Validated Containment Architectures are here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2615 threat reports
Page 217 of 218

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 25932604 / 2615 reports
Amazon Stops APT29 Watering Hole Leverage of Microsoft Device Code
Impact· low

Amazon Stops APT29 Watering Hole Leverage of Microsoft Device Code

In August 2025, Amazon Security Intelligence teams detected and disrupted a sophisticated nation-state watering hole campaign attributed to the Russian-linked APT29 group. The attackers compromised multiple legitimate websites, redirecting unsuspecting visitors to malicious infrastructure designed to exploit Microsoft's device code authentication flow. By tricking users into authorizing attacker-controlled devices, APT29 was able to gain unauthorized access to victim accounts and sensitive data. The rapid response by Amazon limited the scope of the compromise, but the incident highlights evolving tactics by advanced persistent threats targeting cloud identity systems. This incident is notable for its exploitation of widely used authentication protocols and the opportunistic use of trusted websites for redirection. It reflects a broader escalation in targeted attacks on cloud identities and authentication flows, as well as the sophistication of nation-state threat actors seeking persistent access to corporate and government assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Q2 2025 Vulnerability Exploitation: Multi-Platform Attacks and C2 Automation
Impact· medium

Q2 2025 Vulnerability Exploitation: Multi-Platform Attacks and C2 Automation

In Q2 2025, there was a surge in the exploitation of both newly reported and longstanding software vulnerabilities across enterprise environments. Threat actors leveraged critical CVEs—targeting platforms like Microsoft Windows, Linux, document-editing suites, UEFI firmware, AI frameworks, and remote access tools—to gain initial access and escalate privileges on victim systems. Notably, advanced persistent threat (APT) groups demonstrated increased use of C2 frameworks such as Sliver, Metasploit, Havoc, and Brute Ratel to automate exploitation and maintain persistence, highlighting attackers’ growing sophistication and automation. The operational impact ranged from data theft and malware deployment to strategic risks, as attackers pivoted laterally and disabled security mechanisms. The Q2 2025 wave underscores a broader industry trend: attackers are rapidly exploiting both legacy and emerging weaknesses, especially as vulnerability disclosure volumes continue to rise. Automation within C2 frameworks and exploitation targeting multi-cloud and hybrid environments reinforce the urgency to modernize detection and patch-management programs to keep pace with evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Turbocharges Exploit Development: Are You Ready for Machine-Speed Cyber Threats?
Impact· medium

AI Turbocharges Exploit Development: Are You Ready for Machine-Speed Cyber Threats?

In mid-2024, two independent Israeli cybersecurity researchers developed an AI-powered system, "Auto Exploit," that can generate proof-of-concept exploit code for new vulnerabilities in as little as 15 minutes. Leveraging large language models like Anthropic's Claude and open-source LLMs, the system parses CVE advisories and code patches, quickly creating vulnerable test environments and customized exploit code. This approach successfully produced exploits for 14 open source software vulnerabilities, dramatically shortening the typical window for defenders to patch their systems before seeing exploitation in the wild. The project highlights the risk posed by adversaries who can now weaponize vulnerabilities and bypass LLM guardrails at machine speed, raising the stakes for enterprise security teams. As automation and AI further accelerate exploit development, organizations face increasing pressure to adapt their vulnerability management and incident response processes. The emergence of such techniques indicates a shift where traditional exploitability scoring is less relevant, and exposure of assets becomes the key risk consideration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical SAP S/4HANA Code Injection Vulnerability Exploited in 2025
Impact· high

Critical SAP S/4HANA Code Injection Vulnerability Exploited in 2025

In August 2025, a critical code injection vulnerability (CVE-2025-42957) in SAP S/4HANA was exploited in the wild, enabling attackers with even low-privileged user access to inject ABAP code and achieve full compromise of both the SAP environment and the underlying host OS. Publicly disclosed and patched by SAP in its August security updates, the flaw affects both private cloud and on-premise deployments. The exploit requires only a basic user account and a remote function call, after which attackers can manipulate or delete SAP data, create persistent admin backdoors, exfiltrate sensitive data, and control the OS. Exploitation attempts surged following patch publication, with confirmed abuse reported by specialist vendors. This incident highlights the increasing risk of low-complexity, high-impact ERP vulnerabilities, especially as attackers rapidly weaponize disclosed flaws. It underscores the continued targeting of critical business platforms by threat actors leveraging phishing and privileged escalation, emphasizing the urgent need for swift patching and stronger access controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Session Hijacking and Browser Cookies: The State of Web App Security in 2024
Impact· low

Session Hijacking and Browser Cookies: The State of Web App Security in 2024

In mid-2024, multiple web applications faced a surge in session hijacking incidents arising from insecure management of browser cookies. Attackers exploited weaknesses such as unencrypted HTTP traffic, poor cookie attributes, cross-site scripting (XSS), and predictable session identifiers to steal user session cookies, especially the Session ID. This allowed cybercriminals to impersonate users, gain unauthorized access to accounts, and exfiltrate sensitive data, including personal and payment information. The business impact was heightened customer risk, regulatory scrutiny, and erosion of trust, while common attack vectors included public Wi-Fi interception, malicious scripts, and subdomain cookie manipulation. The incident is relevant today as web app complexity and regulatory pressure increase, while attackers leverage more advanced session hijacking techniques. With ongoing changes in privacy laws (GDPR, CCPA, etc.) and threat actor innovation, organizations must harden cookie security and session management to avoid breaches with far-reaching consequences.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
TP-Link Routers Hit by 2025 Zero-Day: What You Need to Know About the CWMP Exploit
Impact· medium

TP-Link Routers Hit by 2025 Zero-Day: What You Need to Know About the CWMP Exploit

In September 2025, TP-Link confirmed a critical zero-day vulnerability impacting multiple router models, including Archer AX10 and AX1500. Discovered by independent researcher Mehrun (ByteRay), the stack-based buffer overflow exists within the routers' CWMP (CPE WAN Management Protocol) implementation, specifically in handling SOAP messages due to improper validation in 'strncpy' calls. Attackers can exploit this flaw to achieve remote code execution by redirecting devices to malicious CWMP servers or leveraging unchanged default credentials, leading to device compromise. Once compromised, adversaries can reroute DNS queries, intercept traffic, and inject malicious payloads, raising severe risks for users and organizations relying on affected devices. The continued exploitation of similar router vulnerabilities by groups like Quad7 botnet highlights a shift in attacker TTPs towards leveraging consumer and SOHO networking devices as entry points and persistence mechanisms. The prevalence of these attacks underscores the urgent need for robust patch management and secure configuration in edge infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Q2 2025 Global Ransomware Surge: Qilin, Nefilim, Black Kingdom, and the Modern Threat Landscape
Impact· high

Q2 2025 Global Ransomware Surge: Qilin, Nefilim, Black Kingdom, and the Modern Threat Landscape

In Q2 2025, the global ransomware threat landscape saw a significant surge with the discovery of 1,702 new ransomware variants and nearly 86,000 users targeted. High-profile law enforcement actions included indictments and extraditions involving Black Kingdom, Nefilim, Ryuk, DoppelPaymer, and RobbinHood operators. Major campaigns leveraged vulnerabilities in SAP NetWeaver, Fortinet devices, and Microsoft Windows (CLFS driver), with actors like Qilin and DragonForce demonstrating adeptness in exploiting zero-days and supply chain weaknesses. Double extortion and rapid lateral movement were widely observed, affecting critical sectors worldwide, including healthcare, government, and managed service providers. This incident underscores the advancement of ransomware attack tactics, the spread of sophisticated variants, and the persistence of threat actors despite law enforcement measures. The continued exploitation of newly discovered vulnerabilities and focus on high-revenue targets highlight the urgent need for enhanced prevention, detection, and incident response across organizations of all sizes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Attackers Are Sidestepping macOS Built-in Security in 2024
Impact· medium

How Attackers Are Sidestepping macOS Built-in Security in 2024

In 2024, researchers and incident responders observed a sophisticated wave of cyberattacks targeting macOS systems, where adversaries adapted to built-in security protections such as Keychain, Gatekeeper, TCC, and System Integrity Protection. Threat actors leveraged utilities like Chainbreaker to extract password data, employed social engineering to bypass File Quarantine and Gatekeeper, and manipulated permission prompts through clickjacking techniques. By exploiting command-line utilities, attackers disabled or evaded standard protections, leading to potential exposure of sensitive credentials and increased risk of full system compromise. The macOS attack landscape continues to evolve, with adversaries innovating to evade resilient, native defenses. Rising adoption of macOS in enterprise environments and the seamless integration with personal devices make these evasion TTPs especially critical for security teams and compliance requirements focused on regulated and sensitive data.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
2025 Spotlight: ESET Uncovers First AI-Powered PromptLock Ransomware
Impact· high

2025 Spotlight: ESET Uncovers First AI-Powered PromptLock Ransomware

In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows. PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks
Impact· low

Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks

In early 2024, a significant security incident was discovered involving the inadvertent exposure of Azure Active Directory credentials via a misconfigured JSON configuration file. The public accessibility of this file enabled malicious actors to directly authenticate against Microsoft’s OAuth 2.0 endpoints, bypassing traditional security controls and potentially infiltrating cloud environments. Attackers leveraged this cloud misconfiguration to escalate cloud access, risking business-critical Azure resources, data loss, and lateral movement inside affected organizations. Detection came after researchers observed unusual authentication patterns linked to public file sharing, prompting rapid investigation and remediation efforts. The incident underscores how easily overlooked misconfigurations can undermine enterprise cloud security and compliance obligations. The breach highlights ongoing challenges as organizations migrate sensitive workflows to the cloud. Public file exposure, credential leakage, and abuse of identity platforms like Azure Active Directory remain top attack vectors. This incident amplifies recent regulatory scrutiny, reinforces the need for cloud visibility and zero trust practices, and signals rising attacker sophistication in exploiting misconfigured storage and identity controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection
Impact· medium

Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection

In 2024, a sophisticated phishing-as-a-service (PhaaS) operation leveraged Google and Cloudflare infrastructure to host undetectable phishing sites for over three years. By employing advanced cloaking techniques and encrypted traffic, threat actors were able to evade detection by security platforms and browsers, targeting users globally and harvesting credentials at scale. The persistent campaign highlights the effectiveness of public cloud abuse for malicious operations and the operational difficulties organizations face in detecting and mitigating such well-cloaked threats. This incident underscores a growing trend: cybercriminals turning to public cloud providers for reliable infrastructure and exploiting their reputation to bypass security controls. It also signals the adaptability of phishing campaigns and the need for enhanced monitoring and zero trust strategies in response to evolving attacker TTPs.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)
Impact· low

FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)

Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls. This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports