The Containment Era is here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2551 threat reports
Page 37 of 213

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 433444 / 2551 reports
TanStack npm Supply Chain Attack: A Wake-Up Call for CI/CD Security
Impact· CRITICAL

TanStack npm Supply Chain Attack: A Wake-Up Call for CI/CD Security

In May 2026, TanStack's npm packages were compromised in a sophisticated supply chain attack. The attackers exploited GitHub Actions vulnerabilities, including misconfigured workflows and cache poisoning, to publish 84 malicious versions across 42 packages. This breach led to credential theft and potential malware propagation, impacting developers and CI/CD systems. ([tanstack.com](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem?utm_source=openai)) This incident underscores the critical need for secure CI/CD pipeline configurations and robust supply chain security measures, as similar attacks are on the rise, targeting widely-used open-source libraries.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the OpenClaw Vulnerability and AI Agent Supply Chain Risks
Impact· HIGH

Understanding the OpenClaw Vulnerability and AI Agent Supply Chain Risks

In early 2026, the OpenClaw AI agent framework, widely adopted for automating enterprise workflows, was found to have a critical vulnerability (CVE-2026-25253) that allowed remote code execution via a WebSocket exploit. This flaw enabled attackers to hijack agents by tricking users into visiting malicious websites, potentially compromising entire workstations. The incident highlighted the risks associated with unmanaged, autonomous AI systems operating with extensive access and minimal oversight. ([waxell.ai](https://www.waxell.ai/blog/openclaw-ai-agent-supply-chain-security?utm_source=openai)) This event underscores the growing security challenges in AI agent supply chains, emphasizing the need for robust governance and verification mechanisms. As organizations increasingly deploy AI agents, ensuring the integrity and security of third-party skills and components becomes paramount to prevent similar vulnerabilities and attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA's BOD 26-04: A New Era in Risk-Based Vulnerability Management
Impact· LOW

CISA's BOD 26-04: A New Era in Risk-Based Vulnerability Management

On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, mandating federal agencies to prioritize vulnerability remediation based on four specific criteria: public exposure of the asset, evidence of active exploitation, potential for automated exploitation, and the technical impact of the vulnerability. Vulnerabilities meeting all four criteria require remediation within three days, accompanied by a forensic assessment to determine if systems have been compromised. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai)) This directive reflects CISA's response to the accelerated threat landscape, particularly the role of artificial intelligence in rapidly identifying and exploiting vulnerabilities. By focusing on risk-based prioritization, BOD 26-04 aims to enhance the efficiency and effectiveness of federal agencies' cybersecurity efforts, ensuring that the most critical vulnerabilities are addressed promptly to mitigate potential threats. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Addresses Critical Zero-Day Vulnerabilities: YellowKey, GreenPlasma, and MiniPlasma
Impact· HIGH

Microsoft Addresses Critical Zero-Day Vulnerabilities: YellowKey, GreenPlasma, and MiniPlasma

In June 2026, Microsoft addressed three critical zero-day vulnerabilities—YellowKey, GreenPlasma, and MiniPlasma—disclosed by the researcher 'Nightmare Eclipse.' YellowKey (CVE-2026-45585) allowed attackers with physical access to bypass BitLocker encryption via the Windows Recovery Environment. GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) were privilege escalation flaws in the Collaborative Translation Framework and Cloud Files Mini Filter Driver, respectively, enabling local attackers to gain SYSTEM privileges on fully patched Windows systems. These vulnerabilities were patched in Microsoft's June 2026 Patch Tuesday updates. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/?utm_source=openai)) The disclosure of these vulnerabilities highlights ongoing challenges in vulnerability management and coordinated disclosure practices. The public release of proof-of-concept exploits prior to patches underscores the need for robust security measures and prompt patch management to mitigate potential threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523
Impact· CRITICAL

Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523

In June 2026, Ivanti disclosed two critical vulnerabilities in its Sentry secure mobile gateway: CVE-2026-10520, an OS command injection flaw allowing unauthenticated remote code execution with root privileges, and CVE-2026-10523, an authentication bypass enabling attackers to create administrative accounts. Both vulnerabilities were patched in Sentry versions R10.5.2, R10.6.2, and R10.7.1. These vulnerabilities underscore the persistent targeting of Ivanti products by threat actors, highlighting the necessity for organizations to promptly apply security patches to mitigate potential exploitation risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Exchange Server CVE-2026-42897 Zero-Day Exploited in Attacks
Impact· MEDIUM

Microsoft Exchange Server CVE-2026-42897 Zero-Day Exploited in Attacks

In May 2026, Microsoft disclosed a high-severity cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This flaw allows remote attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, which, when opened in Outlook Web Access (OWA), trigger the exploit. The vulnerability was actively exploited in the wild, prompting Microsoft to release security updates in June 2026 to address the issue. Organizations were advised to apply these updates promptly and maintain existing mitigations to ensure comprehensive protection. The exploitation of CVE-2026-42897 underscores the persistent targeting of email infrastructure by threat actors, highlighting the critical need for organizations to prioritize the security of their communication platforms. This incident serves as a reminder of the importance of timely patch management and the implementation of robust security measures to defend against evolving cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
ShinyHunters' Exploitation of Oracle PeopleSoft: A Wake-Up Call for ERP Security
Impact· MEDIUM

ShinyHunters' Exploitation of Oracle PeopleSoft: A Wake-Up Call for ERP Security

In June 2026, the ShinyHunters cybercriminal group launched a series of data theft attacks targeting Oracle PeopleSoft servers across more than 100 organizations, predominantly within the education sector. By exploiting a combination of known and zero-day vulnerabilities, they successfully exfiltrated sensitive data from approximately 300 instances. The University of Nottingham was among the affected institutions, with its data subsequently published on ShinyHunters' data leak site. These incidents underscore the critical need for organizations to promptly apply security patches and conduct thorough system configurations to mitigate potential vulnerabilities. This attack highlights a concerning trend of cybercriminals increasingly targeting enterprise resource planning (ERP) systems, which are integral to organizational operations. The exploitation of both known and unknown vulnerabilities in such systems emphasizes the importance of proactive cybersecurity measures, including regular system audits, timely patch management, and comprehensive incident response planning to safeguard sensitive data and maintain operational integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GitHub's npm v12: Strengthening Security Against Supply-Chain Attacks
Impact· CRITICAL

GitHub's npm v12: Strengthening Security Against Supply-Chain Attacks

In June 2026, GitHub announced significant security enhancements for npm version 12, aimed at mitigating supply-chain attacks. Key changes include requiring explicit approval for running preinstall, install, or postinstall scripts from dependencies, and restricting automatic fetching of dependencies from Git repositories and remote URLs unless explicitly permitted. These measures are designed to prevent unauthorized code execution during package installations, thereby enhancing the security of the npm ecosystem. This initiative addresses vulnerabilities exploited in recent supply-chain attacks, such as the Shai-Hulud campaign, which compromised numerous npm packages to steal developer credentials. By implementing these changes, GitHub aims to fortify the software supply chain against emerging threats and protect developers from potential security breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Langflow Vulnerability CVE-2026-5027 Exploited in the Wild
Impact· HIGH

Critical Langflow Vulnerability CVE-2026-5027 Exploited in the Wild

In early 2026, a critical path traversal vulnerability, CVE-2026-5027, was discovered in Langflow, an open-source AI development platform. This flaw allowed unauthenticated attackers to write arbitrary files to exposed servers by exploiting the 'POST /api/v2/files' endpoint, which failed to properly sanitize user-supplied filenames. The vulnerability was publicly disclosed on March 27, 2026, after initial reports to the Langflow team went unanswered. Exploitation of this flaw has been observed in the wild, with attackers dropping test files on vulnerable instances. Langflow users are urged to upgrade to version 1.10.0 to mitigate this risk. This incident underscores the critical importance of timely vulnerability management and the risks associated with default configurations that allow unauthenticated access. Organizations must prioritize patching known vulnerabilities and reassess default settings to prevent unauthorized exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
JDY Botnet's Rapid Expansion: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

JDY Botnet's Rapid Expansion: A Wake-Up Call for Cybersecurity

In June 2026, cybersecurity researchers reported a significant expansion of the JDY botnet, a covert network linked to Chinese state-sponsored actors. The botnet has grown from 650 to over 1,500 compromised small office and home office (SOHO) routers and IoT devices. This network is utilized for large-scale reconnaissance, enabling rapid identification and mapping of exposed services within hours of new vulnerability disclosures. The JDY botnet's resilience and adaptability underscore the persistent threat posed by state-sponsored cyber activities targeting critical infrastructure. The rapid expansion of the JDY botnet highlights the increasing sophistication of state-sponsored cyber operations. Organizations must prioritize timely patching of edge devices, enforce strong authentication measures, and monitor for indicators of compromise to mitigate the risks associated with such covert networks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft's June 2026 Patch Tuesday: Addressing 206 Vulnerabilities, Including Three Zero-Days
Impact· HIGH

Microsoft's June 2026 Patch Tuesday: Addressing 206 Vulnerabilities, Including Three Zero-Days

In June 2026, Microsoft released its largest-ever Patch Tuesday update, addressing 206 vulnerabilities across its product suite, including Windows, Office, Azure, and more. Notably, this update included fixes for three zero-day vulnerabilities: CVE-2026-49160, a denial of service flaw in web servers; CVE-2026-45586, an elevation of privilege issue in the Windows Collaborative Translation Framework; and CVE-2026-50507, a BitLocker vulnerability allowing unauthorized data access. These zero-days were publicly disclosed by a researcher known as 'Nightmare Eclipse,' leading to heightened tensions between the researcher and Microsoft. The rapid disclosure and exploitation of these vulnerabilities underscore the evolving threat landscape and the critical need for timely patch management. Organizations are urged to prioritize the deployment of these updates to mitigate potential risks associated with these vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
The Gentlemen Ransomware Group: A Rising Threat in 2026
Impact· CRITICAL

The Gentlemen Ransomware Group: A Rising Threat in 2026

The Gentlemen ransomware group, emerging in mid-2025, has rapidly become the second most active ransomware-as-a-service (RaaS) operation, claiming over 330 victims by mid-2026. Offering affiliates a 90% revenue share, the group attracts experienced operators who exploit internet-facing devices like VPNs and firewalls to gain initial access, swiftly encrypting entire networks within hours. Their cross-platform ransomware, written in Go, targets Windows, Linux, and ESXi environments, employing advanced techniques such as lateral movement, defense evasion, and data exfiltration to maximize impact. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/?utm_source=openai))The rapid ascent of The Gentlemen underscores the evolving sophistication of ransomware operations, highlighting the urgent need for organizations to bolster their cybersecurity defenses. The group's aggressive recruitment and advanced tactics exemplify the growing threat posed by RaaS platforms, emphasizing the importance of proactive threat intelligence and robust security measures to mitigate such risks. ([computerweekly.com](https://www.computerweekly.com/news/366643511/The-Gentlemen-emerging-as-key-ransomware-player?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports