Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2614 threat reports
Page 188 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 22452256 / 2614 reports
Critical WSUS RCE Exploit in Windows Server: Immediate Patching Required
Impact· low

Critical WSUS RCE Exploit in Windows Server: Immediate Patching Required

In June 2024, Microsoft urgently released out-of-band security patches to address a critical vulnerability (CVE-2024-30080) in Windows Server Update Services (WSUS). Security researchers publicly disclosed a proof-of-concept exploit that bypassed authentication and enabled remote code execution (RCE) on WSUS servers, exposing connected enterprise environments to attacker control. Threat actors could exploit this flaw to gain high-level privileges, push malicious updates to endpoints, or pivot deeper into corporate networks, presenting significant risk to organizations depending on WSUS for patch management. Microsoft advised immediate patching and provided guidance for mitigating exposed servers. This incident underscores a recent escalation in supply-chain and patch management vulnerabilities targeted by threat actors. Public exploit availability heightens the urgency for rapid remediation, as adversaries increasingly weaponize new vulnerabilities before standard patch cycles can address them.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Attackers Used LastPass Inheritance Phishing to Breach Vaults in 2024
Impact· high

How Attackers Used LastPass Inheritance Phishing to Breach Vaults in 2024

In June 2024, LastPass disclosed a targeted phishing campaign in which attackers sent fraudulent emails to customers, falsely claiming an access request to password vaults as part of a legacy inheritance process. These sophisticated phishing emails leveraged urgent social engineering tactics, such as fake death notifications, aiming to trick users into divulging their master passwords or clicking malicious links. Attackers subsequently attempted unauthorized access to vaults, raising concerns about potential credential compromise and data theft. This incident underscores the evolving threat landscape, where social engineering techniques and highly tailored phishing campaigns are targeting password managers and identity-centric security controls. As threat actors continue to exploit trust and human error, organizations must strengthen user awareness, enhance detection of inbound phishing, and revisit identity-based access protections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Amazon AWS 2024 Outage: What the DNS Infrastructure Failure Reveals
Impact· high

Amazon AWS 2024 Outage: What the DNS Infrastructure Failure Reveals

On June 13, 2024, Amazon Web Services (AWS) suffered a widespread outage attributed to a major DNS (Domain Name System) infrastructure failure. This disruption impacted numerous high-traffic websites and mission-critical online services, causing downtime and service degradation for businesses relying on AWS. While the outage was not caused by a cyberattack, the critical nature of DNS infrastructure meant that service availability and operational continuity were significantly affected. Amazon engineers quickly identified the root cause as an internal DNS misconfiguration and implemented remediation protocols to restore operations within hours. This incident highlights growing concerns about cloud infrastructure dependencies and the cascading business impact of DNS and network-layer disruptions. As digital ecosystems become more interlinked, organizations must consider both cyberattacks and operational failures in their risk management and compliance strategies.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
GlassWorm Worm Spreads via VS Code Extensions in Massive 2025 Supply Chain Attack
Impact· medium

GlassWorm Worm Spreads via VS Code Extensions in Massive 2025 Supply Chain Attack

In October 2025, cybersecurity researchers uncovered a major supply chain attack involving a self-spreading worm dubbed 'GlassWorm' that compromised Visual Studio Code (VS Code) extensions distributed via the Open VSX Registry and Microsoft Extension Marketplace. The threat actors leveraged malicious extensions to automatically propagate the worm among developer environments, enabling it to execute unauthorized code, exfiltrate credentials, and embed backdoors in developer toolchains. This incident resulted in widespread risk to organizations whose software supply chains depend on the integrity of these popular extension repositories, forcing rapid incident response across the global developer community. The GlassWorm incident highlights the escalating targeting of developers and DevOps pipelines by sophisticated cyber adversaries. As attackers evolve to exploit trust relationships in software ecosystems, organizations must strengthen supply chain security controls and increase vigilance around third-party code dependencies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WSUS Windows Server Vulnerability Exploited: What Organizations Need to Know in 2024
Impact· low

WSUS Windows Server Vulnerability Exploited: What Organizations Need to Know in 2024

In June 2024, attackers began actively exploiting a critical-severity vulnerability in Microsoft’s Windows Server Update Services (WSUS), allowing unauthenticated remote code execution on unpatched Windows Server instances. Public proof-of-concept exploit code enabled threat actors to target organizations’ update infrastructure, potentially granting attackers elevated privileges and control over networked endpoints. The attack vector leverages unencrypted or weakly secured WSUS communication endpoints, risking malware delivery or the propagation of malicious updates across enterprise environments. Immediate business impacts can include system compromise, lateral movement, and potential data exfiltration. This exploitation reflects a recent trend where attackers leverage highly impactful remote code execution bugs in widely deployed software with public exploits, underscoring the need for rapid patch management and improved east-west traffic visibility. Organizations using legacy or unpatched WSUS deployments are most at risk as targeted attacks continue to rise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft WSUS 2025: Critical RCE Vulnerability Exploited in the Wild
Impact· low

Microsoft WSUS 2025: Critical RCE Vulnerability Exploited in the Wild

In October 2025, Microsoft disclosed and urgently patched a critical remote code execution vulnerability (CVE-2025-59287) impacting the Windows Server Update Services (WSUS) framework. Following the public release of a proof-of-concept exploit, threat actors began actively targeting vulnerable WSUS deployments to execute malicious code, gain unauthorized access, and potentially compromise large segments of enterprise environments. The flaw, assigned a CVSS score of 9.8, allowed unauthenticated attackers to leverage exposed update services, posing significant risk to organizations’ patch management infrastructures before the emergency fix was implemented. This incident highlights the continuing trend of sophisticated adversaries exploiting zero-day and n-day vulnerabilities in widely used systems with available PoCs. It also underscores growing urgency for proactive patch management, real-time anomaly detection, and adoption of Zero Trust models to protect against rapidly weaponized threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Global Smishing Triad Campaign: 194,000 Malicious Domains Power Massive Phishing Surge
Impact· low

Global Smishing Triad Campaign: 194,000 Malicious Domains Power Massive Phishing Surge

In 2024, security researchers attributed a global smishing campaign to a threat group known as the Smishing Triad, which registered more than 194,000 malicious domains since January 1. Utilizing infrastructure predominantly registered through Hong Kong-based providers with Chinese nameservers, the actors orchestrated widespread phishing via SMS attacks targeting banking, logistics, and other sectors. Victims received highly targeted text messages that redirected them to credential-harvesting sites, leading to financial fraud and data compromise. The campaign’s scale and global reach underline the adversaries’ operational sophistication and heavy use of automation. This incident reflects a broader surge in phishing tactics leveraging SMS and vast domain infrastructure, bypassing traditional email security. The growing adoption of QR and mobile-first communication further widens the threat surface, putting regulatory and compliance emphasis on new vectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Salt Typhoon’s 2024 Attack: Nation-State Espionage Exploits Forgotten Network Devices
Impact· high

Salt Typhoon’s 2024 Attack: Nation-State Espionage Exploits Forgotten Network Devices

In early 2024, a cyber espionage campaign orchestrated by the China-linked Salt Typhoon group targeted forgotten and unpatched network perimeter devices, such as out-of-support routers, VPNs, and firewalls, across both public and private sector organizations in the U.S. and allied nations. Adversaries leveraged advanced "living off the land" tactics, establishing persistent access by exploiting technical debt and overlooked legacy hardware—bypassing hardened endpoint defenses and moving laterally within affected networks. Operational impacts included exposure of sensitive credentials, long-term surveillance risks, and significant challenges in incident detection and response due to the stealthy nature of the attacks. This incident highlights a surge in sophisticated nation-state threats adapting to improved endpoint security by targeting unmanaged infrastructure. The campaign underscores the urgency for organizations to reassess asset inventories, prioritize decommissioning of end-of-life devices, and deploy proactive detection strategies, as similar tactics are increasingly observed across multiple state-sponsored and ransomware actors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Atlas & Comet AI Sidebar Spoofing: How Attackers Are Hijacking Trust in Browser AI
Impact· low

Atlas & Comet AI Sidebar Spoofing: How Attackers Are Hijacking Trust in Browser AI

In early June 2024, security researchers identified a novel application security vulnerability affecting OpenAI’s Atlas and Perplexity’s Comet browsers. Attackers leveraged spoofed AI sidebars to present malicious, AI-generated instructions that duped users into actions compromising security, such as running unverified commands or visiting phishing sites. The attack method bypassed traditional endpoint defenses by exploiting inherent trust in AI-powered browser features. Though no widespread exploitation has been confirmed, proof-of-concept demonstrations exposed a significant risk of credential theft, data leakage, or lateral movement within enterprise environments. The rapid adoption of AI assistants made this vector both timely and dangerous. This incident highlights the growing trend of attackers targeting AI-powered productivity tools by manipulating contextual interfaces. Rising adoption of AI chatbots and browser plugins increases the threat surface, demanding urgent reevaluation of security controls and staff awareness. Regulatory scrutiny of AI and application security is expected to accelerate in response.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Sounds Alarm: Lanscope Endpoint Manager Flaw Actively Exploited
Impact· low

CISA Sounds Alarm: Lanscope Endpoint Manager Flaw Actively Exploited

In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) warned organizations of active exploitation of a critical vulnerability in Motex’s Lanscope Endpoint Manager software. Threat actors leveraged the flaw (tracked as CVE-2024-27956) to gain unauthorized access and potentially execute remote code on unpatched systems. The attackers could bypass authentication and gain administrative privileges, enabling lateral movement and further compromise of affected network environments. The incident impacted enterprises using Lanscope Endpoint Manager for device monitoring and management, raising concerns over exposure of sensitive data and operational disruption. This incident is notable for its speed of exploitation following public disclosure, illustrating the ongoing trend of threat actors rapidly weaponizing software vulnerabilities in endpoint management tools. The breach underscores the importance of immediate patching and rigorous monitoring as attackers increasingly target IT infrastructure software to establish initial footholds.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack
Impact· medium

CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack

In October 2025, a critical vulnerability (CVE-2025-61932, CVSS 9.3) in Motex Lanscope Endpoint Manager was added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation in the wild. Attackers leveraged the on-premises endpoint management platform’s remote code execution flaw to obtain unauthorized access, enabling lateral movement and potential data exfiltration. Organizations relying on Lanscope Endpoint Manager may face business disruption, data integrity issues, and heightened regulatory scrutiny as a result of this exposure. The recent exploitation of this vulnerability underscores a larger trend of remote code execution exploits targeting widely deployed endpoint management products. With attackers increasingly seeking supply-chain and IT management footholds, regulatory bodies and security leaders are prioritizing rapid patch cycles and robust segmentation to limit risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024
Impact· high

It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024

In 2024, cybersecurity researchers demonstrated that the integrity of large language models (LLMs) can be severely compromised with as few as 250 poisoned documents strategically inserted into their training data. By covertly introducing manipulated or malicious content into public data sources, attackers can alter a model’s understanding, bias its outputs, or degrade its reliability. This proof-of-concept highlights that ‘data poisoning’ attacks require minimal input yet pose substantial risk for AI reliability, potentially opening the door for misinformation, backdoors, or loss of operational trust across industries leveraging AI. Organizations relying on LLMs for critical tasks face a heightened threat of silent, hard-to-detect breaches affecting their core AI deployments. The urgency around AI/ML supply chain security has intensified, as threat actors and researchers increasingly explore the feasibility of data poisoning. Regulatory frameworks and industry best practices now emphasize the need for data provenance controls and continuous integrity monitoring of training pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports