✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories
In November 2025, security researchers uncovered a widespread supply chain attack dubbed the "Sha1-Hulud" wave targeting the npm registry. Threat actors compromised over 25,000 repositories by trojanizing hundreds of widely used npm packages, injecting malicious code into the preinstall scripts. This code siphoned developer credentials and environmental secrets during package installations, potentially giving attackers unauthorized access to private projects and infrastructure. The campaign relied on malicious npm uploads, affecting downstream open-source users and organizations across the software supply chain. This incident highlights the persistent risk of supply chain attacks via popular package ecosystems, underscoring the need for robust code vetting, audit logging, and least privilege principles. With growing reliance on open-source software, attackers continue to exploit trusted platforms to achieve broad compromise.
6 months ago
Kill Chain
Inside the STORM-2603 & JustAskJacky Multi-Vector macOS Stealer Campaign
In November 2025, a sophisticated multi-vector cyber campaign targeted macOS users, leveraging a cluster of new information stealers and advanced lateral movement techniques. Threat actors, prominently STORM-2603 and JustAskJacky, exploited vulnerabilities in east-west traffic controls and manipulated encrypted traffic in hybrid cloud environments to evade detection. Utilizing covert remote-access tools and exploiting hybrid connectivity pathways, the attackers exfiltrated sensitive business and personal data—including credentials and intellectual property—before security teams were alerted. The coordinated attack spanned several organizations, resulting in notable data leaks and operational disruption. This incident highlights the growing trend of high-performance, cross-platform info-stealing malware and the convergence of cloud, on-prem, and user device threats. Security leaders should note the increased adoption of identity-based policy enforcement, robust segmentation, and enhanced anomaly detection to counter similar campaigns now escalating in prevalence.
6 months ago
Kill Chain
Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach
In late 2022, the Hitachi Vantara Pentaho Business Analytics Server was targeted by attackers exploiting CVE-2022-43939 and CVE-2022-43769, leveraging flaws in URL mapping and URL-based access control. Threat actors, including the 'Rondo' botnet group, exploited a template injection vulnerability that allowed unauthenticated command execution by bypassing authentication controls via specific URL paths. This enabled attackers to remotely execute arbitrary code, potentially gaining control over affected systems, exfiltrate data, and laterally move within enterprise networks. The automation and scale of these attacks highlighted application misconfigurations, lapses in secure access control design, and the ongoing risk of vulnerable web application endpoints. This incident underscores a broader trend of threat actors exploiting subtle misconfigurations in URL handling and web server rules. Organizations are now under increased regulatory and operational pressure to audit legacy web applications and APIs, implement zero trust segmentation, and rigorously validate access control rules as attackers aggressively pursue these weaknesses.
6 months ago
Kill Chain
Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data
In June 2024, Spanish airline Iberia disclosed a significant data breach originating from the compromise of an external supplier. Attackers leveraged a third-party network to steal approximately 77 GB of sensitive customer data, including contact information, travel details, and partial payment card data. The breach was first publicized on underground forums, with threat actors claiming possession of the data days before Iberia notified its customers. The incident underscores how supply chain vulnerabilities can directly jeopardize core business operations and customer trust, disrupting service continuity and triggering regulatory scrutiny for the airline industry. This breach illustrates the ongoing escalation of supply chain attacks, where organizations are exposed through weak vendor controls. With similar tactics increasingly exploited against critical infrastructure, maintaining robust controls over partners is now essential in light of growing attacker sophistication and tightening data protection requirements.
6 months ago
Kill Chain
CISA Issues Urgent Alert: Oracle Identity Manager Zero-Day (CVE-2025-61757) Exploited in Active Attacks
In June 2025, CISA issued an emergency warning following the discovery of active exploitation against Oracle Identity Manager (OIM), targeting a critical remote code execution vulnerability tracked as CVE-2025-61757. Attackers leveraged this flaw, possibly as a zero-day, to gain unauthorized access to governmental and enterprise identity infrastructures. Evidence shows threat actors performed arbitrary code execution on affected systems, enabling privilege escalation and potential lateral movement within targeted networks. This breach presents serious risks to the integrity and availability of authentication systems, exposing sensitive data and potentially undermining access controls across impacted organizations. The incident stands out due to a surge in direct attacks targeting identity infrastructure and core authentication providers. The increasing reliance on identity management platforms makes these systems high-value targets, highlighting a broader trend towards exploiting supply chain and zero-day vulnerabilities with immediate, widespread consequences.
6 months ago
Kill Chain
Unpacking the Qilin Ransomware Attack: Lessons from a ScreenConnect Breach
In early 2024, a Qilin ransomware attack demonstrated the risks of third-party remote access tools when threat actors gained entry via ScreenConnect to a corporate endpoint. Leveraging this precarious foothold, attackers navigated the environment, launched failed infostealer payloads, then successfully executed ransomware—all while evading detection due to severely limited log visibility. Despite these blind spots, incident responders from Huntress used endpoint forensics and cross-correlation of minimal artifacts to reconstruct the entire attack path, including lateral movement attempts and the precise ransomware execution timeline. This incident highlights the growing sophistication of ransomware actors using remote IT management software for covert entry. As RMM tool vulnerabilities and minimal logging become more prevalent, organizations face heightened risk and pressure to implement deeper east-west threat detection and robust zero trust network segmentation.
6 months ago
Kill Chain
WhatsApp’s 2024 API Flaw: 3.5 Billion Accounts Exposed via Automated Scraping
In early 2024, a significant data exposure incident affected WhatsApp when researchers discovered and exploited a vulnerability in the platform's contact-discovery API. The API lacked effective rate limiting and permitted mass enumeration of registered user accounts by automating queries, enabling adversaries to harvest data on approximately 3.5 billion mobile phone numbers and associated details. No evidence suggests the involvement of a deliberate threat actor beyond security researchers, but the scale and scope highlight serious privacy and operational risks for both users and WhatsApp’s business integrity. The incident underscores ongoing risks for messaging applications leveraging public-facing APIs without stringent access and abuse controls. This breach is highly relevant as API abuse and large-scale account enumeration techniques are increasingly exploited by attackers seeking personal data. Regulatory scrutiny is poised to intensify, and similar flaws are being reported across numerous communications platforms, making robust API security and anomaly detection critical in today’s threat landscape.
6 months ago
Kill Chain
Cox Enterprises Data Breach 2024: Oracle Zero-Day Exploit Compromises Sensitive Data
In June 2024, Cox Enterprises disclosed a significant data breach where attackers exploited a zero-day vulnerability in Oracle E-Business Suite to gain unauthorized access to the company’s network. The exploitation enabled the threat actors to bypass existing security controls, potentially exfiltrating sensitive personal data of customers and employees. The breach was detected after anomalous network activity was flagged, prompting a forensic investigation and subsequent notification to affected individuals. The incident underscores the ongoing risks associated with unpatched enterprise software and the increasing sophistication of threat actors in targeting supply-chain and business applications. This breach is particularly relevant amid a surge in zero-day exploits targeting enterprise management platforms, highlighting the urgency for robust vulnerability management, continuous monitoring, and rapid incident response. Organizations must reassess their exposure to similar risks due to heightened regulatory scrutiny and the evolving tactics used by cybercriminals.
6 months ago
Kill Chain
CISA Flags Critical Oracle Identity Manager Zero-Day as Actively Exploited
In June 2025, a critical zero-day vulnerability (CVE-2025-61757) affecting Oracle Identity Manager was added to CISA’s Known Exploited Vulnerabilities catalog, following credible reports of active exploitation. Attackers leveraged a missing authentication flaw in a critical function, allowing remote, pre-authenticated access and full compromise of affected systems. Organizations using Oracle Identity Manager faced a risk of unauthorized access, credential theft, and lateral movement, with potential for widespread service disruption and data exfiltration across enterprise networks. Remediation required rapid deployment of patches and security controls to prevent further breaches. This incident underscores the rising impact of identity-driven attack vectors targeting core authentication systems, with adversaries increasingly exploiting zero-day flaws in widely-used identity platforms. The exploitation highlights an urgent need for strengthened identity protection, patch management, and zero-trust segmentation as attackers target the intersection of critical infrastructure and identity orchestration.
6 months ago
Kill Chain
Matrix Push C2 Phishing Exposes Fileless Browser Attacks in 2025
In November 2025, a sophisticated phishing campaign was uncovered utilizing a novel command-and-control (C2) platform called Matrix Push C2. The threat actors exploited browser push notifications, fake alerts, and fileless redirection to lure users across multiple operating systems into interacting with malicious links. Researchers observed that the campaign delivered phishing payloads without traditional downloads, thereby evading many endpoint defenses and expanding its cross-platform reach. Impacted organizations reported heightened risks of credential theft, business email compromise, and data exfiltration stemming from the hard-to-detect, browser-native behavior of Matrix Push C2. This incident highlights the escalating threat of fileless attacks and creative social engineering, particularly as businesses increasingly rely on browser-based workflows. The abuse of browser notifications as a phishing vector presents a growing challenge for security teams and underscores the importance of proactive browser and endpoint defenses.
6 months ago
Kill Chain
Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack
In June 2024, several Salesforce customers experienced a significant data breach perpetrated by the ShinyHunters extortion group. Attackers exploited vulnerabilities in a third-party vendor, Gainsight, which had integrations with Salesforce platforms. By compromising Gainsight, ShinyHunters acquired credentials or access tokens, enabling them to exfiltrate sensitive Salesforce customer data from multiple organizations. The breach demonstrates the persistent risk of attacks originating from trusted third-party software supply chains, resulting in the exposure of business and customer information and raising concerns about the security posture of major SaaS ecosystems. This breach highlights a continued trend in which attackers bypass direct controls by targeting vendors in a SaaS environment, leveraging weak third-party access and inadequate segmentation. As businesses increase SaaS adoption and interconnectivity, these attacks demonstrate the urgent need for enhanced third-party risk management and more granular network and identity controls.
6 months ago
Kill Chain
ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024
Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains. This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports