✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Understanding Device Code Phishing: The New Frontier in MFA Bypass
In early 2026, cybersecurity researchers identified a surge in phishing campaigns exploiting the OAuth 2.0 Device Authorization Grant flow to bypass multi-factor authentication (MFA). Attackers trick users into entering device codes on legitimate Microsoft authentication pages, granting unauthorized access to services like Outlook, OneDrive, and Teams without stealing credentials. This method allows persistent access, even after password resets, posing significant risks to organizations relying on traditional MFA for security. The proliferation of Phishing-as-a-Service platforms, such as Kali365, has lowered the technical barrier for cybercriminals, enabling large-scale exploitation of this technique. The FBI and Microsoft have issued warnings, emphasizing the need for organizations to implement conditional access policies, disable device code authentication where unnecessary, and adopt phishing-resistant MFA solutions to mitigate these evolving threats.
1 month ago
Kill Chain
Critical Vulnerability in Gravity SMTP Plugin: CVE-2026-4020 Exploited
In June 2026, an unauthenticated information disclosure vulnerability (CVE-2026-4020) was discovered in the Gravity SMTP WordPress plugin, affecting versions up to 2.1.4. This flaw exposed sensitive data, including API keys, email service credentials, and system configuration details, to unauthenticated users via an improperly secured REST API endpoint. Exploitation of this vulnerability could lead to unauthorized access and control over affected websites. The incident underscores the critical importance of promptly updating plugins and implementing robust security measures to protect against emerging threats. Organizations must remain vigilant, as attackers continue to exploit such vulnerabilities to gain unauthorized access and compromise sensitive information.
1 month ago
Kill Chain
AutoJack Attack: A Wake-Up Call for AI Agent Security
In June 2026, Microsoft researchers disclosed a critical vulnerability named 'AutoJack' that allows a single web page to hijack AI browsing agents, leading to remote code execution on the host machine. By directing an AI agent to load a malicious web page, attackers can exploit JavaScript to interact with privileged local services, spawning unauthorized processes without requiring user credentials or further interaction. This exploit underscores the significant risks associated with AI agents' integration with web content and their elevated system privileges. The AutoJack attack highlights the growing trend of adversaries targeting AI development tools and agents. Similar incidents, such as the 'Agentjacking' attack, have demonstrated how AI coding agents can be manipulated into executing malicious code through crafted error reports. These developments emphasize the urgent need for robust security measures in AI agent design and deployment to prevent exploitation through prompt injections and other novel attack vectors.
1 month ago
Kill Chain
The Gentlemen RaaS Unleashes GentleKiller: A New EDR Evasion Framework
In June 2026, The Gentlemen ransomware-as-a-service (RaaS) operation was identified as actively developing and distributing a suite of endpoint detection and response (EDR) termination tools, collectively known as the GentleKiller framework. This framework targets approximately 400 processes associated with 48 distinct security programs, effectively disabling system defenses prior to deploying ransomware payloads. The Gentlemen group has demonstrated rapid operationalization of newly disclosed proof-of-concept exploits, often integrating them within days of public release. The Gentlemen's ability to swiftly adapt and enhance their EDR evasion techniques underscores a significant evolution in ransomware tactics, emphasizing the need for organizations to implement robust, multi-layered security measures. The group's extensive use of the bring your own vulnerable driver (BYOVD) technique highlights the importance of monitoring and controlling driver installations to prevent such attacks.
1 month ago
Kill Chain
Unpatchable 'usbliter8' Exploit Compromises Apple A12 and A13 SecureROM
In June 2026, security researchers at Paradigm Shift disclosed 'usbliter8,' an unpatchable BootROM exploit affecting Apple's A12 and A13 chips. This vulnerability allows arbitrary code execution within the SecureROM, a critical component of the device's boot process. Due to its hardware nature, the flaw cannot be remedied through software updates, leaving devices such as the iPhone XS, XR, and 11 series permanently susceptible. Exploitation requires physical access to the device in DFU mode and a USB connection to a specialized microcontroller, enabling the execution of unsigned code and potential bypassing of Apple's secure boot chain. ([macrumors.com](https://www.macrumors.com/2026/06/18/a12-and-a13-chips-facing-exploit/?utm_source=openai)) The disclosure of 'usbliter8' underscores the persistent challenges in hardware security, particularly with vulnerabilities that cannot be mitigated post-manufacture. This incident highlights the importance of robust hardware design and the need for continuous vigilance in identifying and addressing security flaws that could be exploited through physical access.
1 month ago
Kill Chain
FortiBleed Campaign: A Wake-Up Call for Credential Security
In June 2026, the 'FortiBleed' campaign was uncovered, revealing that cybercriminals had compromised approximately 73,932 Fortinet FortiGate firewalls across 194 countries. The attackers, identified as Russian-speaking, executed over 1.1 billion credential attempts against FortiGate VPN instances and 2.1 billion against Microsoft SQL Server systems. They exploited weak or default credentials and intercepted SSL VPN authentication hashes, which were cracked using a 45-GPU cluster managed through Hashtopolis. This led to unauthorized access to internal Active Directory environments, affecting sectors such as government, telecommunications, financial services, healthcare, manufacturing, and critical infrastructure. Notably, a Turkish NATO defense contractor reportedly lost classified documents due to this breach. This incident underscores the critical importance of robust credential management and the implementation of multi-factor authentication (MFA). The scale and sophistication of the FortiBleed campaign highlight the evolving tactics of threat actors and the necessity for organizations to proactively secure their network devices and monitor for unauthorized access.
1 month ago
Kill Chain
Apple Releases Critical Firmware Update for Beats Studio Buds
In June 2026, Apple released firmware update 1B211 for its Beats Studio Buds to address a critical vulnerability (CVE-2025-20701) that allowed attackers within Bluetooth range to eavesdrop through the device's microphone during the pairing process. This flaw, stemming from incorrect authorization in the Airoha Bluetooth audio SDK, enabled unauthorized pairing without user consent, potentially compromising user privacy. ([macrumors.com](https://www.macrumors.com/2026/06/16/beats-studio-buds-bluetooth-vulnerability/?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used consumer devices, especially those involving open-source components. It highlights the need for continuous vigilance and timely updates to protect user privacy and maintain trust in wireless technologies.
1 month ago
Kill Chain
FBI and Google Dismantle 'Outsider Enterprise' Phishing Operation
In June 2026, the FBI, in collaboration with Google and Lumen Technologies, dismantled 'Outsider Enterprise,' a China-based phishing-as-a-service (PhaaS) operation. Active since 2023, this network utilized AI-driven phishing kits to impersonate trusted brands, distributing over 2.5 million fraudulent SMS messages to Android users within a two-week period. The operation led to the theft of approximately 3.8 million credit card records, resulting in an estimated $1.9 billion in financial losses. Authorities seized multiple administrative servers, a Shopify storefront, a Telegram bot containing customer data, and approximately $100,000 in cryptocurrency. Google also filed a civil lawsuit against the infrastructure operators and coordinated with major U.S. telecommunications carriers to block the fraudulent messages before they reached targeted users. This takedown underscores the escalating threat posed by AI-enhanced phishing campaigns and the necessity for robust, collaborative cybersecurity measures to protect sensitive information and financial assets.
1 month ago
Kill Chain
Novo Nordisk 2026 Breach: A Wake-Up Call for Software Development Security
In March 2026, Novo Nordisk, a leading pharmaceutical company, experienced a significant security breach initiated through an exposed GitHub personal access token found in client-side JavaScript on a subdomain. The threat group FulcrumSec exploited this token to clone private repositories, harvest additional credentials, and infiltrate deeper into the company's network. Over a span of more than two months, the attackers exfiltrated approximately 1.3TB of sensitive data, including source code, proprietary drug information, clinical trial data, internal AI models, and personal information of healthcare professionals and clinical trial participants. The breach was publicly disclosed on June 11, 2026, after unauthorized access to internal IT systems was detected. This incident highlights the critical vulnerabilities in software development pipelines, particularly concerning secrets management and the security of code repositories. The reliance on hardcoded credentials and improperly scoped access keys within development environments presents a substantial risk. Organizations are urged to treat development platforms as production systems, enforce stringent secrets management practices, and implement robust monitoring to prevent similar breaches.
1 month ago
Kill Chain
Critical Security Alert: AVer PTC Cameras Vulnerable to Remote Code Execution (CVE-2026-40624)
In June 2026, a critical vulnerability (CVE-2026-40624) was identified in AVer PTC series cameras, including models PTC500S, PTC115, PTC500+, and PTC115+. This flaw allows remote, unauthenticated attackers to execute arbitrary code via specially crafted web requests, potentially leading to full device compromise. The vulnerability affects all firmware versions of these models. AVer has released firmware updates to address this issue, and users are strongly advised to apply these patches promptly to mitigate the risk of exploitation. This incident underscores the ongoing security challenges in IoT devices, particularly in the surveillance sector. The ease of exploitation and the critical nature of the affected devices highlight the importance of regular firmware updates and robust network security practices to protect against emerging threats.
1 month ago
Kill Chain
Critical Vulnerabilities in Apollo Pharmacy's Blood Glucose Monitoring System APG-01 BT
In June 2026, vulnerabilities were identified in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically affecting version 0x0110_v1.1.0. These vulnerabilities, CVE-2026-50034 and CVE-2026-52866, allow attackers within Bluetooth Low Energy (BLE) range to intercept sensitive health data and disrupt device connectivity. The first vulnerability enables unauthorized access to glucose measurement values, while the second allows an attacker to monopolize the device's BLE connection, preventing legitimate use. These issues highlight the critical need for robust security measures in medical devices, especially those utilizing wireless communication protocols. As healthcare increasingly relies on connected devices, ensuring the confidentiality and availability of patient data is paramount to maintaining trust and compliance with regulatory standards.
1 month ago
Kill Chain
Fortinet Credential Exposure 2026: Massive 'FortiBleed' Campaign
In June 2026, a significant cybersecurity incident known as 'FortiBleed' exposed credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. Security researchers discovered a massive archive containing FortiGate firewall URLs, usernames, emails, and plaintext passwords from major corporations such as Chevron, Samsung, Foxconn, and Toyota. The attackers, reportedly Russian-speaking, executed over 1.1 billion credential attempts against 320,000 FortiGate VPN instances, leading to the compromise of Active Directory environments and, in some cases, the exfiltration of classified documents. Fortinet responded by emphasizing best practices like regular credential updates and enabling multi-factor authentication (MFA) to mitigate risks. This incident underscores the critical importance of robust credential management and the implementation of MFA, especially for internet-facing systems. The scale and sophistication of the 'FortiBleed' campaign highlight the evolving tactics of cyber adversaries and the necessity for organizations to proactively secure their network infrastructures.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports