✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Critical Vulnerability in ZKTeco CCTV Cameras: CVE-2026-8598
In May 2026, a critical vulnerability (CVE-2026-8598) was identified in ZKTeco CCTV cameras, specifically affecting the SSC335-GC2063-Face-0b77 model with firmware versions prior to V5.0.1.2.20260421. This flaw involved an undocumented configuration export port that lacked authentication, potentially exposing sensitive information such as camera account credentials and open services. Exploitation of this vulnerability could lead to unauthorized access and control over the affected devices. This incident underscores the importance of securing physical security devices, as they can serve as entry points for broader network compromises. Organizations are urged to promptly update their firmware to the latest version and implement robust network segmentation to mitigate such risks.
2 months ago
Kill Chain
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
In May 2026, a security researcher known as Nightmare-Eclipse publicly disclosed a vulnerability named 'YellowKey' (CVE-2026-45585) affecting Windows 11 and Windows Server 2025. This flaw allows attackers with physical access to bypass BitLocker encryption by exploiting the Windows Recovery Environment (WinRE), thereby gaining unauthorized access to encrypted data. The exploit involves placing specially crafted 'FsTx' files on a USB drive, booting into WinRE, and triggering an unrestricted shell with full access to the encrypted volume. The public disclosure of YellowKey highlights the ongoing risks associated with physical access attacks and underscores the importance of robust security measures beyond software-based protections. Organizations must reassess their physical security protocols and implement additional safeguards, such as requiring a PIN at startup, to mitigate such vulnerabilities.
2 months ago
Kill Chain
Axios npm Package Compromise: A 2026 Supply Chain Attack
In late March 2026, attackers compromised the npm account of a lead maintainer of Axios, a widely-used JavaScript HTTP client library. They published two malicious versions, `axios@1.14.1` and `axios@0.30.4`, which included a trojanized dependency named `plain-crypto-js`. This dependency executed a `postinstall` script that downloaded and installed a cross-platform Remote Access Trojan (RAT) targeting macOS, Windows, and Linux systems. The malicious packages were available for approximately three hours before being removed by npm. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/axios-npm-package-compromised-in-supply-chain-attack-that-deployed-a-cross-platform-rat?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting open-source software repositories. The rapid deployment and removal of the malicious packages highlight the need for vigilant monitoring and swift response mechanisms within the software development community.
2 months ago
Kill Chain
Typosquatting Supply Chain Attack 2026: A New Era of Cyber Threats
In December 2025, attackers exploited typosquatting techniques to embed AI-generated lookalike domains within legitimate third-party scripts running on web properties. This method allowed malicious code to execute in users' browsers without requiring mistyped URLs or server breaches, leading to significant data exfiltration and financial losses. The Trust Wallet incident exemplifies this trend, where a trojanized Chrome extension resulted in the theft of $8.5 million from 2,500 wallets within 48 hours. This incident underscores a critical shift in cyber threats, highlighting the vulnerability of supply chains to typosquatting attacks. The rapid generation of convincing domain variants by AI tools has outpaced traditional security measures, necessitating enhanced detection capabilities and vigilance in monitoring third-party scripts.
2 months ago
Kill Chain
GitHub Breach 2026: Understanding TeamPCP's Supply Chain Attack
In May 2026, GitHub experienced a significant security breach when an employee's device was compromised through a malicious Visual Studio Code extension. This intrusion allowed the threat actor known as TeamPCP to exfiltrate approximately 3,800 internal repositories containing proprietary source code and internal organizational data. TeamPCP subsequently listed this data for sale on a cybercrime forum, demanding a minimum of $50,000, with threats to release the information publicly if no buyer emerged. GitHub has stated that, as of now, there is no evidence indicating that customer data or external repositories were affected. This incident underscores the escalating threat posed by supply chain attacks targeting development environments. The use of compromised development tools to infiltrate organizations highlights the need for heightened vigilance and robust security measures within software development processes. Organizations must reassess their security protocols to mitigate the risks associated with such sophisticated attack vectors.
2 months ago
Kill Chain
Critical XSS Vulnerability in Kieback & Peter DDC Controllers: CVE-2026-4293
In May 2026, a cross-site scripting (XSS) vulnerability, identified as CVE-2026-4293, was discovered in Kieback & Peter DDC Building Controllers. This flaw allows attackers to execute malicious JavaScript in a victim's browser via the controller's web interface, potentially leading to unauthorized control over the browser. Affected models include DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e, and DDC520, with firmware versions up to 1.12.14 and 1.23.4, respectively. ([windowsforum.com](https://windowsforum.com/threads/kieback-peter-ddc-xss-advisory-patch-supported-controllers-isolate-legacy-ot.418939/?utm_source=openai)) This incident underscores the critical need for robust security measures in building automation systems, especially as such vulnerabilities can serve as entry points for broader network compromises. Organizations are urged to update firmware where possible and isolate legacy systems to mitigate potential risks.
2 months ago
Kill Chain
Microsoft Disrupts Fox Tempest's Malware-Signing Service
In May 2026, Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation run by the threat actor Fox Tempest. This operation exploited Microsoft's Artifact Signing system to generate fraudulent code-signing certificates, enabling cybercriminals to distribute malware that appeared legitimate. Fox Tempest's service was linked to various ransomware groups, including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249, facilitating attacks that compromised thousands of machines and networks worldwide. The disruption involved seizing domain names, websites, and Azure resources associated with Fox Tempest, effectively dismantling their infrastructure. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who increasingly abuse legitimate services to enhance the effectiveness of their attacks. The takedown of Fox Tempest highlights the critical need for continuous monitoring and rapid response to such threats, as well as the importance of strengthening verification processes to prevent the misuse of code-signing tools. ([blogs.microsoft.com](https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/?utm_source=openai))
2 months ago
Kill Chain
Mini Shai-Hulud 2026: Unveiling TeamPCP's npm Supply Chain Attack
In May 2026, the self-replicating malware campaign known as Mini Shai-Hulud resurfaced, compromising hundreds of npm packages. The threat actor, TeamPCP, utilized this campaign to autonomously spread malware, install persistent OS-level backdoors, and harvest sensitive credentials such as GitHub tokens, npm tokens, SSH keys, and cloud provider credentials. The malware executed upon package installation, affecting both local development environments and CI/CD pipelines, and propagated by republishing infected packages under legitimate maintainers' names. ([cyberscoop.com](https://cyberscoop.com/mini-shai-hulud-malware-npm-packages-compromised-again/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The ability of such malware to persist beyond standard remediation efforts, like package removal, highlights the need for comprehensive security measures, including thorough auditing of developer tools and CI/CD environments, to prevent unauthorized access and data exfiltration.
2 months ago
Kill Chain
Verizon's 2026 DBIR: A Wake-Up Call on Exploited Vulnerabilities and Ransomware
In 2025, Verizon's Data Breach Investigations Report (DBIR) analyzed over 22,000 breaches, revealing that exploited vulnerabilities became the primary initial access vector, accounting for 31% of incidents—up from 20% the previous year. This surge underscores the challenges organizations face in timely vulnerability management, with the median time to fully patch a vulnerability increasing to 43 days from 32 days in 2024. Additionally, ransomware incidents rose to 48% of breaches, highlighting the persistent threat posed by financially motivated cybercriminals. The report also noted a decline in the remediation of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog, with only 26% fully addressed by organizations in 2025, down from 38% in 2024. This trend emphasizes the need for enhanced vulnerability management practices and proactive security measures to mitigate the evolving cyber threat landscape.
2 months ago
Kill Chain
Critical Microsoft Vulnerabilities Doubled in 2025: A Call to Action
In 2025, Microsoft disclosed 1,273 vulnerabilities, a slight decrease from the previous year. However, critical vulnerabilities surged from 78 to 157, reversing a multi-year downward trend. Notably, Elevation of Privilege vulnerabilities accounted for 40% of all CVEs, and Information Disclosure flaws rose by 73%, indicating attackers' focus on stealth and reconnaissance. Cloud platforms like Azure and Dynamics 365 saw critical vulnerabilities jump from 4 to 37, highlighting the increasing risk in these environments. This trend underscores the need for organizations to prioritize vulnerabilities that enable privilege escalation, identity abuse, and lateral movement. Traditional patch management is insufficient; a comprehensive approach addressing excessive privileges, misconfigurations, and weak identity controls is essential to mitigate these evolving threats.
2 months ago
Kill Chain
Shai-Hulud Malware Compromises 600+ npm Packages in May 2026
In May 2026, a significant supply chain attack known as the Shai-Hulud campaign compromised over 600 npm packages, primarily targeting the @antv ecosystem. Threat actors infiltrated developer accounts to publish malicious versions of popular JavaScript libraries, including echarts-for-react, @antv/g2, and timeago.js. The malware harvested sensitive information from developer environments and CI/CD pipelines, exfiltrating data via encrypted channels to evade detection. This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the need for enhanced security measures in software development pipelines. The attackers' use of valid Sigstore provenance attestations to lend credibility to malicious packages represents a concerning evolution in attack methodologies, emphasizing the urgency for developers and organizations to implement robust verification processes and maintain vigilance against such sophisticated threats.
2 months ago
Kill Chain
Storm-2949's Exploitation of SSPR in Microsoft 365 and Azure Breach
In May 2026, the threat actor known as Storm-2949 executed a sophisticated attack targeting Microsoft 365 and Azure environments. Utilizing social engineering tactics, they impersonated IT support to exploit the Self-Service Password Reset (SSPR) feature, gaining unauthorized access to privileged accounts. This access enabled them to exfiltrate sensitive data from OneDrive, SharePoint, and Azure resources, including virtual machines, storage accounts, key vaults, app services, and SQL databases. The attackers leveraged legitimate administrative tools to blend into normal operations, complicating detection efforts. This incident underscores the evolving threat landscape where attackers increasingly exploit identity management systems and cloud services. Organizations must enhance their security protocols, particularly around identity verification and access controls, to mitigate such sophisticated attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports