chain systems, the exposure has immediate downstream risk for any organizations leveraging impacted Tika libraries. The incident highlights a significant supply-chain security challenge, reinforcing the urgency for immediate patching and improved review of third-party open-source components. Increasingly, threat actors are exploiting foundational software dependencies to bypass traditional security perimeters, making software supply-chain vigilance a key priority for 2025 and beyond.
6 months ago
Kill Chain
Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025
In December 2025, two Chinese nation-state threat groups rapidly began exploiting CVE-2025-55182—dubbed 'React2Shell'—a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC). Within hours of public disclosure, attackers scanned for and targeted vulnerable servers globally, leveraging the flaw to gain full control over application environments, execute arbitrary commands, and establish persistent footholds for lateral movement. The wide adoption of React in enterprise and SaaS environments increased the exposure and impact of these attacks, putting sensitive business-critical data at risk and causing major security teams to issue rapid patch advisories. This incident underscores the growing speed with which advanced threat actors weaponize zero-day vulnerabilities in widely used software frameworks. It highlights the urgent need for rapid vulnerability management, enhanced east-west segmentation, and robust threat detection, as attackers increasingly exploit supply chain and development stack exposures in cloud and hybrid environments.
6 months ago
Kill Chain
Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)
In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms. This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.
6 months ago
Kill Chain
AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users
In December 2024, researchers identified a fresh malware campaign abusing compiled AutoIT3 scripts to deliver infostealers and remote access trojans to Windows systems. Attackers distributed malicious executables packaged in ZIP archives, which, upon execution, leveraged AutoIT3’s FileInstall() function to embed and unpack additional payloads, including obfuscated shellcode. Once unpacked, these scripts decoded and executed shellcode in memory, deploying threats such as Quasar RAT and Phantom Stealer, thereby enabling credential theft and system compromise for victim organizations. This campaign highlights a growing trend where attackers utilize low-profile development tools, like AutoIT, to evade traditional defenses and deliver sophisticated payloads. The resurgence of compiled script-based malware demonstrates ongoing innovation in attack vectors, requiring defenders to expand their monitoring to scripting environments and unpacked resource analysis.
6 months ago
Kill Chain
React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability
In early 2024, a critical zero-day vulnerability in the widely used React JavaScript library—dubbed React2Shell—was actively exploited in the wild by sophisticated China-nexus threat actors. Attackers leveraged compromised software supply chains to infiltrate organizations during regular package updates, gaining access via vulnerable dependency injection into production environments. Once inside, adversaries orchestrated lateral movement to exfiltrate sensitive data and disrupt business operations across sectors, leveraging encrypted communication channels and advanced stealth techniques. The incident has underscored the significant risk posed by supply-chain weaknesses in core developer tools and frameworks, amplifying concerns among enterprises and regulators alike. This breach reflects a surge in supply-chain attacks targeting popular open-source components, exposing systemic vulnerabilities beyond traditional perimeter defenses. The rapid weaponization of techniques by nation-state actors highlights the urgent need for zero trust segmentation, proactive patching, and real-time threat visibility within software development ecosystems.
6 months ago
Kill Chain
Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)
In December 2025, a critical remote code execution (RCE) vulnerability—CVE-2025-55182—was discovered in the Flight protocol used by React Server Components. Rated CVSS 10.0, this flaw enabled unauthenticated attackers to craft malicious requests, resulting in the compromise of application servers running affected versions. Security researchers observed exploitation in the wild, with threat actors leveraging the flaw for lateral movement and potential data exfiltration. Organizations using Next.js and other frameworks integrating the vulnerable protocol faced heightened risk until urgent patches were issued. Immediate remediation efforts, threat monitoring, and network segmentation were necessary to mitigate the rapid spread. This incident underscores the increasing threat posed by supply chain vulnerabilities in widely adopted developer ecosystems. The exploitation of core component flaws in popular open-source projects amplifies business risk, as attackers accelerate adoption of frontline vulnerabilities for larger-scale impact.
6 months ago
Kill Chain
Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV
In December 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-55182) was discovered and actively exploited in Meta's React Server Components framework. Threat actors leveraged this flaw in internet-exposed REACT instances, enabling them to execute arbitrary code remotely and potentially gain unauthorized access to internal systems. This vulnerability was significant enough to be added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, prompting urgent remediation efforts across public and private organizations. Federal agencies were mandated to act by Binding Operational Directive 22-01, while industry peers were strongly advised to prioritize patching to limit exposure and prevent compromise. The exploit highlights an ongoing trend of attackers targeting widely adopted development frameworks like React, demonstrating how software supply chain and third-party vulnerabilities remain a high-risk vector. Its addition to the KEV Catalog underlines the persistent challenge organizations face in quickly identifying and mitigating critical threats across their infrastructure.
6 months ago
Kill Chain
Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk
In June 2024, a critical vulnerability known as 'React2Shell' was discovered in the React Server Components (RSC) 'Flight' protocol, impacting React and Next.js applications worldwide. This flaw enables unauthenticated remote code execution (RCE), allowing attackers to execute arbitrary JavaScript code on affected web servers. Security researchers observed that threat actors could exploit the protocol by sending crafted requests, potentially leading to a full compromise of application environments and exposure of sensitive data or further lateral movement within networks. This incident underscores heightened risk in modern web application supply chains and the urgent need for timely patching within frameworks. Growing attacks on open-source packages and widespread usage of React/Next.js frameworks amplify the incident's relevance, especially as application-layer vulnerabilities facilitate high-impact breaches at scale.
6 months ago
Kill Chain
ArrayOS AG VPN Vulnerability Exploited: Threat Actors Plant Webshells via Command Injection (2024)
In early June 2024, threat actors began actively exploiting a command injection vulnerability in Array Networks AG Series VPN devices, targeting organizations and critical infrastructure globally. Attackers leveraged the flaw to plant malicious webshells and create rogue administrative users, gaining persistent access to internal networks. The observed attacks allowed adversaries to bypass normal authentication and move laterally, posing significant operational risks by exposing sensitive internal systems and enabling further exploitation. The breach heightened concerns about the security of perimeter VPN appliances and the need for urgent patching. This incident is especially significant as attackers rapidly weaponize new vulnerabilities in edge infrastructure, reflecting a persistent trend of chaining VPN flaws to compromise enterprise environments. Heightened regulatory scrutiny and rising sophistication in attacks on remote access solutions underscore the urgent need for enhanced security controls and vigilant vulnerability management.
6 months ago
Kill Chain
CISA Warns of Chinese 'BrickStorm' Malware on VMware Servers: What Enterprises Must Know
In mid-2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Chinese state-sponsored hackers deployed the 'BrickStorm' malware to backdoor vulnerable VMware vSphere servers across multiple U.S. critical infrastructure sectors. Attackers exploited unpatched or insecurely configured vSphere environments to gain initial access, install persistent web shells, and enable lateral movement within networks. The campaign featured advanced evasion tactics, strong operational security, and targeted high-value assets, risking confidential data exposure, business disruption, and regulatory non-compliance for affected organizations. This attack exemplifies a rising trend of sophisticated supply-chain and infrastructure attacks leveraging known vulnerabilities in virtualized server environments. With ongoing exploitation by nation-state actors and renewed regulatory focus on asset protection, organizations must reevaluate their segmentation, patching, and east-west visibility controls to mitigate similar threats.
6 months ago
Kill Chain
2025’s Multi-Vector Supply Chain Attacks: How AI and Automation Redefined Web Security
In 2025, a coordinated wave of sophisticated attacks exploited web supply chain vulnerabilities, impacting over 180,000 websites globally. Threat actors leveraged multi-vector tactics, combining AI-driven injection methods, automated credential stuffing, and lateral movement across cloud and hybrid environments. The adversaries compromised legitimate third-party libraries and embedded malicious code into trusted web assets, bypassing traditional security controls and causing data breaches, unauthorized financial transfers, and reputation damage for thousands of organizations. Rapid east-west propagation enabled attackers to escalate privileges and exfiltrate sensitive customer data before detection. This incident signals a shift in the threat landscape, with attackers increasingly using AI and automation to exploit supply chain trust, targeting hybrid and multi-cloud infrastructures. Organizations face unprecedented pressure to modernize web security, prioritizing zero trust, real-time threat monitoring, and proactive segmentation to defend against rapidly evolving, multi-pronged attack campaigns.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports