✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
AMD RMPocalypse: 2025 SEV-SNP Hardware Flaw Shakes Confidential Computing
In October 2025, researchers from ETH Zürich disclosed a critical vulnerability, dubbed RMPocalypse, affecting AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) technology. The flaw allowed attackers to undermine confidential computing protections by exploiting incomplete memory protections, making it feasible to alter a single 8-byte memory location and bypass hardware security boundaries. This discovery prompted AMD to release urgent patches across impacted EPYC server platforms, as the risk permitted threat actors—potentially including malicious tenants or insiders in cloud environments—to access sensitive workload data previously thought to be isolated and encrypted. This incident highlights persistent risks within hardware-assisted security frameworks and confidential computing platforms, as attackers increasingly target trusted execution environments. With a rise in high-confidence threats and supply-chain attacks, this breach sets a new precedent for cross-layer vulnerability research and the urgency of continuous hardware and firmware security validation.
6 months ago
Kill Chain
Critical SAP NetWeaver Zero-Day in 2025 Enables Unauthenticated Server Takeover
In October 2025, SAP disclosed and patched a critical zero-day vulnerability (CVE-2025-42944) in its NetWeaver Application Server Java platform, stemming from insecure deserialization. The vulnerability, rated CVSS 10.0, enabled unauthenticated remote attackers to execute arbitrary commands on affected servers, potentially compromising entire SAP landscapes. Though SAP issued urgent patches addressing 13 issues, the deserialization flaw was particularly notable for its potential to allow complete server takeover without credential access. Organizations were urged to deploy security updates immediately to prevent exploitation. This incident highlights the ongoing risk posed by deserialization vulnerabilities in widely deployed enterprise applications. As attackers accelerate exploitation of newly disclosed flaws, organizations must prioritize rapid patching, bolster application-layer controls, and monitor for lateral movement to mitigate the risk of business-critical system breaches.
6 months ago
Kill Chain
ICTBroadcast RCE Vulnerability: Hackers Gain Remote Shell Access via Cookie Exploit in 2025
In October 2025, a critical remote code execution vulnerability (CVE-2025-2611, CVSS 9.3) in ICTBroadcast's autodialer platform was actively exploited by threat actors. By leveraging improper input validation in the application's session cookie handler, attackers achieved unauthenticated remote shell access to internet-exposed servers. This exploit enabled malicious actors to execute arbitrary system commands, potentially compromising sensitive data and business operations for organizations using ICTBroadcast. The incident required immediate patching and forensic investigation to contain the breach and restore normal operations. This breach highlights the persistent risk posed by zero-day vulnerabilities in widely used communications software, especially as remote access vector attacks surge. It underscores the strategic shift among attackers toward supply chain and software-specific exploits, which remain difficult to rapidly mitigate across diverse deployment environments.
6 months ago
Kill Chain
Microsoft’s 2025 Windows Zero-Day Exploitation: What Every Enterprise Needs to Know
In October 2025, Microsoft revealed that two previously unknown zero-day vulnerabilities had been discovered and actively exploited in every supported and unsupported version of Windows, following its Patch Tuesday release. Attackers leveraged these unpatched flaws to compromise systems, facilitating unauthorized access and the potential for privilege escalation and lateral movement. The vulnerabilities affected both enterprise and consumer endpoints, raising concerns about widespread risk at a time when older Windows 10 systems reached end-of-support unless enrolled in paid extended coverage. This incident forced rapid emergency patch deployment and incident response in enterprises worldwide. This event underscores a rising trend in the exploitation of zero-day flaws in core operating systems, putting organizations under pressure to minimize their exposure and improve vulnerability and patch management. Regulatory scrutiny and increased attacker sophistication have elevated expectations for response times and organizational cyber resilience.
6 months ago
Kill Chain
How Attackers Bypass Synced Passkeys: Lessons from the 2025 Incident
In October 2025, a significant security incident highlighted how attackers are bypassing synced passkey protections via adversary-in-the-middle (AiTM) techniques. Attackers exploited weaknesses in the synchronization of passkeys—where user credentials are stored in the cloud and synchronized across devices—to circumvent strong authentication requirements. By leveraging AiTM phishing kits and triggering fallback authentication flows, adversaries gained unauthorized access to enterprise accounts, exposing sensitive data and business operations. This vector sidesteps traditional multi-factor authentication and identity-first defenses, putting organizations reliant on passkey sync at risk. This incident demonstrates an urgent shift in attacker tactics toward abusing authentication recovery and synchronization flows that are increasingly common with passwordless deployments. As more businesses move to passkeys for convenience, the associated risks with synced secrets and recoveries have become a major security concern that demands new approaches and controls.
6 months ago
Kill Chain
VS Code Extension Access Token Leak: A 2025 Supply Chain Wake-Up Call
In October 2025, a major supply chain risk was exposed when over 100 Visual Studio Code (VS Code) extensions were found to have leaked access tokens, allowing threat actors to publish malicious updates to widely used extensions. Attackers who obtained these tokens could have distributed compromised software versions to millions of developers globally, undermining trust in open-source ecosystems and introducing the risk of code tampering, credential theft, or insertion of backdoors into organizational environments. The vulnerability lay in the mishandling and inadvertent leakage of personal access tokens (PATs) for both the VSCode Marketplace and Open VSX, giving adversaries an insidious update path into developer workstations and CI/CD pipelines. This incident highlights the increasing frequency and sophistication of supply chain attacks targeting developer tools and open-source dependencies. As the software landscape grows more interconnected, private access tokens and code-signing credentials now represent high-value targets, requiring robust security controls and zero trust validation across the development lifecycle.
6 months ago
Kill Chain
F5 Breach 2025: Nation-State Hackers Steal BIG-IP Source Code in Supply-Chain Attack
In October 2025, F5, a leading U.S. cybersecurity vendor, reported a significant breach attributed to a sophisticated nation-state threat actor. Attackers infiltrated F5's internal systems, gaining persistent access and exfiltrating files containing proprietary BIG-IP source code as well as details on undisclosed vulnerabilities. The breach underscores advanced adversary tactics, likely leveraging supply-chain vectors or unpatched entry points, with the attackers remaining undetected for an extended period. The exposure of source code and sensitive vulnerability information has significant security and operational implications for F5 customers and the wider ecosystem. This incident illustrates an escalating trend of nation-state-backed attacks targeting critical infrastructure vendors and supply chains. The F5 breach spotlights the urgent need for vigilant monitoring, robust threat detection, and transparent vulnerability management as attackers increasingly focus on extracting valuable code and intelligence from IT suppliers.
6 months ago
Kill Chain
Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about a critical misconfiguration vulnerability (CVE-2025-54253) impacting Adobe Experience Manager (AEM). This flaw, assigned a CVSS score of 10.0, allows remote unauthenticated attackers to achieve arbitrary code execution on vulnerable AEM instances. Active exploitation was confirmed as attackers leveraged the bug to gain foothold, escalate privileges, and deploy malware on targeted organizations, potentially exposing sensitive data and compromising internal operations. The incident highlights the risks of unpatched enterprise software within digital supply chains and data-driven organizations. The AEM vulnerability is currently notable due to increased exploitation by multiple threat actors, coinciding with a larger trend of critical zero-day application flaws being used in advanced persistent attacks. Regulatory agencies and security experts underscore the urgency for patching exposed business applications given the frequency and sophistication of exploitation campaigns in 2025.
6 months ago
Kill Chain
Operation Zero Disco: APTs Weaponize Cisco SNMP Flaw to Deploy Linux Rootkits
In early October 2025, security researchers uncovered Operation Zero Disco, a targeted cyber campaign leveraging a stack overflow vulnerability (CVE-2025-20352) in Cisco IOS and IOS XE software. Advanced persistent threat (APT) actors weaponized this SNMP flaw to access legacy Cisco networking equipment, deploying covert Linux rootkits and securing long-term persistence on compromised devices. The exploitation enabled attackers to bypass standard defenses, facilitate lateral movement, and maintain undetected access to sensitive east-west network traffic, significantly increasing risk for organizations relying on outdated infrastructure. This incident highlights a growing trend of sophisticated actors exploiting unpatched or unsupported networking systems to achieve deep infrastructure compromise. With the resurgence of supply chain and infrastructure-based attacks, persistent network vulnerabilities demand heightened vigilance, rapid patch adoption, and robust segmentation. Industry-wide, there is mounting urgency to secure critical areas exposed by legacy systems and evolving attacker tactics.
6 months ago
Kill Chain
Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities
On the first day of Pwn2Own Ireland 2025, security researchers successfully exploited 34 unique zero-day vulnerabilities across a range of enterprise technologies, earning $522,500 in awards. The event, renowned for responsible disclosure and sponsored by leading vendors, demonstrated both the speed and sophistication with which zero-day flaws can be discovered and exploited in widely used software and hardware platforms. While no criminal group was involved (these are sanctioned research efforts), the findings underscore prevailing vulnerabilities in enterprise defenses and often result in rapid product updates and critical security advisories. This incident highlights the ongoing arms race between researchers and vendors to identify and remediate unknown security gaps. The large number of zero-days found in a single day signals both the growing complexity of attack surfaces and the pressing need for automated detection and proactive patching mechanisms across the digital ecosystem.
6 months ago
Kill Chain
Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025
In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations. This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.
6 months ago
Kill Chain
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports