✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet
In early 2024, cybersecurity researchers uncovered a widespread campaign exploiting misconfigured Docker daemons in cloud environments. Attackers leveraged openly accessible Docker APIs to deploy malicious containers and enlist compromised servers into a large-scale DDoS (Distributed Denial of Service) botnet. Using legitimate, cloud-native tools made detection and remediation more challenging for security teams. The incident resulted in increased infrastructure costs, service disruptions, and heightened risk of lateral movement and data exfiltration within affected organizations. This attack is illustrative of a growing trend where adversaries abuse cloud-native technologies and misconfigurations to orchestrate large-scale, persistent threat activity. As organizations accelerate cloud adoption, gaps in cloud security posture and lack of network segmentation are creating new attack surfaces, stressing the need for enhanced visibility, zero trust controls, and real-time anomaly detection.
6 months ago
Kill Chain
GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024
In early 2024, GitHub took action to secure the NPM supply chain following a surge of sophisticated attacks exploiting weak authentication protocols and overly permissive access tokens. Adversaries—most notably those deploying the Shai-Hulud malware—compromised developer or maintainer accounts, then published malicious NPM packages, creating a vector for large-scale supply chain infection. The breaches risked both open-source and enterprise users, potentially allowing attackers access to downstream projects, credential leakage, and further lateral movement in corporate ecosystems. This incident is a critical reminder that software supply chains are increasingly targeted by cybercriminals using stolen credentials and token abuse. It highlights how even trusted platforms can expose organizations to risk when security controls such as MFA and token lifecycles are insufficiently enforced.
6 months ago
Kill Chain
UNC6148 Installs OVERSTEP Backdoor in SonicWall SMA Devices: 2024 APT Breach Analysis
In early 2024, a sophisticated threat actor group identified as UNC6148 targeted SonicWall Secure Mobile Access (SMA) appliances with a newly discovered backdoor malware named 'OVERSTEP'. By exploiting unpatched vulnerabilities, attackers gained unauthorized access, deployed persistent hidden software, exfiltrated credentials, and established remote control over affected devices. The compromise allowed lateral movement within victim networks, providing attackers with ongoing access to sensitive data and resources while evading detection for extended periods. Organizations using SonicWall SMA were particularly at risk of operational disruptions, data breaches, and unauthorized exposure of business-critical systems. This incident exemplifies the growing trend of supply-chain and edge-device attacks by advanced persistent threats (APTs). The deployment of stealthy backdoors like OVERSTEP signals increased sophistication and automation among threat actors, further pressuring organizations to improve detection, patch management, and east-west segmentation strategies.
6 months ago
Kill Chain
GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul
In August and September 2025, GitHub's npm ecosystem suffered a series of coordinated supply chain attacks involving high-impact campaigns such as "s1ngularity," "GhostAction," and worm-style "Shai-Hulud." Threat actors infiltrated GitHub repositories and npm packages via credential compromise and weaknesses in access controls, ultimately compromising thousands of developer accounts and private repositories. These attacks resulted in theft of sensitive code and data, disruption across open-source ecosystems, and considerable remediation costs for affected organizations. In response, GitHub has announced the rapid rollout of mandatory two-factor authentication, granular access tokens, and removal of insecure authentication methods for npm publishing, aiming to prevent recurrence and empower developers to proactively enhance their security posture. This wave of supply chain attacks underscores the growing risk of software dependency manipulation at scale. The incident highlights the urgency of hardening access controls, enforcing stronger authentication, and shifting developer communities toward zero trust principles to counteract increasingly sophisticated threats facing software ecosystems.
6 months ago
Kill Chain
UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025
In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations. The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.
6 months ago
Kill Chain
SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025
In September 2025, SolarWinds disclosed a critical security vulnerability (CVE-2025-26399) in its Web Help Desk (WHD) software, affecting version 12.8.7 and prior. This flaw—stemming from unsafe deserialization in the AjaxProxy component—permits unauthenticated attackers to achieve remote code execution (RCE) on affected servers. The issue represents a patch bypass for earlier vulnerabilities (CVE-2024-28986, CVE-2024-28988), demonstrating persistent weaknesses in the remediation process. While there are no documented exploitations as of publication, previous flaws in this component were added to CISA’s Known Exploited Vulnerabilities catalog, underscoring risk to organizations reliant on WHD for ticketing and IT asset management. This incident underscores the enduring challenge of patch bypasses, where subsequent hotfixes fail to fully resolve underlying flaws, leading to repeated exposures. Weaknesses in serialization logic and high-value IT management software are a favored target for attackers seeking lateral movement, privilege escalation, or supply chain compromise.
6 months ago
Kill Chain
State-Sponsored Command Injection Breach Targets Libraesva ESG in 2025
In September 2025, Libraesva, a widely used email security gateway provider, identified and patched a medium-severity vulnerability, CVE-2025-59689, actively exploited by a state-sponsored threat actor. The flaw involved improper sanitization in the handling of compressed email attachments, allowing attackers to execute arbitrary shell commands from non-privileged user accounts. The exploit targeted a specific appliance, highlighting both the technical skill and tactical precision of the attacker. Libraesva’s emergency fix was deployed within 17 hours to cloud and on-premise environments, and an automated scan for indicators of compromise was also released. Organizations running unsupported product versions must upgrade manually to remain protected. This incident exemplifies the growing sophistication and focus of state-linked adversaries exploiting command injection flaws in trusted security layers like email gateways. As supply-chain and infrastructure-focused attacks increase across sectors, organizations face mounting regulatory and operational pressure to maintain up-to-date security and swift response mechanisms.
6 months ago
Kill Chain
ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks
In September 2025, researchers uncovered that the ShadowV2 botnet exploited misconfigured Docker containers deployed on Amazon Web Services (AWS) instances. Attackers leveraged these open containers to install Go-based malware, transforming vulnerable cloud servers into nodes for distributed denial-of-service (DDoS) attacks available for hire. The botnet operators were able to saturate targets’ networks and disrupt organizational operations using cloud-scale resources, highlighting a sophisticated abuse of both infrastructure-as-a-service offerings and container orchestration weaknesses. The campaign predominantly impacted organizations with unmanaged or lax security practices around containerized workloads and cloud network borders. This attack underscores the growing trend of threat actors targeting cloud misconfigurations and using them as platforms for broader cybercriminal infrastructure. The incident reflects both the increasing commoditization of DDoS-as-a-service and the urgency of securing cloud-native deployments against well-known attack patterns.
6 months ago
Kill Chain
GitHub Mandates 2FA and Short-Lived Tokens After npm Supply Chain Attack
In September 2025, GitHub responded to a series of sophisticated supply chain attacks targeting the npm package ecosystem, most notably the Shai-Hulud compromise. Adversaries exploited weak authentication mechanisms and abused publishing tokens to inject self-replicating malware into widely used npm libraries. These malicious packages were automatically distributed downstream to thousands of unsuspecting development workflows, putting the integrity of software supply chains at risk. The attacks prompted GitHub to mandate two-factor authentication (2FA) for all npm publishers and to introduce short-lived authentication tokens to substantially reduce exposure to token theft. This incident underscores the growing trend of attackers targeting developer ecosystems as entry points for widespread compromise. The enhanced security controls by GitHub reflect a broader industry movement to harden software supply chains amid intensifying regulatory scrutiny and increasingly sophisticated attack methods.
6 months ago
Kill Chain
SolarWinds 2025 RCE Flaw: What CVE-2025-26399 Means for Enterprise Security
In September 2025, SolarWinds disclosed a critical vulnerability (CVE-2025-26399, CVSS 9.8) in its Web Help Desk software, allowing remote code execution via deserialization of untrusted data. Attackers could exploit this flaw to execute arbitrary commands on affected systems, potentially leading to full compromise of customer environments. SolarWinds released urgent hotfixes to address the flaw after it was identified during routine security testing, emphasizing the risk to organizations running unpatched instances exposed to the internet. This incident underscores the persistent threat posed by software supply chain vulnerabilities and insecure coding practices in widely used IT management platforms. With high-profile supply chain attacks on the rise, rapid vulnerability disclosure and patching are now critical to minimizing both direct exploitation and regulatory exposure.
6 months ago
Kill Chain
Supermicro BMC Supply-Chain Bugs Reveal Firmware Trust Weaknesses in 2025
In September 2025, researchers unveiled two medium-severity vulnerabilities affecting Supermicro's Baseboard Management Controller (BMC) firmware. Attackers could leverage improper cryptographic signature validation to bypass root-of-trust controls, allowing the deployment of malicious firmware images through supply-chain vectors. The flaws enable an adversary to compromise hardware integrity, potentially resulting in persistent access, data exfiltration, and disruption within enterprise server environments. Supermicro promptly released firmware updates and provided mitigation guidance as exploitation risks became public. This incident reflects an unsettling rise in supply-chain attacks targeting device firmware and hardware trust anchors. It underscores both the growing sophistication of attacker techniques and the criticality of maintaining robust verification, anomaly detection, and real-time firmware integrity validation for modern IT infrastructure.
6 months ago
Kill Chain
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports