✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Microsoft 2025 Zero-Day Patch Tuesday: SMB & SQL Server Vulnerabilities Fixed
In September 2025, Microsoft addressed 81 security flaws in its monthly Patch Tuesday, including two significant zero-day vulnerabilities—one impacting the Windows SMB Server (CVE-2025-55234) and another affecting Microsoft SQL Server through the Newtonsoft.Json library (CVE-2024-21907). The SMB Server flaw enabled attackers to perform relay attacks that could escalate user privileges, while the SQL Server vulnerability allowed unauthenticated remote attackers to trigger denial of service conditions. These flaws were publicly disclosed prior to the release and posed a heightened risk, as threat actors could exploit them before organizations applied the necessary patches. The broad spectrum of vulnerabilities underscores potential exposure across a wide range of Microsoft products and services. This incident exemplifies the urgent need for organizations to keep patch management processes rigorous and up-to-date. The increasing sophistication of attacker TTPs and the frequency of zero-day exploitation have positioned timely security updates as a frontline defense against data compromise and operational disruption.
6 months ago
Kill Chain
Hackers Deploy Advanced Botnet Over Exposed Docker APIs via Tor (2025)
In September 2025, a sophisticated threat campaign was uncovered targeting exposed Docker APIs, where attackers leveraged the Tor network to obfuscate their activities and deploy a new, evolving botnet. The attackers used automated scanning to discover open Docker API endpoints (commonly on port 2375), then executed a multi-stage infection chain utilizing malicious containers. These payloads established persistent SSH access, blocked further exploitation by others, and launched additional tools for internal scanning, lateral movement, and covert communication. While earlier versions dropped cryptominers, the updated tooling focused on botnet expansion, user monitoring, and groundwork for additional attacks such as credential theft or DDoS. This incident exemplifies the rapid shift toward automation and stealth in cloud-native threats. Its relevance is underscored by the proliferation of misconfigured APIs and cloud workloads, combined with attackers’ increasing use of anonymizing networks (like Tor) and multi-vector attacks. Organizations with exposed or poorly secured container environments are urgently at risk.
6 months ago
Kill Chain
Ransomware's New Playbook: 2024 Sophisticated Extortion Hits Major Enterprises
In early 2024, a prominent enterprise fell victim to a highly sophisticated ransomware attack orchestrated by the notorious LockBit gang. Attackers gained entry through compromised credentials, swiftly encrypting critical systems and demanding a $30 million ransom within 72 hours, threatening public data exposure. The perpetrators leveraged professional, SaaS-style operations, exploiting sensitive internal documentation—such as financials and cyber insurance details—to tailor their extortion tactics. Business operations were severely disrupted as the company rushed to contain the breach, initiate crisis response procedures, and engage third-party negotiators. This incident underscores the growing maturity of ransomware groups, who now use advanced negotiation and psychological tactics alongside technical exploits. The increased reliance on credential theft and swift lateral movement, combined with extortion strategies targeting both IT infrastructure and organizational psychology, reflects a broader trend impacting all sectors.
6 months ago
Kill Chain
Salesloft's GitHub Compromise Sparks 2024 Supply Chain Breach
In early 2024, Salesloft experienced a significant cybersecurity breach after attackers compromised a developer's GitHub account. By exploiting weak authentication protocols, threat actors were able to steal OAuth tokens, which enabled them to access and manipulate connected Salesforce instances of downstream customers, resulting in a widespread supply chain attack. The attackers leveraged their foothold to propagate malicious code and gain privileged access to hundreds of enterprise environments, exposing sensitive data and business operations across multiple organizations. This incident highlights the escalating risk presented by software supply chain attacks, particularly those exploiting code repositories and third-party integrations. It underscores the urgent need for organizations to implement strong access controls, enforce zero trust principles, and continuously monitor code and account activity in their development workflows.
6 months ago
Kill Chain
45 New Domains Fuel Salt Typhoon's Stealthy APT Campaign (2024)
In mid-2024, security researchers uncovered that the China-based Advanced Persistent Threat group Salt Typhoon (UNC4841) had deployed 45 new domains and previously undiscovered infrastructure to facilitate persistent, stealthy compromises of targeted organizations. Exploiting their advanced tradecraft, Salt Typhoon gained and maintained long-term access undetected, leveraging encrypted traffic and lateral movement techniques. The attacks primarily targeted sectors with sensitive data and critical infrastructure, amplifying operational and reputational risk for the victims. The campaign demonstrates ongoing actor adaptation and the challenges of detecting covert infrastructure expansion. This incident is especially relevant as organizations face a surge in nation-state actor activity leveraging novel infrastructure and sophisticated evasion methods. The discovery highlights the evolving threat landscape, where increased regulatory pressure and cloud adoption make comprehensive visibility and proactive response capabilities more critical than ever.
6 months ago
Kill Chain
MostereRAT Malware: New Era of EDR Bypass and Persistent Threats
In 2024, security researchers uncovered a sophisticated campaign deploying the 'MostereRAT' malware against Windows environments. The threat actor used advanced techniques to deliver an EDR (Endpoint Detection and Response)-killing tool, enabling long-term, covert persistence on infected systems. MostereRAT blends into legitimate network traffic, leverages encrypted channels, and systematically disables or bypasses security controls, making detection and remediation difficult. Impacted organizations faced risks of data exfiltration, lateral movement, and significant business disruption, with attackers maintaining access for extended periods before discovery. This incident highlights the increasing prevalence of anti-EDR malware designed to counter modern defensive capabilities. As organizations adopt stronger endpoint security, attackers are deploying stealthier, more evasive malware, presenting ongoing challenges for incident detection, compliance, and cyber resilience.
6 months ago
Kill Chain
Logit-Gap Steering: New Jailbreak Threat Undermines LLM Security in 2024
In mid-2024, academic security researchers unveiled a novel attack against large language models (LLMs) termed "logit-gap steering." This technique exploits the mathematical limits of alignment training by manipulating the logits—the raw output probabilities—of refusal and affirmation tokens. Attackers found that by identifying and minimizing the gap through tailored prompt suffixes, they could frequently bypass internal model guardrails and elicit harmful or disallowed responses, even on the latest open-source models such as gpt-oss-20b, LLama, Gemma, and Qwen. The published methodology demonstrated over 75% attack success rates and triggered industry-wide concern about the resilience of current AI safety controls. This incident comes at a pivotal time as organizations accelerate adoption of AI and generative language models in production. The research spotlights a significant, previously underestimated vector for LLM jailbreak attacks, amplifying regulatory scrutiny and forcing enterprises to re-evaluate security practices for AI deployments.
6 months ago
Kill Chain
Remote Code Execution via Model Namespace Reuse Hits AI Supply Chains
In early 2024, security researchers identified a novel AI supply-chain attack involving 'model namespace reuse' on popular machine learning platforms such as Hugging Face. Threat actors exploited the inherent trust in model names and namespaces to upload malicious AI models, thereby enabling remote code execution upon download or integration into downstream applications. The attack allowed adversaries to compromise systems within seconds of a user or developer integrating tainted models, potentially resulting in data breach, lateral movement, or disruption of AI-driven business processes. This incident underscores the growing risk within the AI and ML ecosystem, where reliance on third-party and community-contributed models is accelerating. As more organizations rapidly adopt AI across production workloads, supply-chain vulnerabilities like namespace reuse present urgent challenges for security and compliance.
6 months ago
Kill Chain
The New Insider Threat: How a Fake Employee Infiltrated a Tech Giant in 2025
In August 2025, an advanced cyberattack targeted a major tech company when an attacker successfully joined the organization as a new employee using a fabricated identity, bypassing digital and in-person HR and IT onboarding checks. The attacker, under the alias 'Jordan from Colorado,' leveraged expertly forged credentials and references to gain legitimate system access and privileges from day one. Once inside, the attacker rapidly accessed sensitive data, established lateral footholds through internal network movement, and deployed covert remote access tools. The business suffered significant intellectual property theft and operational disruptions before the activity was detected during a routine audit. The incident demonstrates a rising trend in identity-based infiltration, where social engineering is used not to breach perimeters but to abuse trusted onboarding processes. This kind of attack highlights the urgent need for organizations to modernize identity verification and insider threat detection in response to sophisticated credential fraud and evolving attacker tradecraft.
6 months ago
Kill Chain
Sitecore Zero-Day Breach: ViewState Exploits Lead to Remote Code Execution
In early 2024, threat actors exploited a zero-day vulnerability in Sitecore's ASP.NET-based content management system by weaponizing exposed machine keys, enabling remote code execution via malicious ViewState deserialization. Attackers bypassed authentication controls to inject arbitrary code and gain persistent control over vulnerable web servers, leading to potential data exfiltration and site takeover. Multiple Sitecore installations globally were at risk, highlighting weaknesses in secure key management and web application security monitoring. Organizations faced reputational and operational impacts as attackers abused trusted digital experiences to deliver malware and conduct further intrusions. The incident is part of a broader surge in deserialization and code injection attacks targeting legacy .NET applications. Zero-day exploitation against business-critical CMS platforms increases urgency for robust segmentation, runtime detection, and zero trust controls to defend against rapidly evolving attack techniques.
6 months ago
Kill Chain
Sitecore Vulnerabilities: Cache Poisoning and RCE Exploit Chain Uncovered (2025)
In August 2025, researchers disclosed an exploit chain in the Sitecore Experience Platform involving three newly uncovered vulnerabilities—CVE-2025-53693 (HTML cache poisoning), CVE-2025-53691 (remote code execution via insecure deserialization), and CVE-2025-53694 (not yet detailed). The flaws allow attackers to first poison cached content by manipulating reflected inputs, and then leverage insecure deserialization to remotely execute arbitrary code on targeted Sitecore servers. If exploited, these issues can expose sensitive data and potentially compromise the full web application environment of affected organizations, particularly in sectors relying on large-scale digital experience management. This incident highlights the persistent risk of chained application vulnerabilities enabling critical attacks, such as lateral movement and RCE, within enterprise environments. With web applications being frequent targets and exploit code often surfacing soon after disclosures, organizations must prioritize proactive vulnerability management and robust segmentation to contain blast radius.
6 months ago
Kill Chain
Attackers Exploit Velociraptor Forensics Tool for Covert C2 Tunneling With Visual Studio Code
In June 2025, cybersecurity researchers reported a sophisticated incident in which attackers abused the open-source forensic tool Velociraptor to deploy Visual Studio Code on compromised endpoints and establish an encrypted command-and-control (C2) channel. Threat actors leveraged the legitimate forensic software as a Living Off The Land Binary (LOLBin) to evade detection, achieve execution, and enable covert lateral movement within enterprise environments. This innovative TTP circumvented traditional perimeter detections, and resulted in unauthorized access to sensitive internal systems, raising concerns over the misuse of trusted IT tools in targeted intrusions and potential data exfiltration. The incident highlights a growing trend of blending legitimate IT and developer software within attack chains, making malicious activity harder to distinguish from normal operations. Organizations face increasing regulatory and operational pressure to implement robust east-west traffic monitoring, behavioral detection, and zero trust controls as attackers adopt stealthier methods.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports