Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2610 threat reports
Page 177 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 21132124 / 2610 reports
runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024
Impact· low

runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024

In June 2024, critical vulnerabilities (CVE-2024-21626, CVE-2024-21627, and CVE-2024-21628) were disclosed in the runC container runtime, which underpins Docker, Kubernetes, and many modern container platforms. These flaws could be exploited by attackers to break out of a container, bypassing isolation controls and gaining unauthorized access to the underlying host system. A successful exploit would allow lateral movement and potentially compromise entire cloud or on-premises environments. Prompt patching and risk assessment are essential, as proof-of-concept exploits have already been published in the wild. This incident underscores the increasing sophistication and focus of attackers on supply chain and containerization technologies, as organizations accelerate cloud and DevOps adoption. As regulatory expectations around zero trust and runtime controls intensify, keeping pace with container threat vectors is now mission-critical for enterprise security teams.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem
Impact· low

GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem

In June 2024, the GlassWorm malware resurfaced in a significant supply chain attack on the OpenVSX and Visual Studio Code (VSCode) extension marketplaces. Threat actors uploaded three malicious extensions, which were collectively downloaded over 10,000 times before detection and removal. These extensions were designed to compromise developer environments by deploying malware capable of exfiltrating credentials and enabling persistent access. The attack leveraged trusted open-source ecosystems, making it difficult for end users and organizations to detect the compromise until indicators of compromise (IoCs) were published, potentially exposing sensitive data and intellectual property. This event underscores a broader rise in supply chain attacks targeting developer tools and open-source package ecosystems. The campaign highlights the urgent need for rigorous code vetting, extension auditing, and enhanced supply chain security controls as attackers increasingly exploit automated trust in widely used development platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic
Impact· medium

Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic

In late 2025, Microsoft researchers uncovered the 'Whisper Leak' side-channel attack, a novel method allowing passive adversaries to deduce the topics of conversations with streaming AI language models despite the use of encrypted, high-performance network protocols. Attackers exploited traffic analysis techniques, observing packet timing and size patterns, to infer sensitive discussion details traversing enterprise VPNs and encrypted links. Although private circuit encryption such as MACsec and IPsec was in place, the attack effectively bypassed traditional data-in-transit security controls, raising concerns for sectors leveraging AI in sensitive communications. This incident is significant as it highlights an emerging risk where encrypted cloud AI traffic can be compromised via sophisticated traffic analysis, just as generative AI adoption is surging across regulated industries. It illustrates evolving attacker sophistication beyond classical exploits, prompting urgent review of AI data security and zero trust segmentation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
'Ransomvibing' Supply Chain Attack Strikes Visual Studio Extension Marketplace
Impact· medium

'Ransomvibing' Supply Chain Attack Strikes Visual Studio Extension Marketplace

In early 2024, a malicious Visual Studio Code extension named 'Ransomvibing' was discovered on the Visual Studio Marketplace. The extension used AI-generated code to encrypt and exfiltrate sensitive project data from developer environments, leveraging encrypted outbound traffic to evade traditional detection methods. Despite containing telltale signs of automation and suspicious behavior, the extension bypassed security controls and was downloaded before being taken down, exposing users to significant intellectual property and operational risks associated with a compromised development supply chain. This incident highlights growing risks in open-source and extension marketplaces, as attackers increasingly exploit trusted software ecosystems with novel supply-chain techniques. Organizations should prioritize continuous monitoring of third-party integrations and reinforce their zero trust controls in response to evolving adversary methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Landfall Malware: Covert Mobile Surveillance Hits Samsung Galaxy in 2024
Impact· medium

Landfall Malware: Covert Mobile Surveillance Hits Samsung Galaxy in 2024

In early 2024, cybersecurity researchers uncovered a sophisticated mobile surveillance campaign targeting Samsung Galaxy users through a malware strain dubbed 'Landfall.' Delivered primarily via malicious apps and phishing schemes, Landfall granted attackers covert access to device microphones, cameras, geolocation, and sensitive stored data. The threat actors capitalized on advanced evasion tactics to remain undetected, enabling them to record conversations, track user locations, collect photos, and exfiltrate contacts without the victims’ knowledge. The incident highlights the growing complexity of targeted mobile threats and the operational risks facing organizations with a mobile workforce. With the rise of mobile malware like Landfall exploiting modern smartphones’ vast attack surface, security teams must reassess their controls for device management, east-west traffic monitoring, and policy enforcement. This case underscores the urgency for enterprises to adopt zero trust defenses and adapt to evolving mobile threat tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT Groups Exploit Hybrid & Multicloud Gaps: Insights from ESET Q2–Q3 2025 Activity Report
Impact· medium

APT Groups Exploit Hybrid & Multicloud Gaps: Insights from ESET Q2–Q3 2025 Activity Report

In Q2 and Q3 of 2025, ESET Research identified a surge in advanced persistent threat (APT) activity, with multiple sophisticated threat actors targeting organizations across various industries and geographies. These groups leveraged techniques such as east-west lateral movement within hybrid and multicloud environments, encrypted traffic tunneling, and exploitation of zero trust segmentation gaps. Attackers infiltrated networks via phishing campaigns, supply chain vulnerabilities, and exploitation of unpatched cloud workloads, achieving persistent access and data exfiltration. The business impacts included service disruptions, data breaches, and regulatory scrutiny for affected organizations. This incident underscores the increasing complexity of APT operations in cloud-centric architectures and highlights the urgency of implementing comprehensive east-west visibility, zero trust controls, and robust anomaly detection. The trends reported by ESET indicate a continued escalation of multicloud security risks and a persistent threat landscape adapting to modern enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How State-Sponsored APTs Bypassed Multi-Cloud Defenses in 2025
Impact· medium

How State-Sponsored APTs Bypassed Multi-Cloud Defenses in 2025

Between Q2 and Q3 2025, ESET researchers identified a significant rise in sophisticated Advanced Persistent Threat (APT) attacks spanning multiple regions and industry verticals. State-sponsored actors leveraged encrypted communications and advanced lateral movement tactics to compromise organizations’ east-west cloud traffic, successfully bypassing conventional perimeter defenses. These campaigns exploited unmonitored internal traffic and insufficient network segmentation, leading to the exfiltration of sensitive data and critical infrastructure disruptions. The attackers demonstrated thorough knowledge of multi-cloud environments, combining zero-day exploits with stolen credentials to maintain persistent access and evade detection for weeks. This incident is emblematic of a broader trend—APT groups are accelerating the use of sophisticated, stealthy methods in hybrid cloud contexts. Modern enterprises must recognize the increased risk to east-west workloads, stay vigilant to evolving TTPs, and augment internal defenses in the face of rising geopolitical tensions and regulatory enforcement.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
QNAP 2025 Zero-Day Breach: Pwn2Own Shatters NAS Security
Impact· medium

QNAP 2025 Zero-Day Breach: Pwn2Own Shatters NAS Security

In March 2025, QNAP addressed seven critical zero-day vulnerabilities after security researchers demonstrated successful exploitation against their network-attached storage (NAS) devices during the Pwn2Own Ireland cybersecurity competition. The vulnerabilities allowed attackers to gain unauthorized access, compromise stored data, and potentially escalate privileges on affected systems. Once these flaws were publicly disclosed through the competition, QNAP developed and released urgent security patches to mitigate the risk to its global customer base, which includes enterprises and individuals relying on QNAP NAS for data storage. This incident underscores the increasing attention given to storage infrastructure as an attack vector, especially as threat actors and security researchers focus on discovering and weaponizing new zero-day vulnerabilities. The Pwn2Own event continues to reveal hidden risks across common network appliances, prompting vendors to accelerate patch cycles and organizations to prioritize vulnerability management for critical data repositories.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cisco Firewalls Under Siege: 2024 Zero-Day Flaws Trigger DoS Attacks on ASA & FTD
Impact· high

Cisco Firewalls Under Siege: 2024 Zero-Day Flaws Trigger DoS Attacks on ASA & FTD

In June 2024, Cisco disclosed that two actively exploited zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls were being weaponized in the wild. Attackers leveraged these flaws (CVE-2024-20353 and CVE-2024-20359) to trigger repeated reboot loops, effectively causing Denial-of-Service (DoS) on critical network perimeter defenses. Initial exploitation began as targeted zero-days, but attackers quickly adopted the flaws in larger campaigns, dramatically impacting the availability and security of organizations relying on Cisco ASA or FTD devices. The incident underscores a growing trend of targeting infrastructure security devices as a primary attack vector, especially given the rise of ransomware actors and APT groups seeking disruption over data theft. Exploitation of device vulnerabilities for DoS attacks highlights the heightened urgency for rapid patching and robust segmentation in modern enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Powered Malicious VS Code Extension Triggers Supply Chain Ransomware Alert (2025)
Impact· high

AI-Powered Malicious VS Code Extension Triggers Supply Chain Ransomware Alert (2025)

In late 2025, cybersecurity researchers discovered a malicious Visual Studio Code extension named "susvsex" distributed through an official plugin marketplace. Created using artificial intelligence techniques, the extension exhibited overt ransomware capabilities, encrypting files on infected development environments without attempts at obfuscation. The initial infection vector was a seemingly legitimate VS Code extension, weaponized to compromise developer systems and potentially propagate within software supply chains. Organizations relying on VS Code for coding or CI/CD faced the risk of credential theft, data loss, and business disruption if infected by the extension before it was removed. This incident highlights an escalating trend in supply chain and developer ecosystem attacks, where attackers leverage trusted distribution channels and AI-generated malicious code. With open marketplaces and widespread dependency sharing, even reputable software can become a conduit for advanced threats, requiring enterprises to rethink their extension vetting, monitoring, and incident response practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
LandFall Spyware: Samsung Zero-Day Exploited Through WhatsApp (2024 Attack Insights)
Impact· medium

LandFall Spyware: Samsung Zero-Day Exploited Through WhatsApp (2024 Attack Insights)

In early 2024, cybersecurity researchers identified that a sophisticated threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware, dubbed 'LandFall.' The attackers delivered malicious images via WhatsApp messages, abusing the image parsing process to gain device access without user interaction. Once installed, LandFall enabled covert surveillance, exfiltration of private data, and remote control capabilities, putting millions of Samsung devices at risk globally—especially given the attack’s stealthy, user-independent execution method. The breach demonstrates a significant advancement in mobile spyware delivery and a major supply chain risk for mobile OS providers. This incident is highly relevant as attackers increasingly leverage messaging platforms and zero-click vulnerabilities to distribute advanced spyware. The weaponization of zero-days against widespread consumer hardware underscores the urgent need for rapid vulnerability detection and robust response protocols across the mobile ecosystem.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Samsung 2025: LANDFALL Zero-Day Spyware Breach Exposes Enterprise Mobile Risks
Impact· high

Samsung 2025: LANDFALL Zero-Day Spyware Breach Exposes Enterprise Mobile Risks

In October 2025, a critical zero-day vulnerability (CVE-2025-21042) in Samsung Galaxy Android devices was actively exploited in the wild to deploy commercial-grade Android spyware known as LANDFALL. Attackers leveraged an out-of-bounds write flaw in the 'libimagecodec.quram.so' component through remote zero-click techniques, enabling arbitrary code execution without user interaction. Targeted campaigns, primarily in the Middle East, allowed adversaries to gain full device access and conduct covert surveillance until Samsung issued an urgent patch. The attacks highlight the sophistication and stealth of modern mobile threat actors and the increasing use of zero-day exploits to compromise mobile endpoints. This incident exemplifies the rise of highly targeted mobile spyware attacks leveraging zero-day vulnerabilities in globally popular hardware. It signals a broader trend in which commercial surveillance tools are abused by both state and non-state actors, driving greater urgency around mobile threat detection, zero-trust controls, and rapid patch management in enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports