✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Oracle E-Business Suite Hit by Cl0p: CVE-2025-61882 Breach Exposes Enterprise Data
In October 2025, Oracle urgently released a security patch addressing CVE-2025-61882, a critical vulnerability in its E-Business Suite platform with a CVSS score of 9.8. The flaw, allowing unauthenticated remote attackers network access via HTTP, was actively exploited by the Cl0p ransomware gang in a series of data theft attacks. Threat actors leveraged the bug to gain control of impacted systems, enabling lateral movement and the exfiltration of sensitive business data. Oracle customers with exposed E-Business Suite deployments were specifically targeted, prompting a rapid, emergency response. This incident highlights the resurgence of large-scale supply chain ransomware attacks exploiting zero-day vulnerabilities in widely used enterprise software. Threat actors like Cl0p are increasingly automating exploitation campaigns, raising the bar for threat detection, patch management, and regulatory compliance requirements in digital enterprises.
6 months ago
Kill Chain
Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up
In October 2025, Oracle faced a significant security incident that exposed critical new 0-day vulnerabilities, impacting key platforms via exploits including a BitLocker bypass, the 'VMScape' hypervisor escape, and a fast-spreading WhatsApp worm. Threat actors leveraged multiple sophisticated attack vectors, targeting both enterprise infrastructure and end-user devices. The campaign enabled unauthorized lateral movement, data exfiltration, and disruption of cloud workloads, with global enterprises and managed service providers feeling downstream impact as security researchers identified widespread exploitation across hybrid and multicloud environments. These multi-pronged intrusions forced urgent mitigation efforts, including rapid patching, segmentation, and new traffic visibility controls to stem active attacks. The incident underscores escalating attacker sophistication in blending 0-day exploitation, social engineering, and cloud platform abuse. As threat campaigns increasingly combine lateral spread mechanisms with supply chain risks and targeted ransomware, it highlights the necessity of modern Zero Trust frameworks, advanced detection, and continuous security governance for organizations operating at cloud scale.
6 months ago
Kill Chain
Oracle E-Business Suite 2025: Critical SSRF Exploit Exposed and Analyzed
In October 2025, Oracle E-Business Suite was found to be vulnerable to an actively exploited server-side request forgery (SSRF) vulnerability, tracked as CVE-2025-61882. Threat actors leveraged a publicly available exploit script to manipulate the product’s servlet endpoints, extracting CSRF tokens and delivering a crafted payload capable of executing arbitrary commands via XSLT and Java reflection. The attack enabled remote code execution and potential lateral movement within affected enterprise environments, with indicators of compromise made public shortly after discovery. Oracle’s rapid response included a critical patch and threat intelligence advisory. This incident highlights an ongoing surge in advanced web exploitation techniques, particularly SSRF combined with deserialization and XSLT-based attacks. It underscores the urgent need for timely patching, defense-in-depth, and continuous anomaly detection, as well as the growing focus of attackers on business-critical ERP platforms.
6 months ago
Kill Chain
How Attackers Exploited a Zimbra Zero-Day via iCalendar Files in 2024
In early 2024, attackers exploited a previously unknown zero-day vulnerability in Zimbra Collaboration Suite (ZCS), targeting organizations via specially crafted .ICS (iCalendar) attachments. The vulnerability allowed threat actors to execute code by delivering malicious calendar files through email, bypassing traditional security filters. Incident responders observed attackers using this method for initial access, resulting in potential data theft, lateral movement, and disruption of email communications for affected businesses. The exploitation remained undetected for a significant period, amplifying operational and reputational risks for impacted entities. This incident highlights a growing trend of attackers leveraging supply chain and collaboration software vulnerabilities for sophisticated phishing and malware campaigns, often exploiting zero-days before vendors can respond. Organizations relying on common email and collaboration platforms face increased exposure to targeted file-type exploits and require improved visibility and rapid patching capabilities.
6 months ago
Kill Chain
Palo Alto Networks Portals Targeted by 500% Surge in Reconnaissance Scanning
On October 3, 2025, cybersecurity researchers at GreyNoise detected an unprecedented 500% spike in scanning activity targeting Palo Alto Networks login portals, marking the highest volume observed over a three-month period. The scanning involved a surge of IP addresses systematically probing these portals, suggesting highly targeted reconnaissance efforts by unknown threat actors. While no direct exploitation or breach was reported, such coordinated scanning is often the precursor to exploitation attempts against potential vulnerabilities in security infrastructure, especially as targeted technologies are foundational for enterprise security postures. This incident exemplifies the growing trend of automated reconnaissance on high-value network assets as adversaries aim to map attack surfaces for later campaigns. Organizations relying on exposed management interfaces must bolster detection, segmentation, and access controls to address these evolving reconnaissance tactics.
6 months ago
Kill Chain
CometJacking: How a Single Click Turned Perplexity's Comet AI Browser into a Data Thief
In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools. This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.
6 months ago
Kill Chain
Oracle EBS Exploited in Clop Ransomware Extortion Campaign (2025)
In September 2025, Oracle confirmed that customers running E-Business Suite (EBS) were targeted by extortion emails attributed to the Clop ransomware gang, following exploitation of security vulnerabilities addressed in the July 2025 Critical Patch Update. Multiple executives at affected companies received emails demanding ransom, with Clop claiming to have exfiltrated confidential data from unpatched Oracle EBS instances. While Oracle has not formally verified the data theft, the vulnerabilities—three of which were remotely exploitable without authentication—enabled attackers to potentially access sensitive business documents and threaten public disclosure if ransoms were not paid. This incident highlights a continued and escalating trend of ransomware groups leveraging zero-day and freshly patched vulnerabilities to target critical enterprise software. Organizations dependent on ERP and business process applications are increasingly at risk, underscoring the urgent need for rapid patching and advanced network-layer security controls.
6 months ago
Kill Chain
CometJacking Attack: How Prompt Injection Exposed Comet AI Browser Users in 2025
In October 2025, security researchers from LayerX uncovered a novel 'CometJacking' attack affecting Perplexity's Comet AI browser. This prompt injection attack leverages URL parameters to deliver hidden instructions that compel the browser to access and exfiltrate sensitive data—such as Gmail messages and Google Calendar information—from connected services, without any need for user credentials or interaction. The technique exploits the 'collection' URL parameter to insert malicious prompts, instructing the AI agent to gather and encode user data (e.g., using base64) before surreptitiously transmitting it to attacker-controlled endpoints. Despite being informed, Perplexity dismissed the security risk, highlighting concerns about unmitigated AI agent behaviors.This incident surfaces amid growing adoption of agentic AI browsers and illustrates the ease with which prompt injection tactics can sidestep controls, particularly in tools integrated with sensitive personal or enterprise accounts. The attack underscores the increasing threat from adversarial prompt engineering as AI agent usage expands rapidly.
6 months ago
Kill Chain
Signal Launches SPQR: A Quantum-Safe Encryption Upgrade for 2025
In October 2025, Signal introduced a major upgrade to its encryption suite by deploying the Sparse Post-Quantum Ratchet (SPQR), designed to secure user communications against present and future quantum computing threats. Developed in collaboration with leading academic and industry partners, SPQR brings a 'triple ratchet' protocol leveraging hybrid cryptography based on both traditional and quantum-resistant key exchange mechanisms. This system provides continual key rotation, forward secrecy, and robust post-compromise security, ensuring that even if current keys are compromised, future messages remain protected. The rollout will be gradual and backward-compatible, affecting Signal’s 100 million global users without requiring manual intervention. The launch of SPQR is a landmark response to the rise of quantum computing, which threatens conventional encryption schemes. Its introduction reflects mounting industry urgency to adopt advanced cryptographic standards and maintain trust in privacy-critical communications platforms amid rapid shifts in the threat landscape.
6 months ago
Kill Chain
SORVEPOTEL: New WhatsApp-Driven Malware Campaign Hits Brazil
In late 2025, cybersecurity researchers identified a rapid outbreak of a self-spreading malware targeting Brazilian Windows users through WhatsApp, labeled SORVEPOTEL and tracked as the Water Saci campaign. The malware leverages the inherent trust and widespread popularity of WhatsApp by delivering malicious payloads via chat messages, which entice users to download infected files. Once inside a system, SORVEPOTEL propagates by messaging victims’ contacts, enabling swift lateral movement and widespread distribution. Notably, the campaign appears engineered for rapid proliferation rather than for data theft or ransomware deployment, showcasing evolving malware propagation tactics. This incident highlights the increasing sophistication and speed of messaging app-based malware and reflects a broader trend of social engineering campaigns capitalizing on trusted digital platforms. Organizations should re-examine endpoint protections and user awareness in light of emerging threats exploiting popular communications channels.
6 months ago
Kill Chain
Detour Dog Exposes DNS-Powered Stealer Risk: A 2025 Campaign Analysis
In October 2025, threat intelligence researchers revealed that the actor known as Detour Dog orchestrated wide-scale campaigns to deliver the Strela Stealer information stealer using DNS-powered malware infrastructure. Detour Dog’s operation involved maintaining control over a network of malicious domains, enabling initial delivery of a backdoor named StarFish, which then facilitated deployment of Strela Stealer. This campaign leveraged covert DNS traffic and evasion techniques, making threat detection and containment difficult for enterprise defenders. Victimized organizations faced increased risk of credential theft, data exfiltration, and operational disruption as a result. This incident highlights the rising trend of weaponizing benign protocols like DNS for malware delivery and lateral movement, as well as the emergence of advanced information stealers targeting enterprise networks and cloud environments. Organizations must adapt controls and detection strategies to defend against increasingly sophisticated, protocol-abusing threats.
6 months ago
Kill Chain
Rhadamanthys Stealer 2025: Device Fingerprinting, Steganography, and the New Face of Data Theft
In October 2025, cybersecurity researchers uncovered significant new capabilities in the Rhadamanthys Stealer malware, including advanced device fingerprinting and the use of PNG steganography to distribute malicious payloads. Initially spread via cybercrime forums, the malware author has expanded its ecosystem with additional tools like Elysium Proxy Bot and Crypt Service, targeting organizations worldwide. Threat actors leveraged these upgrades to collect detailed browser and system data while evading detection, resulting in an uptick of credential, financial, and sensitive data thefts across enterprise environments. The evolution of Rhadamanthys Stealer highlights a broader trend of information stealer malware using novel evasion tactics and multi-tool ecosystems. Its modularity and innovative payload delivery have driven increased attention from security teams and regulators, as businesses seek to defend against ever-more-sophisticated data exfiltration methods.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports