Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2615 threat reports
Page 203 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 24252436 / 2615 reports
Adobe Analytics 2025 Bug Exposes Cross-Tenant Tracking Data
Impact· high

Adobe Analytics 2025 Bug Exposes Cross-Tenant Tracking Data

In September 2025, an ingestion bug in Adobe Analytics caused cross-tenant data exposure, allowing customer tracking data from some organizations to appear in the analytics reports of others for nearly a day. The incident began on September 17 due to a performance optimization update that led to incorrect data values surfacing in Analysis Workspace reports. Approximately 3-5% of collected data—across Data Feeds, Live Stream, and scheduled reports—was impacted, with some fields being overwritten by data from other tenants. Adobe promptly reverted the change on September 18 and undertook remediation to cleanse datasets, advising customers to purge affected data from systems and backups to prevent further exposure. This incident underscores the risk posed by inadvertent data exposure within multi-tenant SaaS platforms and the criticality of robust data segregation and validation controls. With regulatory scrutiny over data privacy at an all-time high, such events illustrate how operational changes, even absent malicious intent, can have significant compliance and business ramifications for all affected customers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
2025 Red Hat OpenShift AI Vulnerability Exposes Hybrid Cloud to Full Takeover
Impact· medium

2025 Red Hat OpenShift AI Vulnerability Exposes Hybrid Cloud to Full Takeover

In October 2025, a critical privilege escalation vulnerability was disclosed in Red Hat OpenShift AI, a popular platform for managing AI workloads across hybrid cloud infrastructures. The flaw allowed attackers to obtain elevated permissions and, under certain conditions, seize full control of affected environments. Security researchers identified that threat actors could exploit weak internal segmentation and misconfigurations within the AI lifecycle management layers, resulting in potential unauthorized lateral movement and broad operational impact across connected workloads. Red Hat promptly released advisories and patches, but organizations running unpatched versions remain at risk of infrastructure takeover and sensitive data exposure. This incident comes amid a surge in attacks targeting AI infrastructure and hybrid cloud environments, as adversaries increasingly exploit complex, interconnected platforms. The breach highlights the escalating risk posed by privilege escalation flaws in widely adopted enterprise AI solutions and underscores the urgent need for rigorous segmentation, threat detection, and rapid patch cycles.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Wiretap Unveiled: DDR4 Side-Channel Attack Extracts Intel SGX ECDSA Keys in 2025
Impact· medium

Wiretap Unveiled: DDR4 Side-Channel Attack Extracts Intel SGX ECDSA Keys in 2025

In October 2025, cybersecurity researchers from Georgia Institute of Technology and Purdue University disclosed a novel hardware-based attack that compromises Intel SGX enclaves by exploiting the DDR4 memory bus. By physically placing a wiretap interposer on the memory channel, the attackers were able to observe and ultimately extract ECDSA private keys used for remote attestation, undermining the core protection mechanisms of Intel’s SGX. This passive attack method does not require malware on the target, posing risk for highly sensitive operational environments and organizations reliant on enclave-based security. This incident underscores the growing sophistication of hardware side-channel research and the urgent need to assess trust boundaries in server environments. With critical infrastructure and cloud offerings often relying on SGX for confidential computing, organizations must scrutinize physical and hardware-layer exposures amid a surge of advanced hardware attack demonstrations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OneLogin 2025: OIDC/API Key Flaw Exposes Client Secrets to Attackers
Impact· medium

OneLogin 2025: OIDC/API Key Flaw Exposes Client Secrets to Attackers

In October 2025, a critical security vulnerability (CVE-2025-59363, CVSS 7.7) was disclosed in the One Identity OneLogin IAM platform. The flaw allowed threat actors to use compromised or exposed API keys to retrieve sensitive OpenID Connect (OIDC) application client secrets. Attackers exploiting this vulnerability could potentially impersonate trusted applications, resulting in unauthorized access to protected enterprise resources and disruption of identity-based authentication flows. OneLogin responded with a patch following public disclosure, but the exposure window placed numerous organizations at risk of credential theft and downstream compromise. This incident highlights persistent risks in identity and access management platforms, especially around API security and secret handling. Recent trends show attackers increasingly targeting IAM tools and exploiting weak OIDC/OAuth implementations, making robust zero trust segmentation, continuous threat monitoring, and compliance with established frameworks more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Chinese APT Group Abuses VMware Privilege Escalation Flaw Throughout 2023
Impact· low

Chinese APT Group Abuses VMware Privilege Escalation Flaw Throughout 2023

In 2023, sophisticated threat actors attributed to China exploited a previously unknown privilege-escalation vulnerability in VMware platforms for nearly a year before its discovery. Attackers leveraged this flaw, which appeared benign, to gain persistent and stealthy access to targeted virtual infrastructure. Their methods enabled lateral movement, data gathering, and privileged actions within highly segmented data center and cloud environments, affecting a broad range of organizations relying on virtualization for critical workloads. The long-term nature of the operation underscores challenges in detecting nation-state activity exploiting zero-day and privilege-related weaknesses. This incident highlights a broader escalation in advanced persistent threat (APT) campaigns targeting cloud and virtualization layers. As attackers increasingly exploit such integral software stacks with subtle techniques, organizations must reevaluate network segmentation, privilege management, and continuous monitoring to remain resilient.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
China APT Launches Fileless, Precision Attack in 2024: Lateral Movement and Cloud Risk
Impact· low

China APT Launches Fileless, Precision Attack in 2024: Lateral Movement and Cloud Risk

In early 2024, an advanced persistent threat (APT) group dubbed 'Phantom Taurus,' believed to be affiliated with China, executed a sophisticated cyberattack targeting large enterprises in the finance and technology sectors. The attackers leveraged an in-memory, fileless backdoor ('IIServerCore') on Microsoft Windows servers to evade traditional detection, exploiting east-west traffic within cloud and hybrid environments. Initial access was likely gained through phishing and exploitation of public-facing applications, enabling lateral movement and persistent foothold. Impact included disruption of business operations, potential data exfiltration, and internal system compromise, with detection hampered by the backdoor's stealth techniques and encrypted command and control channels. This incident underscores an increasing trend of nation-state actors employing fileless malware and leveraging deep Windows system knowledge to bypass endpoint and network defenses. The use of advanced lateral movement tactics and persistent, in-memory attack tools highlights ongoing gaps in east-west cloud visibility and the urgency for zero trust segmentation across enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Windows 10 EOL: The Mass Enterprise Vulnerability Surge of 2024
Impact· high

Windows 10 EOL: The Mass Enterprise Vulnerability Surge of 2024

In October 2024, Windows 10—widely used across enterprise networks—will reach end-of-life, ceasing to receive security patches from Microsoft. This event will instantly triple the number of unsupported operating systems found within business environments, dramatically expanding the global attack surface. Cybercriminals are expected to exploit these 'undead' or unpatched devices by leveraging known vulnerabilities, conducting packet sniffing, lateral movement, and data exfiltration attacks—especially against organizations with poor segmentation and lacking egress enforcement. This shift is particularly significant as attackers increasingly target infrastructure vulnerabilities and exploit legacy systems. The upcoming EOL is driving regulatory attention and sparking urgent reviews of segmentation, east-west security, and encrypted traffic controls in enterprise risk postures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Breaking Confidential Computing: 2024 Hardware Attack Reveals Hidden Risks
Impact· medium

Breaking Confidential Computing: 2024 Hardware Attack Reveals Hidden Risks

In early 2024, cybersecurity researchers demonstrated a major hardware vulnerability impacting modern Intel and AMD processors' confidential computing features. Using a low-cost, hardware-based "battering RAM" side-channel attack, the team was able to extract sensitive data from memory that is meant to be encrypted and protected even during active use. The exploit bypasses both software and hardware encryption of data in use, undermining key assumptions of secure enclave technologies widely deployed in cloud and enterprise environments. This proof-of-concept exposes clients to risks of data theft or tampering, especially in multitenant or shared infrastructure. This incident underscores a growing trend of sophisticated hardware exploitation that threatens cloud workloads employing confidential computing for compliance and security. With confidential computing adoption rising across regulated industries, vulnerabilities at the silicon level present urgent business and regulatory risks, especially as attackers adapt to target trusted execution environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Broadcom Patches VMware NSX Flaws Flagged by NSA: What It Means for Cloud Security in 2024
Impact· low

Broadcom Patches VMware NSX Flaws Flagged by NSA: What It Means for Cloud Security in 2024

In June 2024, Broadcom addressed two high-severity vulnerabilities in VMware NSX, originally discovered and reported by the U.S. National Security Agency (NSA). The flaws—tracked as CVE-2024-22246 (Local Privilege Escalation) and CVE-2024-22247 (Authentication Bypass)—could allow attackers to escalate privileges or bypass security controls on affected VMware NSX deployments. No evidence of exploitation in the wild has been reported, but these vulnerabilities could have enabled threat actors to move laterally, evade segmentation, and compromise critical virtualized environments if left unpatched. This disclosure comes amid heightened scrutiny of virtualization platforms used in cloud and hybrid infrastructures. As state actors increasingly target foundational cloud technologies and security researchers identify complex flaws, enterprises are pressed to maintain rapid patch cycles and review dependency trust, especially for technologies underpinning multi-cloud architectures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA: Critical Linux Sudo Vulnerability (CVE-2025-32463) Now Under Active Attack
Impact· low

CISA: Critical Linux Sudo Vulnerability (CVE-2025-32463) Now Under Active Attack

In September 2025, cybersecurity authorities, including CISA, issued urgent warnings regarding a critical privilege escalation vulnerability (CVE-2025-32463) in the Linux sudo package. Attackers exploited this flaw to execute arbitrary commands with root-level privileges using the -R (--chroot) option even if the user was not listed in the sudoers file. The vulnerability, present in sudo versions 1.9.14 to 1.9.17 and discovered by Rich Mirch of Stratascale, went public with a proof-of-concept exploit shortly after its disclosure, facilitating active exploitation globally. Federal agencies were given a strict deadline to apply mitigations due to confirmed in-the-wild attacks. This incident underscores the persistent threat of privilege escalation in foundational system components and the risks posed by quickly weaponized exploits. The urgency reflects both the ease of exploitation and the wide adoption of vulnerable Linux versions, making rapid patching a critical imperative for organizations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chinese APT UNC5174 Exploits VMware Zero-Day for Widespread Privilege Escalation
Impact· low

Chinese APT UNC5174 Exploits VMware Zero-Day for Widespread Privilege Escalation

In October 2024, Chinese state-sponsored group UNC5174 began exploiting a zero-day vulnerability (CVE-2025-41244) affecting VMware Aria Operations and VMware Tools, enabling privilege escalation from unprivileged users to root on targeted virtual machines. The flaw, present in both credential-based and credential-less modes, allowed attackers to plant malicious binaries, gain root access, and ultimately compromise internal systems. This attack appears to be part of a wider campaign, with UNC5174 known for targeting critical infrastructure and selling access to compromised entities globally. Broadcom, which owns VMware, patched the vulnerability in September 2025 following an investigation by NVISO and Mandiant, but the exploit was active for nearly a year prior to disclosure. This incident underscores the increasing frequency of sophisticated supply chain and virtualization platform attacks by well-resourced APTs, especially those linked to state interests. Security teams should be alert to the persistence of zero-day exploitation and trends in privilege escalation across hybrid and cloud infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Remote Code Execution Vulnerability in WD My Cloud Devices Raises Security Stakes
Impact· medium

Critical Remote Code Execution Vulnerability in WD My Cloud Devices Raises Security Stakes

In June 2024, Western Digital disclosed a critical security vulnerability in its My Cloud NAS devices, allowing unauthenticated remote attackers to execute arbitrary system commands via specially crafted HTTP requests. The exploited flaw, identified as CVE-2024-23333, affects multiple My Cloud firmware versions, exposing data and device functionality to full compromise. Western Digital released urgent firmware patches following the discovery, and no widespread exploitation was reported at the time of disclosure. However, researchers highlighted that remotely exploitable flaws in NAS devices pose significant risk for both individual and enterprise users who rely on these systems for data backup and storage. This incident underscores the growing prevalence of remote code execution vulnerabilities targeting storage infrastructure, particularly as attackers increase focus on internet-exposed edge devices. With data privacy regulations tightening and threat actors refining exploit automation, prompt patching and network segmentation are more critical than ever to prevent lateral movement and data exfiltration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports