✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Operation WrtHug: Tens of Thousands of ASUS Routers Hijacked in Global Botnet Surge
In late 2025, tens of thousands of end-of-life ASUS routers worldwide were hijacked in a large-scale operation dubbed "WrtHug." The attackers exploited six unpatched vulnerabilities in outdated ASUS WRT firmware, targeting devices primarily in Taiwan, the U.S., and Russia, among others. After gaining unauthorized access, WrtHug actors enrolled these routers into a global botnet, leveraging them for coordinated command-and-control traffic and potentially for further attacks. The campaign highlighted the sustained risk posed by unsupported network equipment in both consumer and business environments. This incident underscores an ongoing surge in attacks targeting aging and end-of-life IoT devices, as cybercriminals capitalize on lapses in patching and lifecycle management. Organizations globally are under renewed pressure to inventory, segment, and securely retire vulnerable network infrastructure as such botnet tactics intensify.
6 months ago
Kill Chain
NHS Flags PoC Exploit for 7-Zip Symlink RCE Vulnerability (CVE-2025-11001)
In November 2025, NHS England Digital issued an advisory regarding a significant vulnerability (CVE-2025-11001) in the popular 7-Zip compression software. While no active in-the-wild exploitation was detected, a publicly available proof-of-concept (PoC) exploit for a symbolic link–based remote code execution (RCE) flaw raised concerns of imminent risk. The flaw, if exploited, could allow attackers to execute arbitrary code on systems using 7-Zip, threatening the confidentiality, integrity, and availability of healthcare data critical to NHS operations. Security teams were urged to prioritize patching and closely monitor for suspicious activity. This incident highlights a broader industry trend: attackers are rapidly weaponizing PoC exploits for newly disclosed vulnerabilities, targeting widely used utilities to enable lateral movement and privilege escalation. The urgency of patching and proactive threat detection has never been greater, especially for organizations in regulated sectors like healthcare.
6 months ago
Kill Chain
Cloudflare 2025 Outage: A Wakeup Call for Web Security Resilience
In November 2025, Cloudflare suffered a significant intermittent outage lasting approximately eight hours, which disrupted access for many major websites relying on its services for security and DNS management. The outage was caused by an internal configuration error that expanded a critical feature file, impacting Cloudflare's Bot Management system and resulting in platform instability. Some organizations temporarily bypassed Cloudflare, exposing themselves directly to internet traffic and revealing vulnerabilities previously shielded by Cloudflare's protective layers, such as web application firewall (WAF), bot filtering, and DNS controls. These exposures led to increased malicious probing, raising concerns about previously undetected weaknesses and an overreliance on single-vendor security solutions. The incident highlights the growing operational and security risks of single-vendor dependency, especially as organizations rely more heavily on integrated cloud platforms for web security and availability. Broad industry adoption of zero trust and multi-cloud strategies is now a pressing priority to mitigate similar service disruptions and emergent threats.
6 months ago
Kill Chain
CISA Flags New Chromium Browser Exploit: CVE-2025-13223 in Active Use
On November 19, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-13223—an actively exploited type confusion vulnerability in the Google Chromium V8 JavaScript engine—to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows remote attackers to execute arbitrary code via a crafted web page, exploiting weaknesses in Chromium-based browsers used by federal and commercial entities. Threat actors have been leveraging this vulnerability to deliver malware and potentially gain unauthorized access to systems, heightening risk across government and enterprise environments. This incident is highly relevant as attackers continue to target zero-day and rapidly weaponized browser flaws, reflecting a broader trend of exploiting client-side vulnerabilities to bypass traditional network defenses. Regulatory and industry pressure for rapid patch management and strong endpoint protection is intensifying as attackers' tactics evolve.
6 months ago
Kill Chain
Cloud Firewall Flaws Lead to Widespread IoT Takeovers in 2024
In early 2024, security researchers uncovered a critical cloud misconfiguration enabling silent takeover of internet-connected IoT devices by exploiting gaps in firewall and router management interfaces. Attackers, leveraging lax default policies and insufficient segmentation in multi-cloud environments, gained unauthorized access to endpoints despite security software being in place. The exploit did not require the devices to be directly connected to the public internet—instead, it relied on weaknesses within cloud firewall interfaces and poor east-west traffic controls, allowing attackers to pivot laterally and compromise large numbers of devices with little to no detection. The resulting impact includes device disruption, risk of data exfiltration, and potential staging for larger attacks. This incident comes amid a surge in attacks against IoT and operational technology, with adversaries increasingly targeting missteps in cloud security architectures rather than application-level flaws. The trend underscores the urgency for organizations to implement multi-layered segmentation, robust policy enforcement, and continuous cloud configuration monitoring to defend against rapidly-evolving lateral movement tactics.
6 months ago
Kill Chain
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.
6 months ago
Kill Chain
Anatomy of an Akira Ransomware Attack: 42 Days Hidden After a Fake CAPTCHA
In early 2024, a sophisticated cyberattack attributed to the Akira ransomware group exploited a fake CAPTCHA page to infiltrate an organization's environment. Attackers used this social engineering technique as an entry point, deploying malware that enabled persistent access and undetected movement across internal systems for 42 days. During this period, lateral movement and privilege escalation allowed the attackers to exfiltrate data and ultimately deploy ransomware, encrypting vital business assets and causing significant operational disruption. The incident illustrates how modern ransomware actors leverage stealth, deception, and extended dwell times to maximize their impact. This case underscores an escalating trend of increasingly complex and targeted ransomware attacks that blend technical exploitation with effective social engineering. Organizations are being challenged to enhance east-west traffic security, real-time threat detection, and zero trust segmentation to counter these evolving threats.
6 months ago
Kill Chain
Malicious NPM Packages Exploit Adspect in 2024 Supply Chain Breach
In June 2024, security researchers uncovered a supply chain attack involving seven malicious packages on the NPM registry that abused the Adspect cloud-based service. Attackers used these packages to redirect users through Adspect, circumventing many security sandboxes and researcher analysis tools. This sophisticated evasion allowed threat actors to selectively route potential victims to malicious payloads while deflecting scrutiny from security firms. The malicious packages were rapidly removed from NPM, but not before posing a significant risk to open-source software supply chains. This incident highlights the increasing exploitation of trusted third-party platforms and infrastructure in software supply chain attacks. With adversaries leveraging evasive redirects and advanced obfuscation tactics, organizations face a growing need for robust dependency management, automated threat detection, and enhanced monitoring of public code repositories.
6 months ago
Kill Chain
Fortinet FortiWeb Zero-Day Abuse: 2024 Attack Highlights Security Device Risks
In June 2024, Fortinet disclosed a critical zero-day vulnerability in its FortiWeb web application firewall that was being actively exploited in the wild. Threat actors leveraged the unknown flaw to gain unauthorized access to targeted organizations, bypassing authentication and potentially altering application configurations or exfiltrating sensitive data. Fortinet responded promptly by releasing security patches and urging customers to update affected devices, while security researchers warned this campaign was already impacting several organizations before public disclosure. This incident is part of a growing trend of sophisticated attacks targeting network and security appliances through undisclosed vulnerabilities. Organizations face heightened risk as attackers weaponize zero-days more quickly, making swift patch management and layered controls essential to defending digital infrastructure.
6 months ago
Kill Chain
Google Chrome 2024 Zero-Day Exploited in the Wild: What You Need to Know
In June 2024, Google disclosed and patched a critical zero-day vulnerability in the Chrome web browser (CVE-2024-5274) that had actively been exploited in the wild. Attackers leveraged a type confusion flaw in Chrome’s V8 JavaScript engine to execute arbitrary code on victim devices, enabling full compromise of targeted systems. Google's rapid response—releasing an emergency security update—helped mitigate exploitation risks. The vulnerability represented the seventh zero-day affecting Chrome this year, underscoring persistent targeting of popular browsers for initial access into corporate and consumer environments. This incident illustrates the sustained threat posed by browser zero-days and the increasing velocity with which attackers are weaponizing new flaws. As web browsers remain a ubiquitous endpoint attack vector, organizations must ensure rapid patch cycles and layered security controls to limit exposure.
6 months ago
Kill Chain
Tycoon 2FA: How Phishing-as-a-Service Broke Legacy MFA at Scale in 2024
In 2024, cybercriminals leveraged the Tycoon Phishing-as-a-Service (PaaS) platform to orchestrate over 64,000 successful real-time attacks bypassing legacy multi-factor authentication (MFA) with relay-based phishing toolkits. Tycoon allowed even low-skilled attackers to automate the interception and relay of users’ MFA tokens, defeating common one-time passcodes and push-based authentication. This Phishing-as-a-Service campaign targeted a wide array of industries and organizations, exposing user credentials and compromising sensitive systems at scale. The incident underscores the urgent collapse of legacy MFA methods under modern, scalable phishing threats. The widespread exposure from Tycoon demonstrates how phishing-resistant authentication (such as FIDO2 hardware tokens and biometrics) are now critical. Regulatory agencies and security experts have since elevated calls for organizations to rapidly phase out vulnerable MFA in favor of hardware-backed solutions, as attackers weaponize automated, scalable PaaS infrastructure.
6 months ago
Kill Chain
Google Chrome’s 2025 V8 Zero-Day: What Organizations Must Do After the Latest Exploit
In June 2025, Google disclosed an actively exploited zero-day vulnerability (CVE-2025-13223) in the V8 JavaScript and WebAssembly engine powering Chrome. Attackers leveraged this type confusion flaw to execute arbitrary code or trigger program crashes, enabling them to compromise vulnerable browsers. Google promptly released patches to address the flaw after receiving reports of in-the-wild exploitation. At-risk users included anyone running unpatched Chrome versions across platforms, with attackers potentially able to hijack sessions, install malware, or steal sensitive data simply by enticing users to visit a malicious web page. This incident highlights the persistent risks posed by emerging browser vulnerabilities, as both sophisticated threat actors and opportunistic cybercriminals increasingly exploit zero-day flaws for rapid compromise. Security teams face mounting urgency to prioritize browser patching cycles to counter fast-moving, exploitation-ready threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports