Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2614 threat reports
Page 184 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 21972208 / 2614 reports
New 'Brash' Chromium Exploit Exposes Enterprise Browser Risks in 2025
Impact· high

New 'Brash' Chromium Exploit Exposes Enterprise Browser Risks in 2025

In October 2025, a severe vulnerability affecting Chromium-based browsers was publicly disclosed by security researcher Jose Pino. Nicknamed "Brash," this exploit targets the Blink rendering engine by manipulating specific DOM operations, allowing any attacker to crash a victim's browser with a single specially crafted URL. The vulnerability impacted Chrome, Edge, Brave, and other browsers using Chromium, raising concerns about both service disruption and potential for more severe follow-on attacks. The flaw could be triggered in as little as 15–60 seconds, posing a high risk for denial-of-service campaigns and widespread user impact until an emergency patch was released. The Brash exploit underscores increasing risks from 'zero-click' browser attacks. As reliance on web-based applications rises, threat actors increasingly target foundational browser components. This incident highlights the need for continuous monitoring and rapid browser patching in enterprise environments to counter such fast-moving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Ransomware Leverages AdaptixC2: 2025's Open-Source Attack Surge
Impact· high

Russian Ransomware Leverages AdaptixC2: 2025's Open-Source Attack Surge

In mid-2025, threat intelligence sources reported that Russian ransomware groups had begun leveraging the open-source AdaptixC2 framework to orchestrate highly targeted, advanced ransomware campaigns. AdaptixC2, originally designed for penetration testing, was weaponized to facilitate command-and-control communications, enable lateral movement, and automate deployment of ransomware binaries across hybrid cloud and enterprise environments. The attackers exploited weak internal segmentation and monitoring deficiencies, achieving extensive encryption of critical systems, data exfiltration, and ransom demands that disrupted multiple sectors, including finance and healthcare. This incident reflects a broader trend: threat actors are rapidly operationalizing legitimate open-source red team tools for malicious purposes. Organizations must respond to this evolution in attacker strategies, as post-exploitation frameworks become increasingly prevalent in real-world breaches, complicating detection and increasing regulatory and operational risk.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Alerts on Five New Actively Exploited Vulnerabilities in Critical Platforms (2025)
Impact· low

CISA Alerts on Five New Actively Exploited Vulnerabilities in Critical Platforms (2025)

On October 20, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog, adding five actively exploited vulnerabilities across products from Apple, Kentico, Microsoft, and Oracle. These critical flaws—ranging from authentication bypasses in Kentico Xperience to a server-side request forgery in Oracle E-Business Suite and improper SMB access control in Microsoft Windows—are being leveraged by threat actors to gain unauthorized access, escalate privileges, or exfiltrate data. The directive mandates federal agencies to urgently remediate these risks to safeguard the federal enterprise and critical infrastructure from rapidly evolving threats. The continued expansion of the KEV Catalog highlights the persistent challenge organizations face in tracking and rapidly remediating high-impact vulnerabilities, especially as exploit techniques become more sophisticated and widely disseminated. The urgency is underscored by both regulatory pressure and the increase in observed exploitation campaigns targeting these vulnerabilities across public and private sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CloudEdge Camera Flaw Exposes Millions: MQTT Wildcard and Credentials Risk
Impact· medium

CloudEdge Camera Flaw Exposes Millions: MQTT Wildcard and Credentials Risk

In October 2025, security researchers disclosed a critical vulnerability (CVE-2025-11757) affecting CloudEdge IoT cameras and their mobile application. The flaw, caused by improper sanitization of MQTT topic inputs and the use of hard-coded credentials, allowed remote attackers to subscribe to wildcard topics and intercept sensitive messages. This gave unauthorized access to camera feeds and controls globally for any device running the vulnerable CloudEdge App v4.4.2. Neither CloudEdge nor Meari Technologies responded to official disclosure requests, leaving millions of devices worldwide potentially exposed to attack. This incident exemplifies ongoing risks in consumer IoT, highlighting weaknesses in MQTT implementations and credential management. Similar vulnerabilities are increasingly leveraged by attackers to gain unauthorized access, disrupt operations, and compromise privacy, underscoring the pressing need for stronger IoT security regulation and vendor accountability.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Oxford Nanopore 2025: MinKNOW Vulnerabilities Expose Medical Devices to Remote Exploitation
Impact· high

Oxford Nanopore 2025: MinKNOW Vulnerabilities Expose Medical Devices to Remote Exploitation

In October 2025, Oxford Nanopore Technologies disclosed three critical vulnerabilities in its MinKNOW DNA/RNA sequencing devices, impacting versions prior to 24.11. These flaws, which included missing authentication for critical functions, insufficiently protected credentials, and improper checks for exceptional conditions, allowed unauthorized users—both local and remote—to access, manipulate, or halt sequencing operations. Attackers could exploit default remote access settings and insecure credential storage to exfiltrate or alter sensitive data and cause denial of service in key sequencing workflows. The vulnerabilities were responsibly reported by academic researchers, prompting urgent advisories by CISA and the vendor. This incident underscores increasing risk to healthcare and life sciences infrastructure, with medical device supply chains emerging as a prime target for cyberattackers. As regulatory focus on medical device cybersecurity intensifies globally, organizations must swiftly address legacy systems and implement controls that secure both east-west and egress traffic, limit access, and ensure encrypted credential storage.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Warns of Active Exploitation: Motex LANSCOPE CVE-2025-61932 Added to KEV List
Impact· low

CISA Warns of Active Exploitation: Motex LANSCOPE CVE-2025-61932 Added to KEV List

In October 2025, CISA added CVE-2025-61932 to its Known Exploited Vulnerabilities catalog after confirmation that attackers were actively exploiting an improper verification of source vulnerability in Motex LANSCOPE Endpoint Manager. This flaw enables malicious actors to bypass authentication controls or inject unauthorized communications by exploiting weak checks on communication channels. As a result, federal networks and enterprises using the affected endpoint management platform face increased risk of unauthorized access, lateral movement, and potential data compromise. The vulnerability was discovered as part of ongoing efforts to monitor critical endpoint management systems for exploitation in the wild and is considered a significant risk vector, especially for organizations reliant on enterprise management tools. The inclusion of this vulnerability in CISA’s KEV catalog underscores a broader surge in attacks targeting endpoint management platforms, reflecting the ongoing evolution of attacker techniques against core IT infrastructure. Timely patching and visibility into east-west traffic is increasingly essential, as threat actors exploit gaps before organizations can remediate newly disclosed weaknesses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Unveils 2025 ICS Vulnerabilities: Critical Risks to Energy & Healthcare
Impact· medium

CISA Unveils 2025 ICS Vulnerabilities: Critical Risks to Energy & Healthcare

In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released eight advisories highlighting multiple critical vulnerabilities in a range of Industrial Control Systems (ICS) products, including solutions from AutomationDirect, ASKI Energy, Veeder-Root, Delta Electronics, NIHON KOHDEN, Schneider Electric, and Hitachi Energy. These vulnerabilities could allow threat actors, including both cybercriminals and nation-state adversaries, to execute remote code, escalate privileges, disrupt control functionality, or access sensitive operational data. Although no confirmed exploits were publicly detailed at the time of disclosure, the affected systems are widely deployed in energy, healthcare, and manufacturing, raising concerns about both operational integrity and national infrastructure risk. The incident underscores an urgent trend of continuous vulnerability discovery within ICS and operational technology environments as attackers increasingly target these sectors. This rising cadence of disclosures highlights both the complexity of securing interconnected systems and the need for ongoing vigilance and layered defense measures in critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical DoS Flaw in NIHON KOHDEN CNS-6201 Exposes Legacy Healthcare Systems
Impact· high

Critical DoS Flaw in NIHON KOHDEN CNS-6201 Exposes Legacy Healthcare Systems

In October 2025, a critical security vulnerability (CVE-2025-59668) was disclosed in the NIHON KOHDEN Central Monitor CNS-6201—a medical device used globally in healthcare environments. The flaw, a NULL pointer dereference triggered by a specially crafted UDP packet, allows attackers to remotely cause a denial-of-service (DoS) condition, resulting in abnormal termination of the monitoring process. Exploitation requires no authentication as long as the device is network-accessible. Affected models are end-of-support, placing healthcare environments at heightened risk if legacy equipment remains unsegmented or exposed. This exposure highlights continuing challenges associated with legacy medical devices, the urgency of network segmentation, and the importance of proactive vulnerability management in healthcare. Similar technique trends surrounding unauthenticated DoS vulnerabilities in critical infrastructure increase regulatory, patient-safety, and operational risk considerations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft WSUS RCE Vulnerability (CVE-2025-59287) Exposes Critical Infrastructure
Impact· low

Microsoft WSUS RCE Vulnerability (CVE-2025-59287) Exposes Critical Infrastructure

In October 2025, Microsoft disclosed and released an out-of-band security update for a critical remote code execution vulnerability (CVE-2025-59287) affecting Windows Server Update Services (WSUS) across multiple Windows Server versions (2012–2025). The flaw allowed unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on unpatched WSUS servers, particularly when ports TCP 8530/8531 were exposed. Exploitation involved spawning child processes through wsusservice.exe or w3wp.exe, with threat actors leveraging PowerShell payloads and potentially broader lateral movement. Organizations failing to patch faced severe risk of compromise. This incident underscores the escalating trend of supply chain and infrastructure attacks, where core update and provisioning mechanisms are targeted to gain privileged access or disrupt operations. Active exploitation and KEV listing prompt heightened urgency for organizations to address legacy system exposures and reinforce privileged system monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Vertikal Systems 2025: Healthcare Data at Risk via Hospital Manager Backend Vulnerabilities
Impact· medium

Vertikal Systems 2025: Healthcare Data at Risk via Hospital Manager Backend Vulnerabilities

In September 2025, Vertikal Systems disclosed two critical vulnerabilities affecting its Hospital Manager Backend Services. The first flaw (CVE-2025-54459) allowed unauthorized, remote access to the ASP.NET tracing endpoint, potentially exposing sensitive data such as authorization tokens and server metadata. The second (CVE-2025-61959) disclosed verbose error pages on invalid requests, inadvertently leaking application stack traces and configuration files. Both issues were exploitable without authentication, posing significant data privacy and operational risk across healthcare sites globally. This incident spotlights ongoing risks to healthcare organizations due to misconfigurations and unnecessary exposure of sensitive developer endpoints. With increasing regulatory pressure on patient data security and the healthcare sector's targeted threat profile, such vulnerabilities could lead to compliance violations or facilitate wider attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Raises Alarm on Schneider Electric & Vertikal ICS Vulnerabilities (2025)
Impact· medium

CISA Raises Alarm on Schneider Electric & Vertikal ICS Vulnerabilities (2025)

In October 2025, CISA released urgent advisories for three significant industrial control system (ICS) vulnerabilities affecting Schneider Electric EcoStruxure, Vertikal Systems Hospital Manager Backend Services, and Schneider Electric Modicon. The vulnerabilities, discovered through active monitoring and intelligence efforts, could allow unauthorized access, system manipulation, or disruption if exploited by threat actors. These issues expose critical infrastructure, including healthcare and industrial automation environments, to increased risk of cyberattacks that could impact operations, safety, and patient care. CISA highlighted immediate mitigations and urged organizations to review and apply them to safeguard their assets. The frequency of high-severity ICS vulnerabilities underscores an ongoing trend of targeting operational technology environments, in both healthcare and industrial sectors. These risks are magnified by legacy platforms, the rise of ransomware, and increasingly sophisticated attackers. Regulatory scrutiny and mandates for rapid patching, segmentation, and real-time detection are on the rise as a result.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
New 2025 Guidance: Securing Microsoft Exchange Servers from Infrastructure Vulnerabilities
Impact· medium

New 2025 Guidance: Securing Microsoft Exchange Servers from Infrastructure Vulnerabilities

In October 2025, cybersecurity authorities including CISA and the NSA released urgent best practices following persistent threats targeting on-premises Microsoft Exchange servers. Despite patch releases and increased awareness, many organizations continued running outdated or misconfigured Exchange environments, leaving them vulnerable to exploitation. Attackers leveraged these weaknesses to gain unauthorized access, often leading to lateral movement, data exfiltration, and in some cases, ransomware incidents. The culmination of such ongoing attacks prompted renewed guidance emphasizing strong authentication, rigorous encryption, and decommissioning of unsupported hybrid Exchange servers to minimize operational risk. This incident underscores the ongoing trend of adversaries exploiting infrastructure vulnerabilities, especially in legacy and hybrid setups. With continued attacker innovation and regulatory scrutiny, organizations must adopt zero trust principles, prioritize patch cycles, and upgrade legacy systems to mitigate evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports