✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
F5 Breach 2024: Nation-State Actors Steal Source Code and Vulnerabilities
In early 2024, F5 Networks suffered a significant security breach attributed to a sophisticated nation-state actor, which resulted in the theft of BIG-IP source code and undisclosed vulnerability details. The attackers leveraged targeted intrusion tactics, exploiting gaps in F5's internal protections to gain access to proprietary codebases and sensitive vulnerability information. This breach elevated the risk for F5’s enterprise and government customers, as the exposed vulnerabilities could facilitate future attacks on critical infrastructure globally. The incident highlights both supply chain implications and the heightened impact of intellectual property theft. This attack underscores a strategic shift where advanced threat actors seek not only data but also exploit software supply chains and zero-day vulnerabilities, raising urgent concerns for organizations dependent on key network infrastructure vendors. With regulatory scrutiny sharpening around supply chain risk and software assurance, incidents like this set new urgency for proactive defense and vendor risk management.
6 months ago
Kill Chain
Adobe AEM Forms Zero-Day (CVE-2025-54253) Actively Exploited for Remote Code Execution
In October 2025, a maximum-severity vulnerability (CVE-2025-54253) in Adobe Experience Manager (AEM) Forms was discovered to be actively exploited in the wild. The flaw, allowing unauthenticated remote code execution via authentication bypass, affected AEM Forms on JEE versions 6.5.23 and earlier. Researchers from Searchlight Cyber originally reported the issue in April, but public exploit code and detailed writeups emerged before Adobe issued a patch in August. Attackers were able to exploit the misconfiguration to gain complete control over unpatched systems, endangering both public and private sector organizations. This incident underscores the increasing threat posed by delayed patching and public disclosure of unpatched zero-days. It highlights the importance of rapid vulnerability management, particularly for federal agencies under BOD 22-01, and serves as a warning for organizations to prioritize patching high-impact application flaws to protect critical business operations.
6 months ago
Kill Chain
Exploited Zero-Day in Gladinet CentreStack: Rapid RCE and the Need for Zero Trust
In October 2025, Gladinet patched a critical zero-day vulnerability (CVE-2025-11371) in its CentreStack file-sharing software, which had been exploited by threat actors since late September. The attackers leveraged a local file inclusion flaw to access the application's Web.config file and extract the machine key, subsequently exploiting a chained deserialization vulnerability (CVE-2025-30406) to achieve unauthenticated remote code execution. The service's SYSTEM-level privileges enabled lateral movement and sensitive file access. Gladinet released mitigations and a full patch, urging immediate client upgrades to prevent further compromise of business environments. This incident highlights a continuing trend in targeting widely used business collaboration platforms via sophisticated vulnerability chaining, often bypassing previous mitigations. The exploitation’s speed and public proof-of-concept release underscore the growing urgency for rapid patch management and proactive threat detection across enterprise SaaS deployments.
6 months ago
Kill Chain
Microsoft Disrupts 2025 Ransomware Campaign Using Fake Teams Installers
In October 2025, Microsoft successfully disrupted a ransomware campaign orchestrated by the threat group Vanilla Tempest (also known as Vice Society/VICE SPIDER) targeting Microsoft Teams users. Attackers used malvertising and SEO poisoning to promote websites impersonating the official Teams download page, tricking users into downloading malicious installers. These fake installers delivered the Oyster backdoor, granting attackers remote access for data theft, command execution, and the deployment of Rhysida ransomware. Microsoft responded by revoking over 200 abused code-signing certificates used to legitimize the malicious payloads, effectively hampering the campaign. This attack underscores the growing risk of supply chain compromise via trusted application installers and increasingly sophisticated social engineering techniques. The resurgence of ransomware-as-a-service operators leveraging signed malware highlights the urgent need for identity-driven defenses, vigilant certificate monitoring, and robust endpoint security measures.
6 months ago
Kill Chain
Hackers Exploit Cisco SNMP Zero-Day to Deploy Rootkit on Switches
In October 2025, threat actors exploited a zero-day vulnerability (CVE-2025-20352) in Cisco networking devices, leveraging flaws in the Simple Network Management Protocol (SNMP) to gain remote code execution on affected IOS and IOS XE switches. Trend Micro reported that attackers primarily targeted Cisco 9400, 9300, and legacy 3750G series devices, deploying rootkits on switches and unprotected Linux systems. These rootkits established a persistent backdoor, allowing attackers to control device behavior, evade logging, bypass security controls, and move laterally across VLANs. Cisco acknowledged active exploitation and classified the issue as a zero-day, urging immediate firmware and ROM analysis if compromise is suspected. The incident highlights the continued targeting of network infrastructure via legacy vulnerabilities and sophisticated rootkits, as well as the pressing need for organizations to update detection capabilities, even on older or end-of-life systems. The use of unpatched infrastructure and the absence of robust endpoint detection provided attackers with a broad attack surface, underpinning the current urgency around zero trust networking and east-west traffic monitoring.
6 months ago
Kill Chain
Nation-State Breach of F5 Sparks CISA Emergency Directive for Federal Agencies
In mid-2024, F5 Networks disclosed that a sophisticated nation-state attacker gained prolonged, unauthorized access to its internal systems, compromising BIG-IP source code and undisclosed vulnerability details. The breach, detected in August, prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to issue an emergency directive compelling federal agencies to immediately identify, patch, or disconnect thousands of F5 products in their environments. While no direct federal compromises have been reported yet, the theft of sensitive product and security information could facilitate widespread exploitation across both federal agencies and private organizations relying on F5 systems. This incident underscores heightened risks to supply chain integrity and critical infrastructure posed by persistent nation-state campaigns. With attackers targeting widely deployed technology vendors, government and industry face urgent pressure to enhance monitoring, rapid patching, and zero trust defenses to mitigate risks from downstream exploitation of software supply chains.
6 months ago
Kill Chain
F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code
In August 2025, cybersecurity giant F5 detected a sophisticated breach by nation-state hackers who gained unauthorized access to its BIG-IP product development environment and engineering knowledge management platforms. Over an extended period, attackers exfiltrated undisclosed BIG-IP vulnerabilities, product source code, and select customer configuration information. F5 asserts no evidence that the attackers modified software, exploited the stolen vulnerabilities in active attacks, or that critical customer data was exposed. Response actions included credential rotations, hardening of development environments, enhanced threat detection, and external code audits by firms such as CrowdStrike, Mandiant, NCC Group, and IOActive. F5 also proactively issued security updates and guidance to impacted customers. This incident underscores the growing trend of sophisticated, supply-chain-oriented intrusions targeting technology providers with a wide enterprise customer base. It illustrates the strategic value of source code and zero-day exploits to well-resourced threat actors, and raises ongoing concerns about the security of key software infrastructure used widely across industries.
6 months ago
Kill Chain
Microsoft Windows Server 2025 Update Breaks Active Directory Sync
In September 2025, Microsoft’s security updates for Windows Server 2025 triggered Active Directory (AD) Domain Services synchronization issues, specifically affecting environments with large AD security groups exceeding 10,000 members. The incident, stemming from update KB5065426, disrupted vital processes like Microsoft Entra Connect Sync, resulting in incomplete directory synchronization. Microsoft quickly acknowledged the bug, issued a temporary registry-based workaround, and warned that improper registry modifications carried significant risks. The root cause is connected to directory synchronization controls that do not yet officially support Windows Server 2025. This event highlights the increasing operational risk organizations face from software update regressions affecting core identity infrastructure. In an era of widespread cloud adoption and hybrid identity services, such failures can severely impact business continuity and compliance, amplifying the urgency for robust change management and pre-deployment validation.
6 months ago
Kill Chain
F5 2025 Supply Chain Breach: BIG-IP Vulnerabilities Exposed by State Hackers
In August 2025, cybersecurity company F5 detected a sophisticated supply chain attack resulting in the theft of source code and undisclosed vulnerabilities affecting its flagship BIG-IP products. The breach, attributed to state-sponsored hackers, did not lead to immediate exploitation but exposed potentially critical flaws. F5 responded by rapidly developing and releasing security patches for 44 vulnerabilities, proactively urging its global clientele—including many Fortune 500 companies and federal agencies—to update systems and implement enhanced monitoring. No evidence was found of modifications to the supply chain or active use of the stolen information as of disclosure. This incident highlights mounting concerns around supply chain security and zero-day vulnerability exposure, particularly within critical infrastructure and cloud environments. The breach also triggered regulatory intervention, with CISA issuing emergency directives for federal agencies, underscoring rising government attention to third-party risks and broader cybersecurity resilience in the face of advanced persistent threats.
6 months ago
Kill Chain
Fake LastPass & Bitwarden Breach Alerts: Phishing Attack Delivers Malware (2024)
In early June 2024, a sophisticated phishing campaign targeted users of password managers LastPass and Bitwarden. Attackers sent convincing emails, falsely claiming that the services had suffered security breaches and instructing recipients to download a new, supposedly more secure, desktop version. The malicious download actually installed malware, enabling attackers to hijack compromised PCs and potentially steal credentials or other sensitive data. Victims who downloaded the fake app were exposed to significant risks, including credential theft and remote control of their systems. This incident highlights escalating use of credible brand impersonation and urgent alert tactics by cybercriminals. The campaign underscores the vulnerabilities associated with password manager users and demonstrates the growing threat landscape for identity-driven and social engineering attacks.
6 months ago
Kill Chain
Capita Hit by Black Basta Ransomware: 6.6 Million Impacted in 2023 Breach
In March 2023, UK outsourcing giant Capita suffered a major data breach after an employee downloaded a malicious file, giving threat actors access to internal systems. The Black Basta ransomware gang exploited delayed response and weak access controls to maintain persistence for 58 hours, move laterally, and exfiltrate nearly a terabyte of sensitive data covering 6.6 million individuals, including customers of over 325 pension providers. The attackers deployed ransomware, resetting passwords and disrupting access, forcing Capita to take some systems offline and ultimately resulting in a £14 million regulatory fine after failing to meet key security requirements. This breach highlights the growing menace of ransomware operations targeting supply chain and service providers, with regulatory authorities emphasizing rapid response, robust access controls, and continuous security testing. Organizations face increased scrutiny to maintain strong cybersecurity baselines as attackers evolve tactics and exploit internal weaknesses.
6 months ago
Kill Chain
How Adversaries Used AI CLI Tools for Command & Control in 2024
In early 2024, security researchers identified a new wave of cyber intrusions involving adversaries weaponizing AI-enabled command-line tools to facilitate command and control activities within targeted business environments. Attackers leveraged popular AI code-assistants such as Claude Code, integrating them into CLI workflows to generate and execute malicious payloads, exfiltrate credentials, and bypass conventional security controls. The attack chain typically relied on legitimate processes, enabling lateral movement and credential theft while avoiding detection by traditional endpoint defenses. Unauthorized east-west traffic and encrypted exfiltration allowed threat actors to maintain persistence and evade standard monitoring solutions, impacting both operational continuity and sensitive business data. The incident underscores a rapidly evolving threat landscape where generative AI and shell automation converge, accelerating the sophistication and speed of adversary tactics. As enterprises adopt AI-driven DevOps and operational tooling, the risk of shadow AI and undetected rogue automation increases, compelling a shift towards advanced visibility, zero trust segmentation, and policy enforcement across hybrid environments.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports