✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Instructure Canvas Breach 2026: A Wake-Up Call for SaaS Security
In early May 2026, Instructure's Canvas learning management system suffered two significant breaches within a week, orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities in the 'Free-For-Teacher' accounts to gain unauthorized access, leading to the exfiltration of 3.65 terabytes of data from approximately 275 million users across nearly 9,000 institutions. The compromised data included names, email addresses, student ID numbers, and private messages. Following the breaches, ShinyHunters defaced Canvas login pages and demanded a ransom, which Instructure paid in exchange for assurances that the stolen data would be destroyed and not used for further extortion. ([techcrunch.com](https://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/?utm_source=openai)) This incident underscores the escalating threat landscape targeting educational platforms and the critical need for robust identity governance and data protection measures. The breaches highlight the vulnerabilities inherent in widely adopted SaaS platforms and the potential for significant operational disruptions and data privacy concerns when such systems are compromised.
2 months ago
Kill Chain
Tycoon2FA's New Tactics: Device-Code Phishing in Microsoft 365
In May 2026, the Tycoon2FA phishing kit was observed employing device-code phishing attacks to compromise Microsoft 365 accounts. This method involves tricking users into entering a device authorization code on Microsoft's legitimate login page, thereby granting attackers access to the victim's data and services. Despite a prior international law enforcement operation in March 2026 that disrupted Tycoon2FA's infrastructure, the platform quickly resumed operations with enhanced obfuscation techniques to evade detection. The resurgence and evolution of Tycoon2FA underscore the persistent and adaptive nature of phishing threats. The adoption of device-code phishing highlights the need for organizations to implement robust security measures, including user education and advanced threat detection systems, to mitigate the risks associated with such sophisticated attacks.
2 months ago
Kill Chain
Windows 'MiniPlasma' Zero-Day Exploit Grants SYSTEM Access
On May 17, 2026, cybersecurity researcher Chaotic Eclipse released a proof-of-concept exploit named 'MiniPlasma' that enables attackers to gain SYSTEM privileges on fully patched Windows systems. This exploit targets a vulnerability in the 'cldflt.sys' Cloud Filter driver, specifically the 'HsmOsBlockPlaceholderAccess' routine, which was initially reported in 2020 as CVE-2020-17103 and believed to have been patched in December 2020. However, the researcher discovered that the vulnerability remains exploitable, allowing for privilege escalation attacks. The release of this exploit underscores the critical importance of thorough patch validation and continuous security assessments. Organizations must remain vigilant, as previously addressed vulnerabilities can resurface, posing significant security risks. This incident highlights the necessity for robust vulnerability management practices to ensure the effectiveness of security patches.
2 months ago
Kill Chain
NGINX CVE-2026-42945: Critical Vulnerability Under Active Exploitation
In May 2026, a critical heap buffer overflow vulnerability, CVE-2026-42945, was disclosed in NGINX's ngx_http_rewrite_module, affecting versions 0.6.27 through 1.30.0. This flaw allows unauthenticated attackers to send specially crafted HTTP requests, potentially causing worker process crashes and, under certain conditions, remote code execution. The vulnerability stems from improper handling of unnamed PCRE captures combined with rewrite directives containing a question mark in the replacement string. ([thehackernews.com](https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html?utm_source=openai)) The public availability of a proof-of-concept exploit has heightened the risk of widespread attacks, especially given NGINX's extensive use across the internet. Organizations are urged to update to patched versions—NGINX Open Source 1.31.0 or 1.30.1, and NGINX Plus R37, R36 P4, or R32 P6—to mitigate potential threats. ([thehackernews.com](https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html?utm_source=openai))
2 months ago
Kill Chain
Critical Privilege Escalation Vulnerability in Microsoft Azure AKS Exposes Security Disclosure Challenges
In March 2026, security researcher Justin O'Leary identified a critical privilege escalation vulnerability in Microsoft Azure Kubernetes Service (AKS). This flaw allowed users with the 'Backup Contributor' role to gain cluster-admin access without prior Kubernetes permissions. Despite reporting the issue to Microsoft on March 17, the company rejected the report on April 13, claiming the behavior was expected and did not constitute a security vulnerability. Subsequently, O'Leary escalated the matter to the CERT Coordination Center, which validated the vulnerability and assigned it the identifier VU#284781. However, Microsoft intervened to prevent the issuance of a CVE, maintaining that no product changes were necessary. This incident underscores the challenges in vulnerability disclosure processes and the importance of transparent communication between researchers and vendors to ensure the security of cloud services.
2 months ago
Kill Chain
Claude Mythos: AI's Leap in Cybersecurity Threats
In April 2026, Anthropic unveiled Claude Mythos, an advanced AI model capable of autonomously identifying and exploiting thousands of high-severity vulnerabilities across major operating systems and web browsers. This AI demonstrated the ability to perform complex multi-step network attacks in significantly reduced timeframes, surpassing human capabilities in vulnerability discovery and exploitation. The emergence of such AI tools has raised substantial concerns within the cybersecurity community regarding the potential for accelerated cyberattacks and the need for enhanced defensive measures. The rapid advancement of AI in cybersecurity underscores the urgency for organizations to adapt their security strategies. Traditional defense mechanisms may no longer suffice against AI-driven threats, necessitating the adoption of automated defenses, improved vulnerability management, and architectural adaptations to mitigate the risks posed by these powerful AI capabilities.
2 months ago
Kill Chain
CI/CD Pipeline Attacks in 2025: Lessons Learned and Future Strategies
In 2025, a series of sophisticated cyberattacks targeted Continuous Integration and Continuous Deployment (CI/CD) pipelines, exploiting vulnerabilities within these automated software delivery systems. Attackers gained unauthorized access to build servers and developer environments, injecting malicious code that was seamlessly integrated into legitimate software releases. This method allowed adversaries to distribute malware widely, compromising numerous organizations and leading to significant data breaches and operational disruptions. The incidents underscored the critical need for enhanced security measures within CI/CD processes to prevent such supply chain attacks. These attacks highlight a growing trend where cybercriminals focus on the software supply chain, recognizing the potential to infiltrate multiple organizations through a single compromised pipeline. The increasing reliance on automated development tools necessitates a reevaluation of security protocols to safeguard against such pervasive threats.
2 months ago
Kill Chain
CISA Adds CVE-2026-42897 to Known Exploited Vulnerabilities Catalog
On May 14, 2026, Microsoft disclosed a critical cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises versions of Microsoft Exchange Server 2016, 2019, and Subscription Edition. This flaw allows unauthorized attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, which, when opened in Outlook Web Access (OWA), can lead to spoofing attacks. Microsoft has acknowledged active exploitation of this vulnerability in the wild and has provided temporary mitigations pending a permanent fix. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/15/exchange-server-cve-2026-42897-exploited/?utm_source=openai)) The exploitation of CVE-2026-42897 underscores the persistent threat posed by XSS vulnerabilities in widely used enterprise applications. Organizations relying on on-premises Exchange servers are at heightened risk, emphasizing the need for immediate implementation of Microsoft's recommended mitigations and vigilance against similar attack vectors targeting web-based email interfaces.
2 months ago
Kill Chain
Critical Zero-Day Vulnerability in Microsoft Exchange Server: CVE-2026-42897
In May 2026, Microsoft disclosed a high-severity vulnerability (CVE-2026-42897) in Exchange Server, affecting versions 2016, 2019, and Subscription Edition. This cross-site scripting (XSS) flaw allows attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, leading to potential spoofing attacks. Exploitation requires the recipient to open the email in Outlook Web Access (OWA) under specific conditions. Microsoft has confirmed active exploitation of this zero-day vulnerability in the wild. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai)) The urgency of this issue is underscored by the active exploitation of the vulnerability, highlighting the critical need for organizations to implement the provided mitigations promptly. The Exchange Emergency Mitigation Service (EEMS) offers automatic mitigation for affected on-premises servers, and administrators are advised to enable this service immediately to protect their systems. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai))
2 months ago
Kill Chain
Understanding the REMUS Infostealer: A 2026 Cybersecurity Threat
In early 2026, the REMUS infostealer emerged as a significant threat in the cybercrime landscape. Evolving from the Lumma Stealer family, REMUS introduced advanced capabilities such as session theft, targeting password managers, and utilizing blockchain-based command-and-control mechanisms. Its rapid development and commercialization reflect a shift towards malware-as-a-service (MaaS) models, enabling continuous updates and operational scalability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/?utm_source=openai)) The emergence of REMUS underscores the increasing sophistication of cyber threats, highlighting the need for organizations to enhance their security measures against evolving malware tactics and the growing prevalence of MaaS platforms.
2 months ago
Kill Chain
Node-ipc npm Package Compromised: A Wake-Up Call for Open-Source Security
In May 2026, malicious versions of the widely used node-ipc npm package were published, introducing credential-stealing malware into applications. The compromised versions—9.1.6, 9.2.3, and 12.0.1—contained obfuscated code that, upon execution, harvested sensitive information such as cloud credentials, SSH keys, and CI/CD secrets. This data was exfiltrated through DNS TXT queries to attacker-controlled infrastructure. The attack was facilitated by the compromise of a maintainer's account, allowing unauthorized publication of these malicious versions. ([stepsecurity.io](https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Developers and organizations must remain vigilant, implementing robust security measures to detect and prevent such compromises, as the reliance on third-party packages continues to grow.
2 months ago
Kill Chain
Pwn2Own Berlin 2026: Critical Zero-Day Exploits in Microsoft Exchange and Windows 11
During the second day of Pwn2Own Berlin 2026, security researchers demonstrated 15 unique zero-day vulnerabilities across multiple products, including Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux for Workstations. Notably, Cheng-Da Tsai of the DEVCORE Research Team earned $200,000 by chaining three bugs to achieve remote code execution with SYSTEM privileges on Microsoft Exchange. Additionally, Siyeon Wi exploited an integer overflow bug to hack Windows 11, and Ben Koo of Team DDOS escalated privileges to root on Red Hat Enterprise Linux for Workstations, earning $7,500 and $10,000 respectively. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/?utm_source=openai)) This incident underscores the persistent vulnerabilities in widely used enterprise software and highlights the critical need for organizations to prioritize timely patching and robust security measures to mitigate the risks associated with zero-day exploits.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports