✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Ransomware at a Breaking Point: 85 New Gangs and LockBit’s 2025 Re-Emergence
In Q3 2025, the ransomware threat landscape reached unprecedented fragmentation with 85 active ransomware and extortion groups, including the high-profile resurgence of LockBit following international law enforcement takedowns. Attackers targeted organizations across sectors, leveraging decentralized affiliate models to rapidly launch new ransomware 'brands' — 14 of which debuted this quarter. Tactics included sophisticated lateral movement, exploit of unencrypted east-west traffic, and multifaceted extortion through leak sites. Over 1,590 public victim disclosures underscored the sustained operational tempo, with significant financial and reputational losses reported by victims. This incident signals new urgency for defenders, as ransomware operations grow increasingly resilient and adaptive. The proliferation of new actor groups, coupled with a strong affiliate network and advanced techniques, means that traditional prevention strategies are being routinely bypassed, demanding adoption of modern security controls aligned to emerging frameworks and zero trust principles.
6 months ago
Kill Chain
Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack
In November 2025, the threat actor group known as Dragon Breath launched a targeted cyber campaign aimed at Chinese-speaking users, leveraging a sophisticated multi-stage loader called RONINGLOADER. By deploying trojanized NSIS installers disguised as popular applications like Google Chrome and Microsoft Teams, attackers successfully delivered a modified variant of Gh0st RAT. The malware chain allowed adversaries to bypass security tools, perform covert surveillance, and remotely exfiltrate sensitive data from compromised systems, achieving persistent access and extensive control over infected endpoints. This incident highlights the increasing use of advanced loader chains and tailored social engineering vectors to breach defenses. It reflects a broader trend in cyber threats shifting towards multi-stage, modular attacks capable of disabling endpoint protections and evading detection through highly customized payloads and targeted distribution tactics.
6 months ago
Kill Chain
How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025
In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks. This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.
6 months ago
Kill Chain
Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security
In November 2025, Microsoft released patches to address over 60 vulnerabilities affecting Windows operating systems and a broad suite of its applications, including Office, SQL Server, Visual Studio, and Azure Monitor Agent. Notably, this cycle contained at least one actively exploited zero-day flaw (CVE-2025-62215), a memory corruption vulnerability requiring local access, as well as a critical GDI+ bug (CVE-2025-60274) impacting broad swathes of enterprise and third-party applications. Additionally, a low-complexity Office vulnerability (CVE-2025-62199) enabling remote code execution was highlighted as a high priority for patching. Some users also faced complications enrolling in an extended Windows 10 security update program, partially addressed by out-of-band releases. This incident underscores the ongoing acceleration of zero-day and high-impact vulnerabilities targeting ubiquitous enterprise software, making timely patch deployment mission-critical. As the cadence and exploitation of software vulnerabilities increases, organizations must bolster patch management processes and align with evolving regulatory pressures to minimize risk exposure.
6 months ago
Kill Chain
Fortinet 2025: Multi-Vector AI Campaign Disrupts Global Networks
In early November 2025, a coordinated multi-vector campaign targeted Fortinet infrastructure worldwide, exploiting unpatched vulnerabilities in FortiGate VPN appliances. Attackers—some with ties to Chinese state-affiliated threat groups—combined AI-driven phishing-as-a-service (PhaaS) toolkits, malicious code deployment, and supply chain manipulation to bypass legacy perimeter defenses. The campaign leveraged trusted encrypted channels and cloud infrastructure to evade detection, enabling lateral movement and data exfiltration from government agencies, finance firms, and Fortune 500 companies. Cleanup and containment efforts required full infrastructure reviews and forensic triage, disrupting operations across multiple sectors. This incident exemplifies the accelerating convergence of advanced attacker automation, trusted-tool abuse (AI, VPNs), and commercial cybercrime platforms. Organizations must urgently address gaps in segmentation, encrypted traffic inspection, and detection controls to withstand increasingly stealthy, multi-stage attacks.
6 months ago
Kill Chain
Fortinet FortiWeb WAF Zero-Day Breach: 2024 Vulnerability Exposes Perimeter Defenses
In early June 2024, Fortinet disclosed a critical remote code execution (RCE) vulnerability in its FortiWeb Web Application Firewall (WAF). Identified as CVE-2024-21762, this zero-day bug enables unauthenticated attackers to remotely execute administrative commands on affected WAF devices via specially crafted HTTP requests. Threat actors were observed actively exploiting the flaw in the wild before the vendor released patches, allowing them to potentially compromise sensitive networks, bypass perimeter defenses, and gain high-privilege access to protected applications. Burdened by the high privilege level of administrative access, compromised systems are exposed to data theft, operational disruption, or lateral movement within enterprise networks. The incident highlights an ongoing surge in zero-day exploitation of critical infrastructure solutions, particularly targeting network perimeter and cloud security devices. Preliminary evidence suggests opportunistic attackers and advanced persistent threats are both involved, driving renewed urgency for timely patching, actionable threat detection, and Zero Trust strategies across enterprise and cloud environments.
6 months ago
Kill Chain
Cursor Vulnerability: AI Code Assistant Supply-Chain Flaw Exposes Credentials
In early 2024, security researchers uncovered a significant supply-chain vulnerability affecting Cursor, an AI-powered coding assistant, enabling attackers to hijack Cursor's internal application browser via a malicious MCP (Model Control Protocol) server. Exploiting this weakness, threat actors could inject malicious code through the compromised server, control the tool’s browser processes, and steal sensitive user credentials, potentially jeopardizing developer environments and broader organizational security. The vulnerability allows attackers to manipulate trusted workspace sessions, escalating the risk of lateral movement within corporate infrastructure. This incident highlights the increasing risks associated with AI-driven developer tools and the broader supply chain, reflecting a growing attacker focus on abusing trust relationships within cloud-native and collaborative software platforms. Organizations must revisit supply-chain security and adopt robust detection and response strategies for AI-enabled environments.
6 months ago
Kill Chain
The 2024 Finger Protocol ClickFix Malware Attack: Legacy Protocols Reused for Command and Control
In early 2024, security researchers uncovered that threat actors were actively abusing the decades-old 'finger' protocol—a remote access and user lookup protocol seldom used in modern networks—as a covert command and control (C2) channel for deploying ClickFix malware on Windows devices. Attackers leveraged the unencrypted and often overlooked finger service to quietly retrieve remote commands, allowing compromise of endpoints and escalation of persistent access across targeted corporate environments. The attacks often evaded traditional security controls, highlighting a resurgence of legacy protocol exploitation as a lateral movement and control method that bypasses common detection. This incident demonstrates the increased ingenuity of malware authors in repurposing overlooked network protocols to evade security controls. As threat actors broaden their toolkits to exploit legacy services, organizations with insufficient east-west segmentation, network visibility, or outdated protocol restrictions remain at risk of similar covert command and control attacks.
6 months ago
Kill Chain
ClickFix: How Attackers Exploited finger.exe for Stealthy Network Access in 2023
In November 2023, organizations reported a wave of Living-off-the-Land (LotL) attacks known as ClickFix, in which adversaries abused the legacy finger.exe utility on Windows systems. Attackers exploited finger.exe to retrieve and execute malicious scripts by leveraging the finger protocol over TCP port 79, bypassing endpoint security tools that are often tuned for more common protocols. The technique allowed attackers to maintain stealthy communications and initial access, exposing corporate environments where outbound traffic controls were inadequate. No major ransomware group claimed responsibility, but the campaign highlighted increasing sophistication in LotL exploitation, putting enterprises at risk of lateral movement and data exfiltration. This incident is highly relevant given the resurgence of attackers abusing built-in OS utilities to evade detection, as well as increased regulatory scrutiny over encrypted and segmented internal network traffic. Organizations must reevaluate their defenses against legacy protocol abuse.
6 months ago
Kill Chain
Akira Ransomware Hits Nutanix VMs, Exposing Threats to Critical Sectors
In early 2024, the Akira ransomware-as-a-service (RaaS) operation expanded its attack capabilities by targeting Nutanix virtual machines, allowing it to compromise both Windows and Linux workloads within critical infrastructure and enterprise environments. Attackers exploited new vulnerabilities and lateral movement techniques to rapidly deploy ransomware, encrypting data at scale and causing significant business disruption among targeted organizations. Notably, Akira’s evolving tooling enabled them to bypass certain traditional detection measures and exfiltrate sensitive information to pressure victims into ransom payment. This campaign highlights the increasing sophistication of ransomware operators and the growing risk posed to hybrid and multicloud environments. The success of the Akira group against high-value sectors underscores the urgent need for advanced east-west traffic security, visibility, and robust segmentation strategies.
6 months ago
Kill Chain
FortiWeb CVE-2025-64446: Honeypot Reveals Automated Web App Exploits
In November 2025, researchers observed active exploit attempts targeting FortiWeb appliances via CVE-2025-64446. Attackers sent specially crafted POST requests to FortiWeb's administration interface, leveraging the vulnerability to create privileged admin accounts remotely. The attack, first detected in internet-facing honeypots, allowed adversaries potential unauthorized control over victim devices and lateral access to connected environments. Organizations using vulnerable firmware versions face the risk of compromise if patches are not applied. This incident highlights the rapid adoption and automation of new web application exploits by threat actors. With FortiWeb appliances deployed widely across critical infrastructure, mass exploitation attempts have increased urgency for organizations to implement robust patch management and web application security controls.
6 months ago
Kill Chain
Fortinet FortiWeb Zero-Day Exploitation: An Urgent 2024 Security Wake-Up Call
In early 2024, Fortinet was found to have silently patched a critical zero-day vulnerability (CVE-2024-23108) affecting its FortiWeb Web Application Firewall (WAF). Exploited by unknown threat actors, this flaw enabled attackers to remotely execute code on affected devices, bypassing authentication and gaining access to sensitive environments. The exploitation began prior to public disclosure, resulting in exposure and compromise of multiple enterprise networks relying on FortiWeb for web application security. Fortinet responded by releasing a fix without an immediate advisory, which led to delayed recognition and patching by affected organizations. The incident highlights the ongoing threat posed by rapidly exploited zero-days in widely deployed security appliances, emphasizing the critical need for timely patch management and stringent supply chain trust. The continued targeting of network security infrastructure is a concerning trend in 2024, increasing risk for enterprises across sectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports