Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2615 threat reports
Page 212 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 25332544 / 2615 reports
SonicWall 2024 Breach: Cloud Portal Attack Exposes Firewall Configurations
Impact· medium

SonicWall 2024 Breach: Cloud Portal Attack Exposes Firewall Configurations

In June 2024, SonicWall confirmed a security incident impacting its MySonicWall.com portal, where threat actors gained unauthorized access to backup firewall configuration files belonging to fewer than 5% of their customers. The attackers employed targeted brute-force attacks to access encrypted preference files stored in the cloud, potentially exposing sensitive network architecture and policy information. While SonicWall promptly disabled the affected backup feature, notified law enforcement and affected customers, and engaged incident response specialists, the exposure raises substantial risk of follow-on attacks and exploitation due to the detailed nature of the data compromised. This incident highlights a growing concern with threats targeting cloud-managed administrative platforms, especially those operated by key infrastructure vendors. As attackers pivot from device exploits to systemic attacks on cloud portals, organizations must scrutinize cloud data storage and vendor security practices more rigorously to mitigate downstream and supply chain risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Seizes RaccoonO365: 2024’s Largest Phishing-as-a-Service Credential Theft Takedown
Impact· medium

Microsoft Seizes RaccoonO365: 2024’s Largest Phishing-as-a-Service Credential Theft Takedown

In July 2024, Microsoft’s Digital Crimes Unit, in collaboration with law enforcement and cybersecurity partners, led a takedown of RaccoonO365—a subscription-based phishing-as-a-service platform operated by the threat group Storm-2246. Over 338 domains linked to RaccoonO365 were seized after being used to steal more than 5,000 Microsoft credentials across 94 countries since July 2024. The group’s kits, leveraging sophisticated evasion techniques and authentic-looking Microsoft branding, enabled cybercriminals to mount tax-themed and healthcare-targeted phishing campaigns, with sessions often bypassing multifactor authentication to harvest both passwords and session cookies. The breadth and pace of RaccoonO365’s operations highlight the commoditization and professionalization of cybercrime. This incident signals a shift towards scalable, as-a-service attack tools, increasing risks to organizations globally. Security teams must rapidly adapt to evolving TTPs and plug new identity-driven attack pathways, especially as phishing toolkits grow in accessibility and sophistication.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CHILLYHELL and ZynorRAT: Cross-Platform RATs Evade Detection, Threaten Enterprise Environments (2025)
Impact· low

CHILLYHELL and ZynorRAT: Cross-Platform RATs Evade Detection, Threaten Enterprise Environments (2025)

In September 2025, security researchers from Jamf Threat Labs uncovered two sophisticated malware strains: CHILLYHELL, a modular backdoor targeting macOS systems, and ZynorRAT, a Go-based remote access trojan spreading across Windows and Linux environments. CHILLYHELL, written in C++ for Intel macOS architectures, enables persistent remote access and exfiltrates sensitive data, while ZynorRAT facilitates cross-platform attacks and lateral movement. Both threats leverage encrypted communications and modular payloads to evade detection and expand their reach, highlighting attackers’ increasing investment in multi-OS toolkits. The campaign impacted diverse sectors by undermining endpoint trust and exposing organizations to data breaches, extortion, and operational disruption. This incident reflects an ongoing surge in cross-platform malware development, with adversaries targeting heterogeneous enterprise environments using advanced, modular code. The discovery underscores heightened regulatory scrutiny around endpoint security, zero trust enforcement, and incident response as ransomware and espionage risks escalate.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Akira Ransomware Exploits SonicWall SSL VPN Flaw in 2025 – What You Need to Know
Impact· high

Akira Ransomware Exploits SonicWall SSL VPN Flaw in 2025 – What You Need to Know

In late July 2025, threat actors affiliated with the Akira ransomware group launched a wave of attacks by exploiting a vulnerability and misconfigurations in SonicWall SSL VPN appliances. Cybersecurity firm Rapid7 reported a notable surge in intrusions targeting these devices, leveraging unsecured remote access pathways for initial compromise. Once inside, attackers escalated privileges, moved laterally, and deployed ransomware to encrypt critical data, causing extensive operational disruptions for affected organizations. The attacks highlighted gaps in east-west traffic monitoring, segmentation, and visibility, leaving many networks vulnerable to rapid malware spread and data loss. This breach underscores ongoing ransomware innovation and the persistent targeting of networking appliances as low-hanging fruit for initial access. It also reveals the increasing urgency for organizations to enforce zero trust network segmentation, proactively patch perimeter devices, and continuously monitor for anomalous access to defend against evolving ransomware threats and regulatory scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
HybridPetya: Ransomware That Bypasses UEFI Secure Boot with CVE-2024-7344
Impact· high

HybridPetya: Ransomware That Bypasses UEFI Secure Boot with CVE-2024-7344

In September 2025, researchers at ESET identified a new ransomware variant named HybridPetya that combines destructive Petya/NotPetya traits with advanced UEFI attack capabilities. Leveraging the CVE-2024-7344 vulnerability, attackers were able to bypass UEFI Secure Boot, allowing the malware to execute at a privileged level prior to OS load. Initial infection vectors appear to include phishing emails and software supply-chain compromises, leading to widespread disruption of targeted organizations’ endpoints, encrypted data, and in some instances, bricked devices. The attack highlights a disturbing escalation in ransomware sophistication and targeting, with significant operational downtime and financial losses reported in affected sectors. HybridPetya represents an evolution in ransomware, merging firmware exploitation with traditional payload delivery to maximize impact. This incident underscores the expanding threat landscape as adversaries weaponize newly discovered vulnerabilities and aim higher up the trust chain, intensifying pressure on organizations to harden their endpoints and update defenses in real time.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Samsung’s 2025 Critical Mobile Zero-Day: CVE-2025-21043 Exploited in the Wild
Impact· medium

Samsung’s 2025 Critical Mobile Zero-Day: CVE-2025-21043 Exploited in the Wild

In September 2025, Samsung urgently patched a critical zero-day vulnerability (CVE-2025-21043) impacting its Android devices. The flaw, an out-of-bounds write in the libimagecodec.quram.so library, enabled remote attackers to execute arbitrary code on affected devices. This zero-day had been actively exploited in real-world attacks prior to disclosure and patch release, exposing millions of Galaxy smartphone users to the risk of compromise and potential data theft. Samsung responded by releasing its monthly security updates addressing the vulnerability before widespread exploitation could escalate. This incident underscores the persistent targeting of mobile platforms using advanced zero-day techniques, raising concerns for enterprises reliant on mobile endpoints. As threat actors innovate and focus on mobile ecosystems, rapid patch cycles and vigilant threat monitoring remain essential to protect against evolving exploitation methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FBI Alert: UNC6040 & UNC6395 Target Salesforce in Sophisticated Data Theft and Extortion Attack
Impact· medium

FBI Alert: UNC6040 & UNC6395 Target Salesforce in Sophisticated Data Theft and Extortion Attack

In mid-2025, the FBI issued a critical alert warning organizations about two cybercriminal groups, UNC6040 and UNC6395, conducting coordinated data theft and extortion attacks targeting enterprise Salesforce environments. Attackers leveraged multiple initial access vectors—believed to include credential compromise and social engineering—to infiltrate Salesforce platforms, exfiltrating sensitive data at scale. The breach campaigns led to severe business interruptions, reputational damage, and raised concerns over cloud infrastructure security, particularly in environments perceived as “well-defended.” FBI guidance included new indicators of compromise and proactive defense measures for cloud-hosted SaaS platforms. This incident marks a shift in threat actor focus toward high-value SaaS platforms, demonstrating the growing sophistication and persistence of financially-motivated attackers. It underscores the urgency for robust controls around identity, east-west traffic, and cloud-native visibility, as attack surfaces expand in digital-first enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Mass Browser-Based Attack Hits Enterprises: 2025’s Session Hijacking Wakeup Call
Impact· medium

Mass Browser-Based Attack Hits Enterprises: 2025’s Session Hijacking Wakeup Call

In August 2025, a sophisticated wave of browser-based attacks exploited vulnerabilities in popular browser components to hijack user sessions across multiple financial and technology firms simultaneously. Attackers leveraged phishing lures and malicious advertising to distribute payloads capable of intercepting authentication tokens and session cookies, enabling widespread unauthorized access. The campaign, attributed to a financially motivated eCrime group, enabled lateral movement within compromised cloud and SaaS applications, resulting in significant data exfiltration, temporary access loss, and incident-driven downtime for several affected organizations. This incident underscores a dramatic uptick in browser-native TTPs targeting identity, session integrity, and trusted cloud access. Threat actors are exploiting the growing reliance on web-based workflows and overlooked intra-browser security, making enhanced endpoint monitoring and Zero Trust controls more urgent than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Self-Replicating Worm Strikes npm: 2025 Supply Chain Attack Exposes Critical Credential Risks
Impact· high

Self-Replicating Worm Strikes npm: 2025 Supply Chain Attack Exposes Critical Credential Risks

In September 2025, a major supply chain attack targeted the npm ecosystem, compromising over 40 packages and impacting projects worldwide. Attackers utilized a self-replicating worm delivered via manipulated npm modules; these modules would download, alter, and republish themselves by embedding malicious scripts directly into package files. As a result, sensitive developer credentials and system access tokens were harvested at scale, putting thousands of developer environments and downstream applications at risk, eroding trust in open-source software supply chains. This campaign highlights the growing risk and sophistication of supply chain attacks leveraging automated propagation across trusted developer channels. With the expanding reliance on open-source components and increasing regulatory scrutiny, organizations must urgently strengthen controls around development pipelines and dependency security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Apple 2025 ImageIO Zero-Day Breach Highlights Spyware Risks
Impact· low

Apple 2025 ImageIO Zero-Day Breach Highlights Spyware Risks

In September 2025, Apple urgently released backported security updates to address CVE-2025-43300, a critical out-of-bounds write vulnerability in the ImageIO component exploited by advanced spyware campaigns. Attackers leveraged malicious image files to trigger memory corruption on Apple devices, enabling remote code execution and potential device takeover. The exploit was actively seen in targeted attacks against high-profile individuals, emphasizing the risk of spyware abusing zero-day vulnerabilities for persistent surveillance. The incident underscores the growing sophistication and frequency of attacks exploiting media processing flaws. This breach highlights an intensifying trend of threat actors using zero-day vulnerabilities in consumer devices for espionage. It demonstrates how attackers pivot to less-monitored device components and rapidly weaponize novel flaws, reinforcing the urgent need for continuous patching and proactive detection of anomalous behaviors on endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025
Impact· high

Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025

In September 2025, multiple critical vulnerabilities were discovered in Chaos Mesh, a popular cloud-native chaos engineering platform, exposing Kubernetes clusters to remote code execution (RCE) via unauthenticated GraphQL endpoints. Attackers with minimal in-cluster network access could exploit these flaws to execute arbitrary code, trigger disruptive fault injections (such as pod deletion and network outages), and ultimately achieve full cluster takeover. The vulnerability stemmed from insufficient access controls and improper GraphQL API handling, allowing adversaries to escalate privileges and compromise cluster workloads. As a result, organizations relying on Chaos Mesh in production faced heightened risk to workload integrity and business continuity until patches were applied. This breach highlights the increasing threat to supply-chain components in cloud-native environments, where tools with high privileges can inadvertently expose entire clusters. The rapid disclosure and fix cycle signals a need for strict RBAC, vigilant monitoring, and timely patching as attacker focus shifts towards exploiting platform-level risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)
Impact· medium

Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)

In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide. This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports