✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
CometJacking: How Prompt Injection Breached Perplexity AI’s Browser in 2025
In November 2025, cybersecurity researchers discovered a significant prompt injection vulnerability dubbed 'CometJacking' affecting Perplexity’s Comet AI browser. This attack exploited URL parameters to inject malicious commands that instructed the AI agent to extract sensitive data—such as Gmail messages and Google Calendar invites—from connected services and exfiltrate them to external endpoints, all without any user interaction or credentials. By leveraging the AI’s lack of discrimination between trusted and untrusted instructions, attackers could bypass access controls and evade existing security checks, potentially exposing confidential information from a wide set of users and organizations adopting the AI-powered browser for daily workflows. This incident highlights a rapidly evolving threat landscape where prompt injection attacks against generative AI platforms are surging. As organizations increasingly integrate AI agents with sensitive data and workflow automation, risks of unauthorized data access and exfiltration are escalating, prompting urgent action from security teams and regulatory bodies.
6 months ago
Kill Chain
APT37: North Korean Hackers Weaponize Google Find Hub for Android Data-Wiping Attacks (2024)
In early 2024, North Korean threat group APT37 (also known as KONNI) leveraged Google’s Find My Device Hub functionality to remotely track, lock, and factory reset Android devices belonging to targeted individuals. The attack chain involved initial compromise of Android devices via malicious apps or phishing, after which the threat actors abused legitimate Google mobile device management tools to erase and destroy data on compromised endpoints. As a result, affected organizations and individuals suffered total loss of sensitive information and operational disruption, with a clear intent by attackers to destroy evidence and hinder forensic investigations. This incident highlights the growing sophistication of APTs in subverting trusted platform features for destructive ends, signaling elevated risk for organizations relying on mobile endpoints, especially in regions or sectors of geopolitical interest. The trend reveals a shift toward wiper operations and supply chain risks in the mobile ecosystem.
6 months ago
Kill Chain
Expr-eval JavaScript Library Faces Supply-Chain RCE Vulnerability in 2024
In March 2024, a critical remote code execution (RCE) vulnerability was identified in expr-eval, a widely used JavaScript mathematical expression evaluator with over 800,000 weekly NPM downloads. The flaw, if exploited through maliciously crafted input, allowed attackers to execute arbitrary code within applications leveraging the vulnerable versions of the library. As expr-eval is integrated into numerous projects and frameworks, the supply-chain impact was significant, exposing countless downstream applications to the risk of compromise and highlighting the cascading dangers of third-party dependency vulnerabilities. This incident underscores the increasing focus by attackers on widely adopted open-source libraries as high-leverage supply-chain targets. The expr-eval vulnerability echoes a broader industry trend where modern development practices introduce risks outside direct organizational control, prompting renewed concerns about dependency management, zero trust for software supply chains, and regulatory calls for heightened software bill of materials (SBOM) transparency.
6 months ago
Kill Chain
Yanluowang Initial Access Broker’s Guilty Plea: Ransomware Supply Chain Exposed
Between July 2021 and November 2022, a Russian national acted as an initial access broker (IAB) for the Yanluowang ransomware group, facilitating network entry for at least eight U.S. companies. After gaining unauthorized access, the IAB sold credentials and footholds to Yanluowang ransomware operators, enabling follow-on attacks that resulted in significant business disruptions, data encryption, and attempted extortion. U.S. law enforcement’s investigation led to the broker pleading guilty, marking a rare disruption of the ransomware ecosystem’s supply chain. This case underscores the increasing professionalization of ransomware operations, where roles like IABs are critical in enabling threat actors at scale. The incident's legal resolution reflects broader efforts to deter cybercrime, yet highlights the persistent risks posed by RaaS models and outsourced attacker infrastructure.
6 months ago
Kill Chain
GlassWorm: Malicious VS Code Extensions Trigger a New Wave of Supply-Chain Attacks
In late 2025, cybersecurity researchers discovered the 'GlassWorm' malware campaign actively targeting the Visual Studio Code (VS Code) ecosystem via three malicious extensions available on the official marketplace. With over 7,400 combined downloads, these extensions enabled threat actors to inject malware directly into developers' environments, facilitating credential theft, remote access, and potential downstream supply-chain attacks. Attackers leveraged trusted community tools as the entry vector, bypassing traditional perimeter defenses to gain a foothold in development workflows and potentially propagate malware throughout interconnected repositories. This incident underscores the rising prevalence of supply-chain attacks in the software development ecosystem and the unique risks posed by compromised IDE extensions. The popularity of VS Code amplifies the potential blast radius, highlighting an urgent need for improved extension vetting, granular access controls, and continuous threat monitoring within CI/CD pipelines.
6 months ago
Kill Chain
CISA Orders Emergency Patching After Samsung Zero-Day Exploited in LandFall Spyware Attacks
In June 2024, U.S. federal agencies were ordered by CISA to urgently patch a critical Samsung zero-day vulnerability (CVE-2023-21492) after evidence emerged of its exploitation in targeted attacks delivering LandFall spyware. The attackers leveraged the flaw, which enabled privilege escalation, to compromise Samsung Android devices of high-value targets via WhatsApp. Once exploited, the vulnerability allowed unauthorized actors to bypass security controls, deploy surveillance tools, and covertly exfiltrate sensitive communications and data from affected devices, potentially impacting agency operations and confidentiality. This incident highlights a growing trend of mobile zero-day exploitation linked to sophisticated surveillance operations targeting both governmental and private sector entities. The rapid response from CISA underlines the rising regulatory and operational urgency as attackers increasingly exploit unpatched endpoints and messaging platforms in tailored cyber-espionage campaigns.
6 months ago
Kill Chain
Quantum Route Redirect PhaaS: The 2024 Microsoft 365 Phishing Surge
In 2024, cybersecurity researchers discovered that a Phishing-as-a-Service (PhaaS) platform named Quantum Route Redirect orchestrated a large-scale credential theft campaign targeting Microsoft 365 users globally. The threat actors leveraged a distributed network of roughly 1,000 malicious domains to automate phishing attacks and evade detection. Victims were lured through convincing emails, redirecting them seamlessly through multiple stages to capture login credentials. The campaign exploited the trust in corporate SaaS platforms, enabling attackers to compromise user identities, access sensitive business data, and potentially facilitate subsequent attacks across affected organizations. The incident highlighted widespread operational and reputational risks for enterprises relying on cloud collaboration platforms. This incident underscores the growing threat posed by PhaaS platforms, which are lowering the entry barrier for cybercriminals to launch sophisticated, scalable phishing campaigns. As email and identity-based attacks surge, organizations face urgent pressure to reinforce cloud security, strengthen user awareness, and adopt zero-trust frameworks to defend against evolving social engineering tactics.
6 months ago
Kill Chain
AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap
In early November 2025, a series of sophisticated cyberattacks targeted enterprise and consumer systems worldwide, exploiting vulnerabilities in Hyper-V virtual machines, RDP protocols, and leveraging malicious AI bots. Attackers deployed stealthy malware within virtualized environments to evade detection, while advanced spyware campaigns targeted Android devices using side-channel techniques to capture sensitive AI chat data. Additionally, high-profile service disruptions, including a mass WhatsApp account lockdown, affected millions of users and raised concerns about systemic vulnerabilities and cross-platform exploitation. The threat actors behind these incidents demonstrated new levels of coordination and adaptability, with alliances between major cybercrime groups amplifying the scope and impact of the campaigns. This incident underscores an accelerating trend toward multi-vector, AI-enabled cybercrime and highlights the convergence of ransomware, lateral movement, and novel attack methods across cloud and hybrid infrastructures. Security leaders should anticipate further escalation in both the sophistication and frequency of such attacks through 2025, heightening urgency for layered defenses and zero trust strategies.
6 months ago
Kill Chain
Konni APT Exploits Google’s Find Hub to Launch Data-Wiping Attacks
In late 2025, the North Korea-linked threat actor known as Konni (also referred to as Earth Imp, Opal Sleet, TA406, and Vedalia) launched a sophisticated campaign targeting Android and Windows users by abusing Google’s Find Hub functionality as a remote data-wiping weapon. The attackers impersonated psychological counselors and North Korean human rights activists, distributing malware via fake stress-relief applications that enabled remote access, data theft, and destructive wipes. The operation leveraged advanced evasion tactics, encrypted traffic channels, and targeted high-value individuals, resulting in significant loss and compromise of sensitive personal and organizational information. This incident exemplifies the growing risk from state-affiliated actors using social engineering and legitimate platform abuse to bypass defenses. With threat techniques evolving, organizations must now prioritize threat hunting, advance east-west traffic visibility, and enforce robust segmentation policies to catch and contain similar attacks.
6 months ago
Kill Chain
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.
6 months ago
Kill Chain
CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)
In November 2025, CISA added CVE-2025-21042, an out-of-bounds write vulnerability affecting Samsung Mobile Devices, to its Known Exploited Vulnerabilities (KEV) Catalog following active exploitation in the wild. Threat actors have leveraged this flaw to gain unauthorized control over affected devices, potentially allowing them to execute arbitrary code, escalate privileges, and compromise sensitive user data. The vulnerability poses significant risks to both federal agencies and commercial enterprises, prompting CISA to mandate remediation by federal civilian agencies under Binding Operational Directive (BOD) 22-01. Failure to remediate exposes organizations to data breaches and operational disruption. This incident highlights a broader wave of targeted exploits against widely used mobile platforms, illustrating attackers’ ongoing shift toward mobile devices as primary entry vectors. With regulatory attention intensifying, the urgency for rapid vulnerability management and proactive defense measures is escalated for all sectors.
6 months ago
Kill Chain
TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves
In November 2025, researchers disclosed a critical hardware attack known as TEE.fail, which compromised secure enclaves (trusted execution environments or TEEs) across Intel, AMD, and ARM chips. By placing a small hardware device between a DDR5 memory chip and the motherboard, and leveraging kernel-level privileges, attackers were able to bypass the most advanced TEE protections including Confidential Compute, SEV-SNP, and TDX/SDX. Once exploited, these secure enclaves could no longer be trusted to protect sensitive data in-use, raising major concerns for cloud providers, enterprises, and users reliant on confidential computing. The attack’s low cost, simplicity, and applicability to modern hardware make it a significant development, reflecting growing sophistication in hardware-level threats. Regulatory scrutiny and industry attention have intensified as organizations reevaluate their trust assumptions and risk models for sensitive workloads.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports