Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2615 threat reports
Page 211 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 25212532 / 2615 reports
Scattered Spider Strikes: 2024 Ransomware Attack on Transport for London Exposes Critical Gaps
Impact· high

Scattered Spider Strikes: 2024 Ransomware Attack on Transport for London Exposes Critical Gaps

In August 2024, Transport for London (TfL), a critical national infrastructure operator in the UK, suffered a significant ransomware attack attributed to the 'Scattered Spider' cybercrime collective. Law enforcement arrested two UK-based teenagers, believed to be key members of the group, after evidence tied them to not just the TfL breach but also a string of attacks targeting US healthcare and federal systems. The ransomware event caused extensive disruption to TfL’s internal and online systems, delayed refund processing, and ultimately led to a breach of customer data, including names, contact details, and addresses. Financial losses for TfL ran into the millions. This incident highlights both the growing capability and brazenness of young, English-speaking cybercriminals, as well as the expanding impact of ransomware on critical infrastructure and global enterprises. The subsequent law enforcement operation illustrates the increased regulatory scrutiny and international cooperation aimed at dismantling hacker collectives operating ransomware and extortion campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
RaccoonO365: Microsoft & Cloudflare Take Down Major Phishing-as-a-Service Network in 2024
Impact· medium

RaccoonO365: Microsoft & Cloudflare Take Down Major Phishing-as-a-Service Network in 2024

In July 2024, Microsoft, in collaboration with Cloudflare and law enforcement, disrupted the RaccoonO365 Phishing-as-a-Service (PhaaS) operation, which enabled cybercriminals to launch large-scale phishing campaigns mimicking Microsoft 365 and other trusted brands. The service, run by Storm-2246 and attributed to Joshua Ogundipe, offered subscription-based kits that automated credential-theft campaigns targeting over 2,300 US organizations and at least 20 healthcare entities. The takedown involved seizing 338 domains, mapping the attack infrastructure, and revealing financial flows in cryptocurrency, shutting down an operation responsible for stealing at least 5,000 sets of credentials from 94 countries. This incident underscores the industrialization of phishing through subscription-based platforms and highlights how low-skill attackers are being enabled at scale. As phishing-as-a-service proliferates and leverages brand impersonation, organizations face escalating risks of credential theft and downstream ransomware or malware attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Scattered Lapsus$ Hunters: Hacking Groups Go Dark, But Risks Remain
Impact· low

Scattered Lapsus$ Hunters: Hacking Groups Go Dark, But Risks Remain

In early 2024, the notorious Scattered Spider and Lapsus$ cybercriminal groups announced they were disbanding and ending their hacking campaigns, raising hopes of a reprieve from their disruptive cyberattacks. However, security researchers observed ongoing activity linked to these groups, including continued phishing, extortion, and data theft campaigns, suggesting the announcements may have been a smokescreen aimed at evading law enforcement scrutiny. The groups are known for high-profile intrusions into enterprise and technology organizations, frequently exploiting identity-based attacks and lateral movement to access sensitive data and systems, resulting in operational disruptions and significant data breaches. This incident highlights the persistent threat posed by organized cybercriminal groups that leverage identity-centric attack vectors and sophisticated social engineering, underscoring the necessity for robust segmentation, effective threat detection, and advanced access controls on corporate networks. Amid evolving attacker tactics and regulatory demands, organizations must prioritize zero trust strategies to defend against similar threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's September 2025 Patch: Critical Azure & SMB Vulnerabilities Fixed
Impact· medium

Microsoft's September 2025 Patch: Critical Azure & SMB Vulnerabilities Fixed

In September 2025, Microsoft released a critical security update addressing 80 vulnerabilities across its product suite, with particular focus on an SMB privilege escalation flaw and an Azure vulnerability rated CVSS 10.0. While eight of these vulnerabilities were classified as Critical and the rest as Important, none are reported to have been exploited in the wild at release. The patch release comes after public disclosures made some flaws widely known, elevating risk of exploitation. Microsoft urged organizations to immediately apply updates, highlighting the dangers posed by both privilege escalation and remote code execution vectors that could severely impact enterprise security. This incident underscores the continued rise in attacks targeting software supply chains and cloud platforms. With a surge in public disclosures and exploit tool availability, patch management has become both more challenging and more essential—particularly as attackers increasingly exploit unpatched vulnerabilities for lateral movement and privilege escalation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Chrome Zero-Day CVE-2025-10585: Exploit Puts Millions at Risk
Impact· low

Google Chrome Zero-Day CVE-2025-10585: Exploit Puts Millions at Risk

In September 2025, Google addressed a critical security incident involving a zero-day vulnerability (CVE-2025-10585) within Chrome's V8 JavaScript and WebAssembly engine. This type confusion vulnerability was actively exploited in the wild, allowing attackers to execute arbitrary code in users’ browsers. The exploit’s ease of deployment and ability to bypass conventional browser defenses put millions of Chrome users at risk globally until Google released an urgent patch. The attack vector enabled threat actors to compromise targeted endpoints primarily through malicious web content. This incident highlights the ongoing proliferation and rapid exploitation of browser-based zero-days. Continuous advancements in attacker tactics—and their ability to weaponize browser vulnerabilities at scale—underscore the necessity for organizations to implement proactive patch management and behavioral threat detection aligned with zero trust strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SilentSync RAT Supply Chain Attack on PyPI Exposes Python Developer Ecosystem
Impact· medium

SilentSync RAT Supply Chain Attack on PyPI Exposes Python Developer Ecosystem

In September 2025, cybersecurity researchers uncovered a sophisticated supply chain attack targeting Python developers through two malicious packages uploaded to the Python Package Index (PyPI) repository. These packages secretly deployed the SilentSync remote access trojan (RAT) onto Windows systems, enabling cybercriminals to execute remote commands, exfiltrate files, and capture screenshots from infected machines. The attackers leveraged trusted developer platforms to propagate their malware, increasing the risk of widespread compromise and posing a significant operational threat to organizations relying on open-source software dependencies. This incident highlights the ongoing risks associated with open-source ecosystems and third-party package repositories, which have become prime targets for threat actors. The escalation in supply chain attacks underscores the need for robust software supply chain security, vigilant dependency monitoring, and stronger policies governing the use of third-party code.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
SonicWall Cloud Backup Breach: Firewall Configurations Compromised, Credential Resets Urged
Impact· high

SonicWall Cloud Backup Breach: Firewall Configurations Compromised, Credential Resets Urged

In September 2025, SonicWall disclosed a cloud security incident that exposed firewall configuration backup files tied to less than 5% of MySonicWall accounts, prompting a company-wide advisory to reset credentials for impacted users. The breach involved unauthorized access to backup firewall preference files hosted in SonicWall’s cloud backup service, which could potentially allow attackers insight into sensitive network policies and infrastructure details. Upon detection, SonicWall revoked affected credentials, reset authentication tokens, and notified regulatory authorities and end-users. The incident underscores operational risks associated with cloud-based configuration repositories and the downstream consequences for enterprise security posture. This breach highlights ongoing attacker focus on cloud storage services and device configuration files, which are increasingly targeted for initial access or lateral movement. As regulatory scrutiny grows and advanced threats seek out persistent footholds, organizations face mounting urgency to harden cloud storage, segment sensitive data, and enforce continuous credential hygiene.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CountLoader: The Russian Ransomware Loader Redefining Post-Exploitation in 2025
Impact· high

CountLoader: The Russian Ransomware Loader Redefining Post-Exploitation in 2025

In September 2025, cybersecurity researchers uncovered a major campaign involving CountLoader, a newly identified malware loader leveraged by Russian ransomware gangs. CountLoader has been deployed to infiltrate organizations by delivering post-exploitation tools such as Cobalt Strike, AdaptixC2, and the PureHVNC RAT via sophisticated phishing and initial access broker (IAB) operations. Notably, the loader is associated with affiliates of the LockBit ransomware group and is suspected to support both initial access sales and direct ransomware attacks. The campaign enabled attackers to establish stealthy persistence and remote control over compromised environments, amplifying threats of data theft, lateral movement, and disruptive encryption attacks. This incident highlights the growing adoption of multi-stage loader malware by established ransomware actors, blending traditional and cutting-edge post-exploitation tools for maximum impact. The tactics seen here illustrate the evolving, service-based ransomware ecosystem—one where payload delivery, access brokering, and command-and-control capabilities are modular and rapidly evolving in response to network defenses.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
GhostRedirector Backdoors Windows Servers with Malicious IIS Modules
Impact· medium

GhostRedirector Backdoors Windows Servers with Malicious IIS Modules

In early 2024, ESET researchers uncovered a sophisticated cyber campaign known as GhostRedirector targeting Windows servers worldwide. The attacker employed a passive C++ backdoor and a malicious Microsoft IIS module, granting remote control and enabling the manipulation of Google search results. By compromising internet-facing IIS web servers, the threat actor covertly redirected visitors to malicious domains while maintaining persistent access through undetected, stealthy backdoors. The attack had the potential to facilitate broad influence operations, data exfiltration, and further deployment of malware on compromised networks. This incident highlights the growing risk of advanced web server threats utilizing legitimate application modules for stealthy persistence. Such tactics reflect a wider trend of attackers exploiting trusted infrastructure and automated SEO poisoning, challenging organizations to strengthen threat detection, zero trust controls, and incident response.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024
Impact· high

HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024

In June 2024, ESET researchers discovered a ransomware variant dubbed HybridPetya, modeled after the infamous Petya/NotPetya malware, with a significant escalation in its capabilities. HybridPetya leverages the CVE-2024-7344 vulnerability to compromise UEFI-based systems, effectively bypassing Secure Boot protections on outdated hardware. Although not known to be active in broad campaigns, this bootkit joins a small group of malware capable of undermining the fundamental trust mechanisms securing modern machines, representing a sophisticated evolution in ransomware delivery and persistence techniques. HybridPetya’s emergence highlights the rapid adaptation of cybercriminals to harden malware against defensive controls. UEFI bootkit methods—once advanced nation-state territory—are now appearing in ransomware. Organizations must urgently review endpoint protections, hardware patching, and secure boot configurations to lower exposure to these new attack paths.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
HybridPetya Ransomware: UEFI Secure Boot Bypass Proof-of-Concept Shakes Firmware Security
Impact· high

HybridPetya Ransomware: UEFI Secure Boot Bypass Proof-of-Concept Shakes Firmware Security

In July 2025, ESET Research uncovered HybridPetya, a proof-of-concept ransomware closely mimicking the destructive Petya and NotPetya malware. HybridPetya features a novel UEFI bootkit component, capable of targeting both legacy and modern UEFI-based systems by exploiting CVE-2024-7344 to bypass Secure Boot protections. The malware operates by encrypting the Master File Table on NTFS partitions, leveraging advanced techniques such as malicious EFI application deployment and fake CHKDSK screens to evade detection. To date, ESET’s telemetry has found no evidence of HybridPetya in active attacks, and its development suggests an evolving threat landscape for ransomware targeting core system components. HybridPetya’s public discovery underscores an alarming trend: sophisticated ransomware is expanding its reach to firmware and boot processes, previously considered resilient to commodity malware. The rise of UEFI-targeting threats and Secure Boot bypass exploits highlights the urgent need for rigorous patch management and endpoint visibility, especially as new vulnerabilities (like CVE-2024-7344) become weaponized.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Apple Patches 100+ Vulnerabilities in 2025: What Enterprises Need to Know
Impact· low

Apple Patches 100+ Vulnerabilities in 2025: What Enterprises Need to Know

In September 2025, Apple released security updates for iPhones, iPads, Macs, and other products, addressing a total of over 100 vulnerabilities across its ecosystem. While none of the patched vulnerabilities were reported as actively exploited at the time, two severe macOS bugs (CVE-2025-43298 and CVE-2025-43304) were highlighted for their potential to confer root privileges to attackers. The updates followed a year marked by several Apple zero-days, some previously exploited in highly targeted attacks, underscoring ongoing risks to user data and privacy. Devices released prior to 2019 are no longer supported by the latest OS versions, leaving older hardware at higher risk. This incident highlights the persistent and evolving nature of software vulnerabilities targeting consumer platforms, reinforcing the critical importance of timely patching. With increasing regulatory attention and attackers swiftly weaponizing new bugs, organizations must remain vigilant in threat monitoring and adopt robust patch management practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports