The Containment Era is here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2550 threat reports
Page 21 of 213

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 241252 / 2550 reports
Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited
Impact· HIGH

Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited

In May 2026, Microsoft disclosed CVE-2026-45659, a critical remote code execution vulnerability in SharePoint Server caused by deserialization of untrusted data. This flaw allows authenticated attackers with minimal permissions to execute arbitrary code over a network, potentially compromising sensitive data and system integrity. Despite the release of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, 2026, indicating active exploitation in the wild. The inclusion of CVE-2026-45659 in CISA's catalog underscores the urgency for organizations to apply the available patches promptly. The vulnerability's low attack complexity and the widespread use of SharePoint in enterprise environments heighten the risk of exploitation, emphasizing the need for immediate remediation to protect organizational assets.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ToddyCat's Umbrij Malware: A New Threat to Gmail Security
Impact· HIGH

ToddyCat's Umbrij Malware: A New Threat to Gmail Security

In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods. The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security
Impact· CRITICAL

Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security

In July 2026, Trail of Bits, in collaboration with OpenAI, launched 'Patch the Planet,' an initiative leveraging GPT-5.5-Cyber to enhance the security of over 30 open-source projects. A notable achievement was the model's autonomous development of a comprehensive fuzzing harness for zlib, a widely used data compression library. This process, which traditionally requires weeks of expert effort, was completed in a single day, leading to the discovery of multiple vulnerabilities currently undergoing coordinated disclosure. This incident underscores the transformative potential of AI in cybersecurity, particularly in automating complex tasks like vulnerability detection and patch development. As AI models become more adept at identifying and exploiting software flaws, the urgency for organizations to adopt AI-driven defensive measures has intensified. The 'Patch the Planet' initiative exemplifies proactive collaboration between AI developers and security experts to stay ahead of emerging threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Urgent Alert: Active Exploitation of Oracle EBS CVE-2026-46817
Impact· CRITICAL

Urgent Alert: Active Exploitation of Oracle EBS CVE-2026-46817

In late June 2026, threat intelligence firm Defused detected active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle's E-Business Suite (EBS) Payments module. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers to execute arbitrary code via HTTP, potentially leading to full system compromise. The initial exploit attempts were observed on June 27, 2026, targeting the 'ibytransmit' endpoint to read sensitive files from the server. Oracle had released a patch for this vulnerability in May 2026, but the recent attacks indicate that many systems remain unpatched and vulnerable. This incident underscores the persistent threat posed by unpatched critical vulnerabilities in widely used enterprise applications. Organizations relying on Oracle EBS must prioritize applying security updates promptly to mitigate risks. The exploitation of CVE-2026-46817 highlights the need for continuous monitoring and proactive defense strategies to protect against emerging threats targeting enterprise resource planning (ERP) systems.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
Impact· CRITICAL

Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities

In July 2026, Adobe released critical security patches addressing seven maximum-severity vulnerabilities in its ColdFusion and Campaign Classic platforms. These flaws, identified as CVE-2026-48276 through CVE-2026-48282 and CVE-2026-48286, could allow unauthenticated attackers to execute arbitrary code on unpatched systems without user interaction. Affected versions include ColdFusion 2025.9, 2023.20, and earlier, as well as Campaign Classic 7.4.3 build 9396 and earlier. Adobe has urged administrators to apply these updates within 72 hours to mitigate potential exploitation risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/?utm_source=openai)) This incident underscores the increasing frequency and severity of vulnerabilities in widely-used enterprise software, highlighting the critical need for organizations to maintain rigorous patch management practices. The rapid identification and remediation of such flaws are essential to safeguard systems against potential exploits that could lead to significant operational disruptions and data breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Over 900 Oracle E-Business Instances Exposed to Ongoing Attacks
Impact· CRITICAL

Over 900 Oracle E-Business Instances Exposed to Ongoing Attacks

In late June 2026, over 900 Oracle E-Business Suite (EBS) instances were found exposed online, with active exploitation of a critical vulnerability (CVE-2026-46817) in the Oracle Payments component. This flaw allows unauthenticated attackers with HTTP access to take over vulnerable systems. Oracle released a patch in May 2026, but many systems remain unpatched, leading to successful attacks. The ongoing exploitation of CVE-2026-46817 underscores the persistent threat posed by unpatched enterprise systems. Organizations must prioritize timely application of security updates to mitigate risks associated with such vulnerabilities.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Credential-Stuffing Attack Targets Microsoft 365 Accounts
Impact· HIGH

Massive Credential-Stuffing Attack Targets Microsoft 365 Accounts

Between June 12 and 26, 2026, a sophisticated password-spraying attack targeted Microsoft 365 environments, resulting in over 81 million login attempts. The attackers utilized the Azure Command-Line Interface (CLI) to exploit valid username and password combinations from previous breaches. By leveraging the Resource Owner Password Credentials (ROPC) OAuth mechanism, they bypassed multi-factor authentication (MFA) in numerous organizations due to misconfigured Conditional Access policies. This campaign led to the compromise of 78 Microsoft accounts across 64 organizations. This incident underscores the critical need for organizations to review and strengthen their MFA configurations and Conditional Access policies. The exploitation of ROPC highlights vulnerabilities in authentication flows that lack support for modern security measures, emphasizing the importance of comprehensive security assessments to prevent similar breaches.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FortiBleed Credential Theft Campaign Exposes Over 73,000 Fortinet Devices
Impact· CRITICAL

FortiBleed Credential Theft Campaign Exposes Over 73,000 Fortinet Devices

In July 2026, the 'FortiBleed' campaign was uncovered, revealing a massive credential theft operation targeting over 73,000 Fortinet devices. Attackers utilized a custom tool named 'FortiGate Sniffer' to intercept VPN credentials directly from network traffic. Subsequent investigations linked this operation to the INC and Lynx ransomware groups, indicating that the stolen credentials were intended to facilitate future network intrusions. This incident underscores the evolving tactics of ransomware groups, highlighting their focus on exploiting network infrastructure vulnerabilities to gain unauthorized access. Organizations must prioritize securing their network devices and monitoring for unusual activities to mitigate such threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ScreenConnect Exploited in Global AsyncRAT Campaign - 2026
Impact· HIGH

ScreenConnect Exploited in Global AsyncRAT Campaign - 2026

In early 2026, a sophisticated cyber campaign exploited legitimate remote access tools to deploy AsyncRAT malware. Attackers created fraudulent websites mimicking popular software like OBS Studio and DNS Jumper, leveraging search engine optimization to rank these sites highly. Unsuspecting users downloaded trojanized installers containing a legitimate Microsoft-signed binary and a malicious DLL, which installed ScreenConnect for remote access. This access was used to execute scripts that disabled security features and deployed AsyncRAT, enabling data theft and system control. The campaign's extensive infrastructure spanned over 90 domains in multiple languages, indicating a global reach. This incident underscores the evolving tactics of cybercriminals who exploit trusted tools and SEO techniques to infiltrate systems. Organizations must remain vigilant, ensuring software is downloaded from verified sources and implementing robust security measures to detect and prevent such sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ClawHavoc: Unveiling the OpenClaw Supply Chain Attack
Impact· HIGH

ClawHavoc: Unveiling the OpenClaw Supply Chain Attack

In early 2026, the OpenClaw AI assistant ecosystem faced a significant supply chain attack known as 'ClawHavoc.' Threat actors uploaded over 1,100 malicious 'skills' to ClawHub, OpenClaw's official marketplace, disguising them as legitimate productivity tools. These malicious skills, once installed, deployed various malware, including the Atomic macOS Stealer (AMOS), compromising user credentials, cryptocurrency wallets, and sensitive documents. The attack exploited the trust users placed in ClawHub's skill repository, leading to widespread data breaches and system compromises. This incident underscores the evolving threat landscape targeting AI agent ecosystems. The ease of creating and distributing malicious skills highlights the urgent need for robust security measures, including stringent code audits, supply chain verification practices, and user education on the risks associated with third-party extensions.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
VEIL#DROP Malware Exploits Blogger to Deliver PureLogs Stealer
Impact· HIGH

VEIL#DROP Malware Exploits Blogger to Deliver PureLogs Stealer

In July 2026, cybersecurity researchers identified a sophisticated malware delivery framework named VEIL#DROP, which exploits Google's Blogger platform to disseminate the PureLogs information stealer. The attack initiates with a deceptive JavaScript file, often named to resemble a document (e.g., transcript.pdf.js), that executes via Windows Script Host. This script launches PowerShell commands to retrieve additional payloads from Blogger-hosted URLs, effectively bypassing traditional security defenses by leveraging trusted infrastructure. The infection chain culminates in the deployment of PureLogs, a .NET-based infostealer capable of harvesting a wide array of sensitive data from compromised systems. The VEIL#DROP framework employs advanced evasion techniques, including dynamic URL generation, runtime script mutation, and fileless execution, making detection and mitigation challenging. Additionally, it utilizes trusted Microsoft-signed binaries to execute malicious code, further enhancing its stealth and persistence within targeted environments. The emergence of VEIL#DROP underscores a growing trend among threat actors to abuse legitimate platforms and services to distribute malware, complicating detection efforts. This incident highlights the critical need for organizations to implement robust security measures, including advanced threat detection systems and comprehensive user education, to defend against increasingly sophisticated attack vectors.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cybercriminals Exploit SEO and Legitimate Tools to Deploy AsyncRAT
Impact· CRITICAL

Cybercriminals Exploit SEO and Legitimate Tools to Deploy AsyncRAT

In July 2026, cybersecurity researchers uncovered a large-scale campaign where threat actors utilized SEO poisoning to distribute malicious installer archives via spoofed websites. These installers, masquerading as popular software like OBS Studio and Bandicam, bundled a legitimate Microsoft install.exe binary with a rogue DLL, leading to the deployment of the ScreenConnect remote access tool. This tool facilitated the execution of AsyncRAT, enabling attackers to maintain control over compromised systems, steal sensitive data, and monitor user activity. The campaign spanned over 90 domain names across 10 languages, indicating a highly coordinated effort. ([thehackernews.com](https://thehackernews.com/2026/07/seo-poisoned-software-sites-abuse.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit legitimate tools and SEO techniques to enhance the reach and effectiveness of their attacks. The use of trusted software as a delivery mechanism for malware highlights the need for heightened vigilance and robust security measures to detect and prevent such sophisticated threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports