✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
CISA Flags Oracle E-Business Suite SSRF Exploitation: What You Need to Know
In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that threat actors exploited a critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-61884, in Oracle E-Business Suite. Attackers leveraged this zero-day flaw to gain unauthorized access to internal systems, potentially allowing data exposure or further lateral movement within affected organizations. The vulnerability has since been added to CISA's Known Exploited Vulnerabilities catalog, highlighting active exploitation in the wild and prompting urgent remediation efforts across the private and public sectors. This incident underscores the growing trend of exploiting SSRF flaws in enterprise applications to bypass perimeter controls and facilitate initial access. Regulatory agencies globally are increasing pressure on vendors and businesses to patch critical application vulnerabilities rapidly as attacker sophistication and exploitation speed accelerate.
6 months ago
Kill Chain
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.
6 months ago
Kill Chain
Microsoft Revokes Fraudulent Certificates Exploited by Rhysida Ransomware in 2025 Campaign
In June 2025, Microsoft discovered and responded to a sophisticated campaign in which a threat actor known as Vanilla Tempest (also tracked as Storm-0785) fraudulently issued over 200 code-signing certificates. These certificates were leveraged to make malicious files appear legitimate, facilitating the distribution of a fake Microsoft Teams installer that ultimately delivered the Oyster backdoor and deployed Rhysida ransomware across targeted environments. Microsoft quickly moved to revoke all compromised certificates to mitigate the risk and prevent further exploitation by the attackers. The breach highlights the growing sophistication of ransomware groups in leveraging trusted supply chain components for malware delivery. This incident underscores the heightened threat landscape in which adversaries exploit trusted relationships and digital certificates to evade security controls. It also signals an increasing trend of ransomware utilizing living-off-the-land and supply chain abuse techniques, compounding challenges for organizations striving to maintain software integrity and regulatory compliance.
6 months ago
Kill Chain
Vidar Stealer 2.0: Infostealer Adopts Multi-threaded Data Theft & Evasion in 2024
In early 2024, the operators behind Vidar Stealer—a notorious malware-as-a-service (MaaS)—released version 2.0, introducing significant upgrades such as multi-threaded data theft and improved evasion techniques. Threat actors are leveraging this new version to accelerate theft of sensitive information, targeting both personal and enterprise environments by deploying the stealer via malicious emails, cracked software, and malvertising. The enhanced capabilities enable Vidar Stealer to exfiltrate data more efficiently and undermine traditional security controls, heightening the risks for organizations that rely on endpoint- or signature-based defenses. This evolution signals a broader trend in infostealer threats, where malware authors are quickly integrating advanced techniques for bypassing detection and maximizing operational speed. Enterprises should expect an uptick in automated, distribution-scale credential and data theft campaigns driven by increasingly sophisticated MaaS offerings like Vidar 2.0.
6 months ago
Kill Chain
Researchers Reveal Critical WatchGuard VPN Vulnerability Enabling Device Takeover
In October 2025, cybersecurity researchers disclosed a critical vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware devices affecting OS versions 11.10.2 to 11.12.4_Update1 and 12.0. The flaw involved an out-of-bounds write in the VPN functionality, allowing unauthenticated remote attackers to execute arbitrary code. Attackers exploiting this bug could gain full control of affected appliances, potentially intercepting encrypted traffic, moving laterally within networks, or establishing persistent access. Patches were released urgently, but some organizations may remain exposed due to delayed patching or legacy hardware. This incident highlights ongoing attacker targeting of perimeter and VPN infrastructure. With rising reliance on remote access, vulnerabilities in widely deployed appliances continue to provide high-value entry vectors. Timely patching and layered network defenses are essential in light of increased regulatory scrutiny and sophisticated threat landscapes.
6 months ago
Kill Chain
2025’s Phishing Evolution: QR-PDFs, Calendar Attacks, and MFA Relay
In early 2025, organizations faced a surge of advanced phishing attacks leveraging revitalized and sophisticated tactics. Threat actors used emails with password-protected PDF attachments containing QR codes, evading traditional email security solutions and enticing users to open links via less-protected mobile devices. Calendar invitations embedding phishing links, voice message lures with CAPTCHA-guarded landing pages, and high-fidelity credential harvesting forms that relayed real MFA challenges in real-time all contributed to more successful credential thefts. These approaches eroded user trust in standard verification mechanisms and bypassed established detection methods, leading to increased account compromise risks and potential business disruptions. This shift signals a broader trend of attackers reusing and refining both traditional and novel phishing techniques, with rising use of multi-step evasion and identity-focused targeting. Enterprise email, cloud collaboration services, and end user authentication have become critical targets, driving new regulatory scrutiny and requirements for layered, adaptive defenses.
6 months ago
Kill Chain
Silver Fox Targets Japan & Malaysia: Winos 4.0 & HoldingHands RAT in Regional Cyber Attack
In October 2025, the Silver Fox cybercrime group broadened their Winos 4.0 (ValleyRAT) operations outside China and Taiwan by targeting organizations in Japan and Malaysia using the recently identified HoldingHands RAT (also called Gh0stBins). Attackers used phishing emails containing malicious PDFs with embedded links, leading recipients to unknowingly download and execute the remote access Trojan. Once deployed, the malware allowed unauthorized access and remote control over infected endpoints, posing significant threats to sensitive data and operational integrity for both public and private sector entities in the affected regions. This breach underscores the growing prevalence of multi-stage phishing attacks orchestrated by established threat actors, and highlights the transnational expansion of remote access trojan campaigns in Asia. The incident increases urgency for regional organizations to strengthen email security, endpoint defenses, and adopt zero-trust principles as attacker sophistication and geographic reach expand.
6 months ago
Kill Chain
ClickFix Copy/Paste Attacks: How Browser-Based Social Engineering Breached Enterprises in 2025
In October 2025, multiple organizations were impacted by the emerging 'ClickFix' attack trend, in which threat actors leveraged deceptive browser-based prompts (like fake CAPTCHAs or repair dialogs) to manipulate users into copy-pasting malicious code or credentials. These social engineering attacks typically bypassed standard email or endpoint security controls by exploiting a user's trust in solving browser-based challenges, resulting in credential compromise, unauthorized access, and subsequent lateral movement within enterprise environments. The attackers maintained persistence by mimicking legitimate error messages and encouraging users to interact further, drastically increasing the potential for data exfiltration and ransomware deployment. This breach highlights a surge in adversary-in-the-browser tactics, with copy/paste manipulation rapidly becoming a favored method among cybercriminals due to its high success rate and the minimal technical barriers for execution. The incident underscores the growing need for organizations to adopt advanced east-west traffic controls, enforce strong zero trust segmentation, and continually educate users about novel, non-traditional social engineering threats.
6 months ago
Kill Chain
The F5 2025 Multi-Vector Breach: A Wake-up Call for Hybrid Cloud Defense
In October 2025, F5 Networks experienced a sophisticated multi-vector cyber breach in which attackers gained undetected foothold within its environment for a prolonged period. The adversaries reportedly exploited a combination of Linux rootkits, encrypted traffic evasion, and a new attack method known as Pixnapping to laterally move between internal workloads and exfiltrate sensitive data. Their persistence was enabled by bypassing both east-west and egress security controls, leveraging cloud-native environments and covert remote access tools, before the intrusion was detected. Business operations were disrupted, and F5 initiated incident response and regulatory disclosures. This breach underscores the urgent reality that advanced attackers employ stealthy, multi-stage tactics, exploiting visibility gaps, lateral pathways, and cloud complexity. As such, it highlights the evolving need for proactive threat detection, zero trust segmentation, and continuous monitoring in today’s hybrid enterprise landscapes.
6 months ago
Kill Chain
Oracle E-Business Suite Vulnerability Breach: CVE-2025-61884 Exploited in Active Attacks
In October 2025, attackers exploited CVE-2025-61884, a critical vulnerability in Oracle E-Business Suite (EBS), enabling unauthorized remote access and manipulation of sensitive enterprise data. The breach surfaced after CISA added the flaw to its Known Exploited Vulnerabilities Catalog, confirming active exploitation in the wild. Adversaries leveraged the unpatched vulnerability to gain foothold in targeted organizations, potentially leading to data theft, operational disruption, and exposure of personal and financial information stored within Oracle EBS environments. Remediation required immediate patching and review of east-west traffic alongside network segmentation measures. This incident underscores the steady targeting of enterprise SaaS platforms via zero-day and n-day flaws, and the increasing urgency for organizations to rapidly address vulnerabilities as soon as they are disclosed. With threat actors now weaponizing newly published vulnerabilities at an accelerated pace, organizations face renewed regulatory and business pressures to align with security best practices and compliance mandates.
6 months ago
Kill Chain
Inside the Synthient Stealer Log Threat Data: 2025's Monumental Infostealer Breach
In late 2025, a vast dataset known as the 'Synthient Stealer Log Threat Data' surfaced, aggregating over 3.5 terabytes and 23 billion rows of stolen credentials and website entries collected from infostealer malware and credential stuffing campaigns. This dataset comprised logs exfiltrated via platforms like Telegram, social media, and dark web forums, predominantly sourced from malware-infected endpoints. Analysis revealed 183 million unique email addresses, with over 8% never before seen in data breach collections, confirming both scale and uniqueness. The data's authenticity was validated through subscriber checks and corroborating evidence from exposed accounts. This incident underscores the escalating risks posed by mass infostealer malware campaigns, highlighting their ability to industrialize credential theft and rapidly distribute sensitive personal data. As attackers continuously refine malware arsenals and leverage broader distribution networks, organizations and individuals must act urgently to address credential reuse, enhance detection, and mitigate lateral movement threats.
6 months ago
Kill Chain
Malicious OAuth Apps in Microsoft 365: A 2025 Cloud Identity Wake-Up Call
In October 2025, security researchers discovered widespread abuse of OAuth applications within Microsoft 365 environments, exposing tenants to covert identity compromise. Threat actors leveraged both legitimate and custom-built ("traitorware" and "stealthware") OAuth apps to establish persistent, unauthorized access by obtaining illicit consent to sensitive permissions, often evading detection for years. The incident, analyzed across 8,000+ organizations, revealed that nearly 10% had malicious or risky apps, often due to default configurations allowing broad consent and weak app governance, resulting in increased risk of credential theft, data exposure, and lateral movement. This incident underscores the growing threat of cloud identity attacks exploiting trusted cloud-native mechanisms like OAuth. As organizations accelerate Microsoft 365 adoption and attackers pivot to persistent, stealthy access models, regular auditing of app permissions and stronger identity threat detection become urgent priorities for reducing cloud risk.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports