✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Targeted SVG Phishing Hits Ukrainian Agencies with CountLoader, PureRAT
In September 2025, cybersecurity researchers uncovered a targeted phishing campaign impersonating Ukrainian government agencies. Attackers distributed emails containing malicious SVG file attachments, crafted to deliver the CountLoader malware. Upon execution, CountLoader dropped secondary payloads—Amatera Stealer and PureMiner—allowing cybercriminals to steal sensitive information and deploy cryptomining operations on victim systems. The attacks leveraged sophisticated social engineering and file formats to evade detection, threatening both public sector and affiliated organizations. This incident highlights a surge in phishing operations leveraging advanced loaders and novel file types, such as SVG. As more attackers exploit government-themed lures and multi-tool chains, organizations face an elevated risk of data exfiltration, credential theft, and operational disruption, demanding robust, adaptive security controls.
6 months ago
Kill Chain
Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data
In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic. The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.
6 months ago
Kill Chain
Nation-State Zero-Day Attacks Breach Cisco Firewalls in 2024
In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection. This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.
6 months ago
Kill Chain
Forta GoAnywhere 2025: Zero-Day Supply Chain Breach Raises Compliance Alarms
In September 2025, Forta's GoAnywhere MFT file-transfer service was found to contain a critical deserialization vulnerability (CVE-2025-10035) which could enable attackers to execute arbitrary code remotely. Although Forta initially stopped short of confirming exploitation, credible evidence from threat researchers surfaced showing active in-the-wild attacks dating back to at least September 10. The exploit relies on the attacker’s ability to sign Java objects with a stolen or leaked private key, raising concerns over supply chain security and key management. Enterprises using GoAnywhere MFT face risks of data exfiltration and operational disruption. The incident highlights ongoing challenges in vendor transparency and the risks associated with critical third-party software. It underscores the urgent need for enhanced monitoring, timely vendor disclosures, strict key management, and robust segmentation strategies, as similar exploitation patterns have escalated across the supply chain attack landscape.
6 months ago
Kill Chain
Cisco ASA Firewall Zero-Day Attacks 2025: Immediate Remediation Required
In September 2025, Cisco revealed that two zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) affecting ASA Firewall and FTD software were exploited in active campaigns. One flaw allowed authenticated remote code execution, while the other exposed restricted URL endpoints without authentication. Attackers leveraged these security gaps to potentially gain unauthorized access and control over vulnerable network infrastructure. Security advisories emphasized the need for immediate patching, with involvement from global cybersecurity agencies such as ACSC, CCCS, NCSC, and CISA in threat investigation and response. This breach highlights a surge in zero-day exploitations against critical network appliances and underscores the evolving sophistication of attacker reconnaissance and exploitation cycles. The incident reflects an ongoing trend of targeting edge devices as organizations increase reliance on remote and hybrid work models.
6 months ago
Kill Chain
APT Campaign Exploits Cisco ASA Zero-Days: Persistent Threats to Government Devices in 2025
In September 2025, U.S. federal agencies were ordered by CISA to urgently patch Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices after two critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) were exploited by the APT group UAT4356 (STORM-1849). Attackers achieved unauthenticated remote code execution and persistent control by manipulating device ROMMON, deploying malware such as LINE VIPER and the RayInitiator bootkit to facilitate malware implants, command execution, and possible data exfiltration. The campaign, linked to the larger ArcaneDoor operation, threatened essential government and global infrastructure by allowing full device compromise, evasion of detection, and resistance to conventional remediation steps. This incident highlights an escalating trend in sophisticated, state-linked attacks targeting edge infrastructure, often leveraging supply-chain weaknesses and persistent malware able to survive reboots and firmware updates. It also underscores renewed regulatory pressure for timely vulnerability mitigation and increased focus on Zero Trust architectures for critical sectors.
6 months ago
Kill Chain
Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data
In February 2024, the unofficial 'postmark-mcp' npm package—a clone of the genuine Postmark MCP email handler—was discovered to have maliciously exfiltrated users' email data. With a single line of code added in its latest update, the package silently sent every processed email to an external domain controlled by the attacker. This supply chain compromise exploited developer trust in open-source libraries, resulting in unintentional leakage of confidential user communications and putting affected organizations and their customers at risk of data exposure or further attacks. This incident underscores the growing frequency and sophistication of supply chain attacks targeting software ecosystems like npm. Organizations face heightened regulatory and reputational risks as attackers leverage trusted distribution platforms to propagate malicious code, making robust dependency monitoring and vendor validation more critical than ever.
6 months ago
Kill Chain
Cisco 2025: Critical SNMP Vulnerability Actively Exploited in IOS and IOS XE
In September 2025, Cisco disclosed that an actively exploited vulnerability (CVE-2025-20352, CVSS 7.7) in its IOS and IOS XE software allows remote attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition via specially crafted SNMP packets. The flaw, which came to light after attacker activity was observed leveraging previously compromised administrative credentials, impacts a broad range of Cisco networking equipment. The immediate impact includes risks of device takeover, network disruption, and possible lateral movement within victims’ environments. This incident underscores the criticality of securing network infrastructure against both external and internal threats, as attackers continue to exploit overlooked or unpatched vulnerabilities at the core of modern networks. The active exploitation highlights an urgent need for organizations to review segmentation, monitoring, and patch management practices in light of evolving attack techniques.
6 months ago
Kill Chain
Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach
In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch. This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.
6 months ago
Kill Chain
Cisco ASA Zero-Day (CVE-2025-20333) Breach: Inside the CISA Emergency Response
In September 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20333, CVSS 9.9) affecting its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) Software. Attackers actively exploited improper input validation in the VPN web server, enabling them to bypass authentication and potentially gain unauthorized access to sensitive environments. Cisco urged immediate patching as exploitation was observed targeting both perimeter and internal firewalls, demonstrating advanced lateral movement strategies. This exploitation prompted an emergency mitigation directive from CISA to reduce risk across U.S. federal agencies and private enterprises. This incident underscores the ongoing evolution of threat actors leveraging zero-days to target critical infrastructure firewalls, coinciding with a nationwide spike in sophisticated, identity-driven attacks. Organizations are under increasing regulatory scrutiny to patch rapidly and advance segmentation, threat monitoring, and east-west traffic controls.
6 months ago
Kill Chain
Scattered Spider Ransomware: Teen Member Arrested, Group Claims Shutdown in 2024
In June 2024, law enforcement arrested a teenage member of the notorious Scattered Spider ransomware group, a cybercriminal collective linked to disruptive attacks against major organizations including MGM Resorts and Caesars Entertainment. The arrest followed claims by the group that it was shutting down operations amid heightened law enforcement scrutiny and infighting among its members. Scattered Spider became infamous for leveraging social engineering and identity-based attacks to gain initial entry, then rapidly moving laterally to deliver ransomware and conduct data theft. This latest development underscores the increasingly aggressive response from law enforcement to high-impact ransomware threats. The recent action highlights the continued evolution and volatility of ransomware groups, many of which are now using sophisticated identity compromise and cloud-based attack chains. Organizations should remain vigilant as law enforcement disruptions may cause threat actors to splinter, rebrand, or accelerate new attack campaigns using similar techniques.
6 months ago
Kill Chain
Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security
Between 2017 and 2025, waves of exploit attempts have targeted Hikvision IP cameras using vulnerabilities such as CVE-2017-7921. Attackers abused easily guessable or default credentials passed via HTTP GET parameters, leveraging weak authentication mechanisms to access sensitive camera endpoints, user configurations, and device data. The entry vector relied on IoT device misconfigurations and insecure design, while brute-force attempts and credential stuffing remain prevalent. This activity has potential to expose live feeds, user data, and create a foothold into internal networks, with implications for privacy, compliance, and physical security. This breach is notable today as attempts to exploit Hikvision and similar IoT cameras continue at scale, highlighting persistent IoT security challenges due to poor credential hygiene, slow patch adoption, and device interface limitations. The incident demonstrates ongoing risk as attackers increasingly automate targeting of legacy and unpatched embedded devices across global networks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports