The Containment Era is here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2550 threat reports
Page 25 of 213

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 289300 / 2550 reports
The Critical Shift to Post-Quantum Cryptography for Credential Security
Impact· MEDIUM

The Critical Shift to Post-Quantum Cryptography for Credential Security

In June 2026, cybersecurity experts highlighted the imminent threat posed by quantum computing to current cryptographic systems, particularly those safeguarding credentials. As quantum hardware advances, algorithms like RSA and elliptic curve cryptography, which protect sensitive data, are at risk of being compromised. This vulnerability underscores the urgency for organizations to transition to post-quantum cryptography (PQC) to maintain data confidentiality and integrity. ([thehackernews.com](https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html?utm_source=openai)) The relevance of this issue is amplified by the increasing prevalence of 'harvest now, decrypt later' attacks, where adversaries collect encrypted data today, anticipating future quantum capabilities to decrypt it. This trend necessitates immediate action to adopt PQC solutions to safeguard long-term data security. ([thehackernews.com](https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in pydicom's pynetdicom Library Exposes Healthcare Systems
Impact· CRITICAL

Critical Vulnerability in pydicom's pynetdicom Library Exposes Healthcare Systems

In June 2026, a critical vulnerability (CVE-2026-56445) was identified in the pydicom pynetdicom library, specifically affecting versions from 1.0.0 up to and including 3.0.4. This flaw resides in the qrscp application's C-STORE handler, which improperly handles attacker-supplied DICOM datasets, allowing unauthenticated attackers to write files to arbitrary paths on the server. The vulnerability poses significant risks, particularly to the healthcare sector, as it could lead to unauthorized data manipulation or system compromise. The maintainers of pynetdicom have not yet released a fix for this vulnerability. Organizations utilizing affected versions are advised to restrict network exposure of the qrscp DICOM port (default 11112) to trusted peers, implement firewall protections, and monitor for updates from the project's repository. This incident underscores the importance of securing medical imaging software against potential cyber threats.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Flaws Discovered in H.VIEW HV-500S6 IP Cameras
Impact· HIGH

Critical Security Flaws Discovered in H.VIEW HV-500S6 IP Cameras

In June 2026, two critical vulnerabilities were identified in the H.VIEW HV-500S6 IP Camera, specifically in firmware version IPCAM_V4.06.88.251229. CVE-2026-55975 allows authenticated users to execute arbitrary commands with elevated privileges by injecting unsanitized XML fields into the device's certificate generation interface. CVE-2026-56414 permits authenticated users to upload arbitrary files without validation, potentially compromising system integrity. Exploitation of these vulnerabilities could lead to unauthorized access and control over the affected devices. The discovery of these vulnerabilities underscores the growing security challenges in IoT devices, particularly those deployed in critical infrastructure sectors. Organizations must prioritize regular security assessments and firmware updates to mitigate such risks.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical SSRF Vulnerability in OHIF DICOM Web Viewer Framework (CVE-2026-12473)
Impact· HIGH

Critical SSRF Vulnerability in OHIF DICOM Web Viewer Framework (CVE-2026-12473)

In June 2026, a critical vulnerability (CVE-2026-12473) was identified in the OHIF DICOM Web Viewer Framework versions up to 3.12.0. This Server-Side Request Forgery (SSRF) flaw allowed attackers to steal authenticated clinicians' OIDC Bearer tokens via crafted links, potentially granting unauthorized access to sensitive patient data. The issue stemmed from two data sources—DICOMWebProxy and DICOMJSON—fetching arbitrary URL parameters without validation, leading to token exposure when requests were sent to attacker-controlled servers. ([hipaajournal.com](https://www.hipaajournal.com/high-severity-vulnerability-identified-in-ohif-viewers-dicom/?utm_source=openai)) The vulnerability was addressed with the release of version 3.12.2 on May 18, 2026. Users are strongly advised to upgrade to this version or later to mitigate the risk. This incident underscores the critical importance of validating external inputs and implementing robust security measures in healthcare applications to protect sensitive information. ([machinespirits.com](https://www.machinespirits.com/advisory/0a7f3c/?utm_source=openai))

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FBI Issues Warning on Russian Hackers Exploiting Signal Backup Recovery Keys
Impact· HIGH

FBI Issues Warning on Russian Hackers Exploiting Signal Backup Recovery Keys

In June 2026, the FBI and CISA issued an updated warning regarding Russian intelligence phishing campaigns targeting Signal users. Attackers impersonated Signal support, sending messages that prompted users to share their Backup Recovery Keys under the guise of preventing data loss. Once obtained, these keys allowed attackers to restore backups, access private messages, and take over accounts. The campaign primarily targeted individuals of high intelligence value, including government officials, military personnel, political figures, journalists, and Ukrainian officials. This incident underscores the evolving tactics of nation-state actors in exploiting legitimate features of secure messaging apps through social engineering. The focus on high-profile individuals highlights the strategic nature of the campaign, emphasizing the need for heightened vigilance and robust security practices among potential targets.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Impact· HIGH

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

In June 2026, a sophisticated supply chain attack known as 'Miasma' compromised 32 npm packages under Red Hat's @redhat-cloud-services namespace. The attackers gained access through a compromised Red Hat employee's GitHub account, allowing them to push malicious commits that bypassed standard peer reviews. These commits exploited GitHub Actions workflows to publish trojanized package versions to the public npm registry. Upon installation, these packages executed an obfuscated payload designed to steal credentials from various platforms, including GitHub, AWS, Azure, and Google Cloud Platform. The malware also attempted to propagate by compromising additional maintainer packages and, in some cases, could destroy the maintainer’s home directory. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The Miasma campaign highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of package repositories to prevent unauthorized access and mitigate the risk of widespread credential theft and system compromise.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the DirtyClone Linux Kernel Vulnerability (CVE-2026-43503)
Impact· HIGH

Understanding the DirtyClone Linux Kernel Vulnerability (CVE-2026-43503)

In June 2026, a critical Linux kernel vulnerability known as 'DirtyClone' (CVE-2026-43503) was disclosed, allowing local users to escalate privileges to root by exploiting cloned network packets. This flaw, part of the DirtyFrag family, arises from the kernel's mishandling of shared memory flags during packet cloning, enabling unauthorized memory corruption. The vulnerability affects systems with unpatched kernels prior to May 21, 2026, particularly those with unprivileged user namespaces enabled, such as Debian, Ubuntu, and Fedora. The disclosure of DirtyClone underscores the persistent challenges in securing kernel-level code, especially concerning memory management and privilege escalation. This incident highlights the necessity for organizations to promptly apply security patches and reassess configurations that permit unprivileged user namespaces, to mitigate potential exploitation risks.

1 month ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Amazon Q Developer Vulnerability CVE-2026-12957: What You Need to Know
Impact· HIGH

Amazon Q Developer Vulnerability CVE-2026-12957: What You Need to Know

In June 2026, a critical vulnerability (CVE-2026-12957) was identified in Amazon Q Developer's handling of Model Context Protocol (MCP) servers. This flaw allowed malicious repositories to execute arbitrary commands on a developer's machine upon opening and trusting a workspace, potentially leading to unauthorized access to cloud credentials. The issue was promptly addressed by Amazon with the release of Language Servers for AWS version 1.69.0, mitigating the risk of exploitation. This incident underscores the growing security challenges associated with AI-powered development tools. As these tools become more integrated into the software development lifecycle, ensuring robust security measures and prompt patching of vulnerabilities is imperative to protect sensitive data and maintain trust in development environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Linux Kernel Vulnerability 'pedit COW' (CVE-2026-46331) Allows Root Access
Impact· HIGH

Critical Linux Kernel Vulnerability 'pedit COW' (CVE-2026-46331) Allows Root Access

In June 2026, a critical vulnerability identified as CVE-2026-46331, also known as 'pedit COW,' was discovered in the Linux kernel's traffic control subsystem. This flaw allows local unprivileged users to escalate their privileges to root by exploiting an out-of-bounds write in the packet-editing action (act_pedit), leading to corruption of shared page-cache memory. A public, working exploit was released shortly after the CVE assignment, raising significant security concerns across various Linux distributions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-46331?utm_source=openai)) The rapid public disclosure and availability of exploit code for CVE-2026-46331 underscore the critical need for organizations to promptly apply security patches. This incident highlights the ongoing risks associated with kernel-level vulnerabilities and the importance of maintaining up-to-date systems to mitigate potential privilege escalation attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive 2026 Data Breach Exposes One Million Passport Records
Impact· HIGH

Massive 2026 Data Breach Exposes One Million Passport Records

In June 2026, a significant data breach exposed nearly one million passport records worldwide. The compromised data originated from an ID verification system used by cannabis dispensaries, where high-value credentials like passports were utilized for authentication. Attackers exploited vulnerabilities in this ancillary system, leading to the unauthorized disclosure of sensitive personal information. This incident underscores the critical need for robust security measures across all systems handling sensitive data, regardless of their primary function. It highlights the risks associated with using high-value credentials in less secure, ancillary systems and the potential for such breaches to have widespread implications.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Bluekit's Evolution: Browser-in-the-Middle Phishing Attacks
Impact· MEDIUM

Bluekit's Evolution: Browser-in-the-Middle Phishing Attacks

In June 2026, the Bluekit phishing-as-a-service platform introduced browser-in-the-middle (BitM) capabilities, enhancing its ability to steal user credentials. This method involves the attacker controlling a browser session that loads legitimate login pages, intercepting user inputs and session tokens. By leveraging the open-source JavaScript library 'rrweb,' Bluekit streams the page's DOM over a WebSocket connection, allowing real-time interaction and data theft. This evolution signifies a shift towards more sophisticated phishing techniques that can bypass traditional security measures, including multi-factor authentication (MFA). Organizations must be aware of these advanced tactics to bolster their defenses against such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cisco SD-WAN Zero-Day CVE-2026-20245 Exploited
Impact· HIGH

Cisco SD-WAN Zero-Day CVE-2026-20245 Exploited

In June 2026, a high-severity zero-day vulnerability, CVE-2026-20245, was discovered in Cisco Catalyst SD-WAN Manager. This flaw allows authenticated attackers with netadmin privileges to execute arbitrary commands as root by uploading specially crafted files. Exploitation of this vulnerability has been observed in the wild, leading to unauthorized configuration changes on edge devices. Notably, attackers have been exploiting this vulnerability for months prior to its public disclosure, highlighting significant security gaps in the SD-WAN infrastructure. The exploitation of CVE-2026-20245 underscores a concerning trend of increasing attacks targeting SD-WAN solutions. Organizations relying on Cisco's SD-WAN products must prioritize immediate mitigation strategies, as the absence of a patch leaves systems vulnerable to potential breaches and operational disruptions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports