✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
May 2026 Cyber Threats: ClearFake Campaign and GraphRunner Malware
In May 2026, multiple sophisticated cyber threats emerged, notably the ClearFake campaign, which utilized advanced web injection techniques to deploy the Amatera Stealer malware. This malware, an evolution of the ACR Stealer, was distributed through deceptive methods such as EtherHiding and ClickFix, leading to significant data exfiltration. Additionally, the GraphRunner malware debuted, exploiting vulnerabilities in cloud services to execute unauthorized code, posing substantial risks to cloud infrastructure security. These incidents underscore a concerning trend: cybercriminals are increasingly leveraging complex, multi-stage attacks that combine social engineering with technical exploits. The rise of such sophisticated malware campaigns highlights the urgent need for organizations to enhance their cybersecurity measures and remain vigilant against evolving threats.
2 months ago
Kill Chain
Shai-Hulud 2.0: Unveiling the 2025 npm Supply Chain Attack
In November 2025, the Shai-Hulud 2.0 supply chain attack emerged as a significant threat to the npm ecosystem. Attackers compromised hundreds of npm packages by injecting malicious preinstall scripts that executed before installation completion. These scripts harvested sensitive data, including credentials and configuration secrets, from developer environments and CI/CD pipelines, exfiltrating them to attacker-controlled repositories. The malware exhibited worm-like behavior, autonomously spreading by publishing malicious versions of accessible packages, thereby propagating across the npm ecosystem. Major projects such as Zapier, Ethereum Name Service (ENS), PostHog, and Postman were affected, with over 25,000 repositories compromised within a few hours. ([blog.checkpoint.com](https://blog.checkpoint.com/research/shai-hulud-2-0-inside-the-second-coming-the-most-aggressive-npm-supply-chain-attack-of-2025/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks targeting open-source ecosystems. The rapid propagation and automation observed in Shai-Hulud 2.0 highlight the urgent need for enhanced security measures in software development pipelines. Organizations must prioritize securing their development environments, implement robust monitoring, and adopt best practices to mitigate the risks associated with such pervasive threats.
2 months ago
Kill Chain
Critical Vulnerability in ABB Ability™ zenon: CVE-2025-8754
In August 2025, a critical vulnerability (CVE-2025-8754) was identified in ABB's Ability™ zenon software, versions 7.50 through 14. This flaw allows unauthenticated remote attackers to access critical functions, potentially leading to denial-of-service conditions in industrial control environments. The vulnerability arises from missing authentication mechanisms in the Remote Transport Service, enabling unauthorized system reboots. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-8754&utm_source=openai)) The incident underscores the importance of robust authentication protocols in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize timely vulnerability assessments and implement comprehensive security measures to mitigate potential risks.
2 months ago
Kill Chain
CERT-In's 12-Hour Patching Mandate: A Response to AI-Driven Cyber Threats
In May 2026, the Indian Computer Emergency Response Team (CERT-In) issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of identification. This directive aims to mitigate threats from adversaries leveraging artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability discovery and exploitation, thereby accelerating the scale and speed of cyber attacks. CERT-In emphasized that AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems. As organizations become increasingly dependent on interconnected digital infrastructure, cloud ecosystems, software supply chains, operational technologies, and AI-enabled platforms, the potential impact of AI-enabled cyber threats continues to increase across sectors. ([thehackernews.com](https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html?utm_source=openai)) This development underscores the evolving cyber threat landscape, where AI technologies are being harnessed to compress attack timelines and bypass traditional security controls. Organizations are urged to adopt proactive cybersecurity measures, including continuous threat assessment, proactive exposure reduction, and operational preparedness, to effectively counter these AI-assisted threats.
2 months ago
Kill Chain
Understanding and Mitigating MFA Prompt Bombing Attacks in 2026
In May 2026, a significant cybersecurity threat emerged involving Multi-Factor Authentication (MFA) prompt bombing attacks. Cybercriminals exploited push-based MFA systems by repeatedly sending authentication requests to users, aiming to induce fatigue and prompt them to approve unauthorized access. This method effectively bypassed traditional MFA protections, leading to unauthorized access to sensitive systems and data. The attacks primarily targeted organizations utilizing push-based MFA for services like Microsoft 365, VPNs, and other cloud applications, resulting in compromised accounts and potential data breaches. The prevalence of MFA prompt bombing underscores the evolving tactics of threat actors who leverage social engineering to circumvent security measures. This trend highlights the necessity for organizations to adopt more resilient authentication methods, such as number-matching codes or hardware tokens, and to implement comprehensive user education programs to recognize and resist such attacks.
2 months ago
Kill Chain
Microsoft Releases Critical Patch for SharePoint RCE Vulnerability CVE-2026-45659
In May 2026, Microsoft addressed a critical remote code execution vulnerability, CVE-2026-45659, in SharePoint Server versions 2016, 2019, and Subscription Edition. This flaw arises from the deserialization of untrusted data, allowing authenticated attackers with minimal permissions to execute arbitrary code remotely without user interaction. The vulnerability has a CVSS score of 8.8, indicating high severity. ([thehackernews.com](https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html?utm_source=openai)) The prompt release of patches underscores the importance of timely updates, especially given SharePoint's role in storing sensitive corporate data. Organizations are urged to apply these updates promptly to mitigate potential exploitation risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/?utm_source=openai))
2 months ago
Kill Chain
Cybercriminals Exploit Claude AI Popularity to Distribute Malware
In early 2026, cybercriminals launched a sophisticated campaign targeting users seeking to download Anthropic's Claude AI tool. By creating fraudulent websites that closely mimicked the official Claude download pages, attackers distributed trojanized installers. These malicious installers appeared legitimate but secretly deployed malware, such as PlugX and ACR Stealer, granting attackers remote access to victims' systems and enabling the theft of sensitive information, including credentials and financial data. The campaign exploited users' trust in search engine results and official-looking websites, leading to widespread infections across both Windows and macOS platforms. This incident underscores a growing trend where threat actors leverage the popularity of AI tools to execute social engineering attacks. The use of fake installation guides and malicious advertisements highlights the need for heightened vigilance among users and organizations. As AI tools become more integrated into daily operations, ensuring the authenticity of download sources and implementing robust cybersecurity measures are imperative to prevent similar attacks.
2 months ago
Kill Chain
Anthropic's Claude Mythos: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic introduced 'Claude Mythos,' an advanced AI model with exceptional capabilities in identifying and exploiting software vulnerabilities. The model demonstrated the ability to autonomously develop sophisticated cyberattacks, raising significant concerns about its potential misuse. To mitigate these risks, Anthropic restricted public access to Mythos, collaborating with select partners through Project Glasswing to enhance cybersecurity defenses. ([euronews.com](https://www.euronews.com/next/2026/04/08/why-anthropics-most-powerful-ai-model-mythos-preview-is-too-dangerous-for-public-release?utm_source=openai)) The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where AI can both uncover and exploit vulnerabilities at unprecedented speeds. This development underscores the urgent need for robust security measures and proactive strategies to address the dual-use nature of such technologies. ([cfr.org](https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security?utm_source=openai))
2 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Service Exploiting Microsoft 365 Accounts
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform distributed via Telegram, enabling cybercriminals to hijack Microsoft 365 accounts. By exploiting Microsoft's OAuth 2.0 Device Authorization grant flow, attackers trick users into entering device codes on legitimate Microsoft pages, granting unauthorized access to services like Outlook, Teams, and OneDrive. This method bypasses multi-factor authentication (MFA) and does not require stealing user credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/?utm_source=openai)) The emergence of Kali365 underscores a significant shift in cyber threats, where sophisticated phishing tools are now accessible to less-skilled attackers. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving phishing tactics. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
2 months ago
Kill Chain
TrapDoor Supply Chain Attack Compromises npm, PyPI, and Crates.io Ecosystems
In May 2026, a coordinated supply chain attack named 'TrapDoor' targeted the npm, PyPI, and Crates.io ecosystems, distributing credential-stealing malware through over 34 malicious packages across more than 384 versions. The campaign began on May 22, 2026, with attackers publishing these packages in rapid succession. The malware specifically aimed at developers in the cryptocurrency, DeFi, Solana, and AI sectors, seeking to exfiltrate sensitive information such as crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack employed various methods, including postinstall hooks, remote JavaScript payloads executed during package imports, and malicious build.rs scripts, to infiltrate developer environments and establish persistence. ([thehackernews.com](https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the need for enhanced vigilance and security measures among developers and organizations. The sophisticated techniques used in the TrapDoor campaign reflect a broader trend of attackers exploiting trusted software repositories to distribute malware, emphasizing the importance of robust supply chain security practices.
2 months ago
Kill Chain
TeamPCP's Supply Chain Attack: A Wake-Up Call for Software Security
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software ecosystems. The campaign involved compromising the Nx Console VS Code extension, leading to the exfiltration of approximately 3,800 internal GitHub repositories. Additionally, TeamPCP trojanized Microsoft's durabletask Python SDK on PyPI and injected malicious code into 639 versions of 323 npm packages within the @antv ecosystem. These attacks resulted in significant credential theft and potential data loss across affected organizations. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely used development tools and libraries. The rapid succession and scale of these compromises highlight the need for enhanced vigilance and security measures within software development and deployment pipelines.
2 months ago
Kill Chain
ShinyHunters Ransomware Attack on Charter Communications - May 2026
In May 2026, the cybercriminal group ShinyHunters executed a ransomware attack against Charter Communications, Inc., a major U.S. telecommunications and cable company known for its Spectrum services. The attack involved unauthorized access to Charter's systems, leading to the encryption of critical data and disruption of services. ShinyHunters demanded a ransom for the decryption keys, threatening to leak sensitive customer and corporate information if their demands were not met. The breach was publicly disclosed on May 23, 2026, highlighting significant vulnerabilities in Charter's cybersecurity defenses. This incident underscores the escalating threat posed by sophisticated ransomware groups like ShinyHunters, who have been increasingly targeting large corporations across various sectors. The attack on Charter Communications serves as a stark reminder of the importance of robust cybersecurity measures and the need for organizations to proactively defend against evolving cyber threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports