✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Fortinet Hit Again: WAF Zero-Day Exploitation Prompts Security Scrutiny
In June 2024, Fortinet disclosed that a second zero-day vulnerability affecting its FortiWeb Web Application Firewall (WAF) products was actively exploited in the wild. Attackers leveraged the undisclosed flaw to bypass security controls and potentially gain unauthorized remote access to customer environments, raising major concerns about the rapidity and transparency of Fortinet's incident response. The breach followed an earlier 2024 WAF zero-day, indicating a worrying escalation in threat actor targeting and sophistication against network-edge defense systems. This incident underscores the increasing prevalence of zero-day attacks against security appliances themselves, a trend accelerated by sophisticated threat actors who seek to exploit both technical weaknesses and delayed vendor responses. Rapid incident disclosure and robust patching are now critical to safeguarding key infrastructure.
6 months ago
Kill Chain
Five Eyes Target Bulletproof Hosting: Sanctions Rock Media Land & Aeza Group in 2024
In June 2024, the Five Eyes intelligence alliance—comprising the US, UK, and Australia—executed coordinated sanctions against Russia-based bulletproof hosting provider Media Land, its executives, three subsidiaries, and entities supporting the previously sanctioned Aeza Group. These hosting providers were identified as key enablers for major ransomware groups (such as LockBit, BlackSuit, and Play), facilitating operations including malware delivery, phishing, and data extortion. Bulletproof hosting infrastructure aided threat actors by allowing them to mask malicious activity and evade law enforcement action, thereby supporting cybercrime at scale for nearly a decade. This incident highlights the increasing focus by global regulators and law enforcement on disrupting the infrastructure and services that underpin the cybercrime ecosystem, rather than targeting individual attackers. The coordinated international response signals a trend toward attacking the foundational services cybercriminals rely on, underscoring the evolving strategies required to address rising ransomware and data extortion threats.
6 months ago
Kill Chain
PlushDaemon Supply Chain Breach: How Integrity Controls Failed in the 2024 Update Hijack
In early 2024, the China-aligned 'PlushDaemon' advanced persistent threat leveraged software update channels in supply-chain environments to deliver malicious payloads. Attackers infiltrated legitimate update infrastructure, intercepting and modifying update traffic destined for victim organizations across multiple sectors. The campaign enabled remote code execution, deployment of backdoors, and potential data exfiltration by masquerading malicious code as legitimate updates, significantly increasing evasion capabilities and operational impact. Victims discovered the compromise after anomalous network activity and unauthorized privilege escalations were observed within internal systems. This attack highlights a growing trend of sophisticated supply-chain compromises, demonstrating an escalation in targeting trusted dependencies to bypass traditional perimeter defenses. As threat actors expand their tactics and exploit trusted communications, organizations face heightened urgency to enforce software integrity, robust network segmentation, and end-to-end traffic inspection.
6 months ago
Kill Chain
Meet ShinySp1d3r: How Affiliate Ransomware Powered by ShinyHunters Ups the Stakes
In mid-2024, cybersecurity researchers discovered an in-development version of the ShinySp1d3r ransomware-as-a-service (RaaS) platform, believed to be created by the infamous ShinyHunters threat group. The platform equips criminal affiliates with a toolkit designed to automate ransomware deployment, data encryption, and multi-extortion capabilities. Early builds circulated within cybercrime forums preview advanced features, such as dashboard controls, automated leak sites, and an affiliate earnings model, underscoring the maturity and commercialization of the threat. The potential for widespread, coordinated attacks against enterprises and public sector organizations is significantly heightened by the accessibility and ease-of-use facilitated by this service. The emergence of ShinySp1d3r represents a growing trend of professionalized cybercrime, where sophisticated threat actors develop and market turnkey attack platforms to less-skilled operators. This further accelerates ransomware proliferation and amplifies the risks for organizations reliant on digital infrastructure.
6 months ago
Kill Chain
CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks
In June 2024, U.S. government agencies were urgently ordered by CISA to patch a critical vulnerability in Fortinet's FortiWeb web application firewall after it was discovered being exploited as a zero-day. Threat actors leveraged this flaw to bypass security controls, potentially gaining unauthorized access to sensitive government systems. The incident underscores the persistent targeting of network edge devices and highlights the risks associated with unpatched security infrastructure. The rapid CISA directive required agencies to address the exploit within seven days, reflecting the severe operational risk and potential for further compromise. This event demonstrates a rising focus on web application and perimeter device vulnerabilities by sophisticated adversaries, especially those exploiting zero-days. The urgency of the directive and the exploitation method signal a larger industry trend: attackers increasingly prioritize zero-day vulnerabilities in widely deployed security products to maximize impact and evade detection.
6 months ago
Kill Chain
Operation WrtHug: How Legacy ASUS Routers Became a Global Botnet in 2024
In early 2024, thousands of end-of-life ASUS WRT routers worldwide were compromised in a large-scale campaign dubbed "Operation WrtHug". Attackers exploited at least six known vulnerabilities in outdated router firmware to hijack control of the devices. These compromised routers were assimilated into a new botnet infrastructure, enabling malicious actors to facilitate unauthorized traffic routing, launch further attacks, and potentially intercept sensitive data passing through these compromised endpoints. The incident points to neglected device lifecycle management and widespread exposure due to unpatched, unsupported consumer hardware. This breach is particularly notable as it reflects a growing trend: attackers shifting focus to vulnerable, unmaintained IoT and networking hardware. With legacy devices lacking security updates, organizations face heightened risk of compromise and regulatory scrutiny, while defenders must urgently address asset visibility and enforcement across distributed infrastructure.
6 months ago
Kill Chain
Sanctions Hit Russian Bulletproof Hosting Providers Backing Global Ransomware
In June 2024, the United States, together with the United Kingdom and Australia, imposed sanctions on Russian bulletproof hosting provider Media Land and associated entities. Investigations revealed these providers had knowingly facilitated ransomware operations and other cybercriminal activities by offering infrastructure shielding malicious actors from law enforcement, particularly ransomware gangs operating out of Russia. The sanctions block their financial assets and prohibit transactions, aiming to disrupt the ecosystem supporting high-profile global ransomware attacks and cybercrime. This incident is significant amid a surge in ransomware and supply-chain attacks worldwide, with threat actors increasingly relying on bulletproof hosting to evade detection. Governments are moving quickly to cut off these enablers as part of a broader strategy against organized cybercrime.
6 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
6 months ago
Kill Chain
FortiWeb CVE-2025-58034: Command Injection Attack on Fortinet's WAF
In November 2025, Fortinet disclosed a medium-severity vulnerability in its FortiWeb application firewall, tracked as CVE-2025-58034 (CVSS 6.7), which was found exploited in the wild. The flaw is an OS command injection issue (CWE-78) that allows authenticated attackers to execute unauthorized OS commands via improper neutralization of special elements. Attackers leveraged this weakness to gain control over vulnerable web application environments, potentially facilitating lateral movement, data access, and further exploitation, with threat activity detected before a patch was widely adopted. This incident highlights a persistent trend of attackers rapidly weaponizing new vulnerabilities in widely deployed web application security platforms. With adversaries increasingly targeting edge appliances and exploiting authentication weaknesses, organizations must prioritize timely vulnerability management and layered defense to protect sensitive workloads.
6 months ago
Kill Chain
Ransomware Disrupts European Airports in 2025: HardBit & SonicWall VPN Exploit
In September 2025, a coordinated HardBit ransomware attack caused significant operational disruptions across several European airports. The attack exploited a vulnerability in SonicWall SSL VPN devices (CVE-2024-40766), allowing threat actors to bypass multi-factor authentication and gain unauthorized access to critical infrastructure. Prompt law enforcement action led to the arrest of an initial suspect by the UK’s National Crime Agency, though details remain limited as investigations continue. The attack, labeled by researchers as primitive yet effective, underscores how quickly threat actors are leveraging both publicly available exploits and compromised credentials to disrupt essential services with ransomware. This event made headlines due to its impact on vital transportation infrastructure and prompted an international response highlighting the growing urgency for robust network segmentation, encrypted traffic measures, and rapid threat detection. The incident also reflects a broader trend of ransomware actors increasingly targeting critical sectors using innovative entry vectors and expanding their global footprint.
6 months ago
Kill Chain
ServiceNow AI Agents Breached in 2025 via Second-Order Prompt Injection
In November 2025, security researchers uncovered a novel method by which ServiceNow's Now Assist generative AI platform could be manipulated through second-order prompt injection attacks. By exploiting default configurations and inherent agent-to-agent communication, attackers could coerce agentic AI features into executing unauthorized operations. This exposure allowed malicious actors to access, copy, and exfiltrate sensitive enterprise data without proper user authorization. The attack leverages prompt injection to bypass intended policy boundaries, posing significant data risk to organizations relying on ServiceNow’s AI-driven automations. This incident highlights a growing threat landscape in which AI agent-to-agent interactions are harnessed for sophisticated attacks. With increased enterprise adoption of generative AI and autonomous agents, security around configuration and prompt validation has become mission-critical. Organizations should assess agent communication safeguards and be vigilant against emerging prompt injection and shadow AI risks.
6 months ago
Kill Chain
EdgeStepper: PlushDaemon’s DNS Hijack Shakes Supply Chain Trust
In late 2025, the threat actor PlushDaemon leveraged a custom Go-based implant named EdgeStepper to facilitate a sophisticated supply chain attack targeting organizations relying on automated software updates. By hijacking DNS queries via EdgeStepper, attackers rerouted legitimate update traffic to attacker-controlled infrastructure, covertly delivering malware payloads. This adversary-in-the-middle campaign exploited a weakness in outbound traffic validation and DNS trust, leading to silent compromise of enterprise endpoints through poisoned software update mechanisms. The incident resulted in widespread concerns over supply chain integrity and exposed gaps in security monitoring of encrypted or internal network flows. This incident highlights the growing trend of adversaries exploiting DNS and software supply chains as primary attack vectors. With regulatory and industry focus tightening on secure update mechanisms and zero trust, similar AitM tactics are escalating in both frequency and sophistication, requiring renewed urgency for organizations to enhance detection at the DNS and network boundary layers.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports