Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2615 threat reports
Page 209 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 24972508 / 2615 reports
Microsoft Entra ID Flaw Exposed: How One Vulnerability Enabled Global Admin Impersonation
Impact· low

Microsoft Entra ID Flaw Exposed: How One Vulnerability Enabled Global Admin Impersonation

In September 2025, Microsoft disclosed a severe security flaw (CVE-2025-55241) affecting its Entra ID (formerly Azure Active Directory) service. The vulnerability, which received a maximum CVSS score of 10.0, allowed threat actors to bypass token validation and impersonate any user—including Global Administrators—across any tenant. Successful exploitation could grant attackers unrestricted access to sensitive data and resources within affected organizations, making this a high-impact privilege escalation incident. Microsoft responded swiftly, issuing a critical patch to contain the risk and urging immediate customer action. This incident highlights the ongoing trend of identity-based attacks against cloud platforms, emphasizing the necessity of robust access controls and vigilant monitoring. The discovery reinforces the risks of SaaS/IDaaS privilege escalation, as attackers increasingly target provider-side weaknesses to achieve large-scale compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Multi-Vector Cyberattack 2025: AI, Chrome 0-Day, DDR5 and npm Supply Chain Breach
Impact· medium

Multi-Vector Cyberattack 2025: AI, Chrome 0-Day, DDR5 and npm Supply Chain Breach

In September 2025, a multifaceted wave of cyber threats was observed, including a Chrome zero-day exploit, AI-generated hacking toolkits, active exposure of DDR5 memory vulnerability (Rowhammer-based bit-flip attacks), and a virulent npm worm targeting the software supply chain. Attackers leveraged 0-day browser exploits to execute malicious code, engineered advanced AI tools for automation, and deployed the npm worm to laterally move via package dependencies. The surge in attack sophistication resulted in unauthorized access, rapid lateral movement, and significant operational disruption for developers and enterprises globally. This incident underscores an urgent pivot in attacker tactics—combining classic and novel vulnerabilities across infrastructure, code, and memory. The simultaneous exploitation of multiple vectors signals a broader trend of adaptive threat landscapes, increasing regulatory scrutiny, and the need for rapid detection, cross-layer visibility, and agile patching cycles.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Microsoft Entra ID Flaw Put Every Cloud Tenant at Risk in 2024
Impact· medium

Critical Microsoft Entra ID Flaw Put Every Cloud Tenant at Risk in 2024

In early 2024, cybersecurity researchers uncovered a critical authentication flaw affecting Microsoft Entra ID (formerly Azure Active Directory), potentially enabling attackers to hijack any company's Entra ID tenant worldwide. By exploiting legacy identity features in combination with certain misconfigurations, attackers could bypass authentication controls and gain unauthorized administrative access, allowing full control over organizational resources in the affected tenants. Prompt discovery and responsible disclosure to Microsoft helped prevent active exploitation, though the underlying issue raised significant concern across the enterprise cloud ecosystem. This incident underscores the urgent need for organizations to continuously review legacy configurations, monitor identity security posture, and respond proactively to new classes of authentication bypass risks. With identity-based attacks rising across sectors, cloud environments are particularly vulnerable, highlighting zero trust best practices and ongoing vigilance as regulatory and threat environments evolve.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025 Picus Blue Report: Why Ransomware Still Evades Defenses
Impact· high

2025 Picus Blue Report: Why Ransomware Still Evades Defenses

In early 2025, the Picus Blue Report identified a concerning trend in global ransomware attacks: despite widespread awareness of ransomware tactics, organizations failed to prevent over a third of attack attempts, with prevention rates plummeting to 62%. Far more alarming, only 3% of simulated data exfiltration attempts were effectively blocked, exposing substantial gaps in data security frameworks. Attackers leveraged a blend of known and emerging ransomware variants to infiltrate networks, bypassing traditional and next-gen defenses by exploiting east-west traffic and insufficient segmentation. This led to successful encryption and large-scale data theft, disrupting business continuity for multiple sectors globally. This incident underscores a broader industry challenge: as ransomware evolves, so do the techniques for bypassing established defenses. The drastic fall in exfiltration prevention highlights an urgent need for modernized controls, especially with the regulatory and reputational stakes of breaches rising sharply in 2025.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fortra GoAnywhere MFT 2024: License Servlet Zero-Day Exposes File Transfer Infrastructure
Impact· medium

Fortra GoAnywhere MFT 2024: License Servlet Zero-Day Exposes File Transfer Infrastructure

In June 2024, Fortra disclosed a critical vulnerability (CVE-2024-XXXX) in its GoAnywhere Managed File Transfer (MFT) product’s License Servlet, enabling unauthenticated attackers to execute system commands remotely via command injection. Researchers discovered that by submitting crafted requests to the vulnerable servlet, attackers could gain full control of affected servers. No authentication was required, significantly increasing the risk of exploitation. Fortra released immediate security updates and guidance after reports of active exploitation attempts surfaced. Impacted organizations primarily included enterprises leveraging GoAnywhere MFT for secure file transfers, resulting in heightened risk of data exfiltration and business disruption. This incident underscores the ongoing importance of timely patch management, especially for widely used secure transfer solutions. The vulnerability’s ease of exploitation and criticality reflects trends of attackers targeting third-party file transfer products—often for extortion or ransomware campaigns—prompting renewed regulatory and industry scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Inside the Ivanti EPMM 2025 Breach: How China-Linked APTs Exploited Zero-Day Flaws
Impact· low

Inside the Ivanti EPMM 2025 Breach: How China-Linked APTs Exploited Zero-Day Flaws

In May 2025, advanced threat actors exploited two zero-day vulnerabilities (CVE-2025-4427 and CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM), targeting on-premise deployments. Attackers used an authentication bypass and code injection to deliver modular malware kits via crafted API requests, enabling them to gain initial access, perform reconnaissance, harvest credentials, and establish persistence within target environments. While Ivanti released patches shortly after discovery, the exploits were reportedly active before disclosure, affecting a limited set of organizations—primarily through an advanced persistent threat (APT) operation attributed by third-party researchers to a China-nexus espionage group. This incident underscores the growing trend of sophisticated supply chain and zero-day attacks on enterprise mobile device management (MDM) platforms, which are increasingly treated as high-value assets due to their access to sensitive business operations. Organizations must remain vigilant by prioritizing comprehensive patch management and strengthening internal traffic monitoring to mitigate similar risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
ShadowLeak: Zero-Click OpenAI ChatGPT Bug Exposes Gmail Data in 2025
Impact· high

ShadowLeak: Zero-Click OpenAI ChatGPT Bug Exposes Gmail Data in 2025

In June 2025, a critical zero-click vulnerability, codenamed ShadowLeak, was discovered in OpenAI ChatGPT’s Deep Research agent. This flaw enabled attackers to exfiltrate sensitive Gmail inbox content merely by sending a specially crafted email to victims using the agent, requiring no user action. Security researchers from Radware, after identifying the issue, disclosed it responsibly to OpenAI, which released a fix in early August 2025. The flaw had the potential to compromise confidential data across enterprise and personal Gmail accounts, raising major concerns around AI-driven integrations and email ecosystem security. This breach highlights the accelerating convergence of artificial intelligence with traditional email attack surfaces, raising unique risks around invisible, automated threat vectors. With GenAI agents increasingly embedded into communication flows, attackers are rapidly adapting zero-click tactics to exploit new behaviors and trust assumptions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks
Impact· high

MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks

In September 2025, SentinelOne’s SentinelLABS revealed the existence of 'MalTerminal,' the first documented malware leveraging GPT-4-powered Large Language Model (LLM) capabilities. Demonstrated at LABScon 2025, MalTerminal introduces LLM-driven automation within the malware lifecycle—enabling it to generate ransomware payloads, establish reverse shells, and craft social engineering content in real time. The attack method shows that malware authors are blending AI models directly into code to rapidly escalate privilege, automate lateral movement, and obfuscate command-and-control traffic. Business impact includes advanced, adaptive attacks that defeat legacy detection, heightening risks of data exfiltration, extended dwell time, and operational disruption. MalTerminal’s emergence is a bellwether for the rapid weaponization of generative AI technology by threat actors. This incident highlights the urgent need for organizations to re-evaluate traditional controls and accelerate adoption of cognitive security, visibility, and real-time policy enforcement frameworks to keep pace with evolving adversary techniques.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How 'ShadowLeak' Turned ChatGPT into a Data Exfiltration Channel
Impact· high

How 'ShadowLeak' Turned ChatGPT into a Data Exfiltration Channel

In mid-2024, security researchers uncovered a novel cyberattack—dubbed 'ShadowLeak'—that exploits OpenAI’s ChatGPT platform to surreptitiously exfiltrate emails and sensitive enterprise data. Threat actors leveraged covert techniques to route data through OpenAI’s infrastructure, effectively bypassing traditional network security controls and leaving virtually no forensic traces within the victim organization. The attack exploits the trusted status of sanctioned AI platforms inside corporate environments, making malicious exfiltration activity blend in with legitimate AI-assisted workflow traffic. As a result, internal monitoring and traditional DLP tools fail to identify or intercept the breach, putting confidential business communications and data at risk. This incident spotlights the growing risk posed by increasingly sophisticated methods of data exfiltration over legitimate AI services. With organizations accelerating the adoption of generative AI in critical business processes, attackers are exploiting technical and policy blind spots, making traditional perimeter defenses inadequate against such stealthy insider threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Fortra GoAnywhere 2025 Vulnerability Enables Command Injection Attacks
Impact· medium

Critical Fortra GoAnywhere 2025 Vulnerability Enables Command Injection Attacks

In early June 2025, Fortra disclosed a critical command injection vulnerability (CVE-2025-10035) in its GoAnywhere managed file transfer (MFT) solution. The flaw could be exploited by unauthenticated attackers if the management interface was exposed to the Internet, allowing remote code execution and potential takeover of affected servers. Fortra warned that active exploitation had been observed, and threat actors were leveraging the vulnerability to move laterally within compromised networks and facilitate data exfiltration. The incident affected a broad range of organizations reliant on GoAnywhere for secure file transfers, raising concerns about operational continuity and potential data exposure. The attack underscores the ongoing risk posed by internet-exposed enterprise services and highlights the urgent need for timely patching of high-severity vulnerabilities. Increasingly, ransomware and data theft campaigns are targeting known security flaws in widely-used third-party solutions, putting supply chains and regulatory compliance at risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Supercharges Ransomware: SMBs Face New Extortion Tactics in 2024
Impact· high

AI Supercharges Ransomware: SMBs Face New Extortion Tactics in 2024

In early 2024, small and medium-sized businesses (SMBs) experienced a significant surge in ransomware attacks, with threat actors leveraging AI-driven tools to automate reconnaissance, exploit vulnerabilities, and escalate extortion tactics. Attackers typically gained initial access through phishing emails, credential compromise from infostealer malware, or unpatched systems, then deployed dual-pronged ransomware campaigns involving both data encryption and data theft for double extortion. These incidents were characterized by rapidly evolving tactics, including deployment of 'EDR killer' malware to neutralize security controls and the emergence of AI-powered ransomware strains like PromptLock, further complicating incident recovery. Businesses reported severe operational disruptions, permanent data loss, and in some cases, closure due to the financial and reputational fallout. The proliferation of ransomware-as-a-service (RaaS), combined with AI-enabled attack chains, has dramatically widened the threat landscape for SMBs—who account for nearly 9 in 10 ransomware breaches. The current wave highlights the urgent need for organizations of all sizes to revisit their defensive posture, ensure visibility, and adopt zero trust and modern detection solutions to mitigate evolving risks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GoAnywhere 2025: Maximum-Severity Vulnerability Spurs Ransomware Fears Globally
Impact· high

GoAnywhere 2025: Maximum-Severity Vulnerability Spurs Ransomware Fears Globally

In September 2025, a critical vulnerability (CVE-2025-10035) was disclosed in Fortra's GoAnywhere Managed File Transfer (MFT) service, exposing over 3,000 organizations, including major Fortune 500 companies, to significant risk. The flaw, a maximum-severity deserialization bug requiring no authentication, allows remote attackers to gain unauthorized code execution by leveraging a crafted license response signature. While no exploitation was detected at the time of disclosure, researchers warn that ransomware groups—such as Clop, known for previously targeting file-transfer software—are likely to attempt mass exploitation based on past patterns and the high impact of this vulnerability. If exploited, this flaw could result in widespread data theft, business disruption, and regulatory penalties. This incident is especially important as it mirrors techniques used in highly publicized attacks on file-transfer applications, highlighting increased sophistication and urgency among ransomware operators. The ongoing evolution of such vulnerabilities amplifies the threat to critical data flows and underscores rising compliance and zero trust enforcement needs across enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports