The Containment Era is here. →Explore

Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

2571 threat reports
Page 89 of 215

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Health Care / Life Sciences Threat Reports

Showing 10571068 / 2571 reports
TeamPCP's 2026 Supply Chain Attack on LiteLLM: A Wake-Up Call for Open-Source Security
Impact· HIGH

TeamPCP's 2026 Supply Chain Attack on LiteLLM: A Wake-Up Call for Open-Source Security

In March 2026, the threat group TeamPCP executed a sophisticated supply chain attack targeting LiteLLM, a widely used Python package facilitating unified access to various large language models. By compromising LiteLLM's PyPI repository credentials—initially obtained through a prior breach of the Trivy security scanner—TeamPCP published malicious versions 1.82.7 and 1.82.8. These versions contained malware designed to harvest sensitive credentials, including SSH keys, cloud access tokens, and Kubernetes secrets, and to establish persistent backdoors within affected systems. The compromised packages were available for approximately three hours before removal, during which they were downloaded extensively, potentially impacting thousands of systems. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely adopted open-source tools integral to AI and cloud infrastructures. The rapid propagation and depth of access achieved by TeamPCP highlight the critical need for organizations to implement stringent security measures within their software development pipelines and to maintain vigilant monitoring of third-party dependencies.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
Impact· HIGH

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

In March 2026, an Iran-linked threat actor executed a coordinated password-spraying campaign targeting Microsoft 365 environments across Israel and the United Arab Emirates. The attacks occurred in three waves on March 3, 13, and 23, affecting over 300 organizations in Israel and more than 25 in the UAE. Primary targets included municipalities, technology firms, transportation, and healthcare sectors. Attackers utilized rotating Tor exit nodes for scanning and employed VPN services geolocated within Israel to bypass geo-fencing restrictions. Once valid credentials were obtained, they accessed and exfiltrated sensitive data, including personal emails. ([thehackernews.com](https://thehackernews.com/2026/04/iran-linked-password-spraying-campaign.html?utm_source=openai)) This incident underscores the escalating cyber threats in the Middle East, particularly those linked to nation-state actors. The use of password-spraying techniques highlights the critical need for robust authentication measures and vigilant monitoring to detect and mitigate unauthorized access attempts.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Germany Unmasks Leader of REvil and GandCrab Ransomware Groups
Impact· HIGH

Germany Unmasks Leader of REvil and GandCrab Ransomware Groups

In April 2026, German authorities identified 31-year-old Russian national Daniil Maksimovich Shchukin as 'UNKN,' the alleged leader of the notorious ransomware groups GandCrab and REvil. Between 2019 and 2021, Shchukin and his associate, 43-year-old Anatoly Sergeevitsch Kravchuk, reportedly executed at least 130 cyberattacks in Germany, extorting nearly €2 million and causing over €35 million in economic damages. These groups pioneered the double extortion tactic, demanding ransom for decrypting systems and additional payment to prevent data leaks. This revelation underscores the persistent threat posed by sophisticated ransomware operations and highlights the importance of international collaboration in combating cybercrime. Organizations must remain vigilant, as the identification of such key figures does not eliminate the risk of future attacks employing similar tactics.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
UAT-10608's Exploitation of React2Shell: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

UAT-10608's Exploitation of React2Shell: A Wake-Up Call for Cybersecurity

In early April 2026, a threat cluster identified as UAT-10608 launched a global credential theft campaign targeting public-facing Next.js applications vulnerable to the React2Shell flaw (CVE-2025-55182). Exploiting this pre-authentication remote code execution vulnerability, attackers deployed an automated tool named 'NEXUS Listener' to exfiltrate credentials, SSH keys, cloud tokens, and environment secrets from compromised systems. This campaign resulted in the compromise of at least 766 hosts across multiple industries and geographic regions. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/automated-credential-harvesting-campaign-react2shell?utm_source=openai)) The React2Shell vulnerability, disclosed in December 2025, allows unauthenticated attackers to execute arbitrary code on servers running vulnerable versions of React Server Components. Despite the availability of patches, many organizations have yet to update their systems, leaving them susceptible to such attacks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/?msockid=3159dd8396d16eca0085cb7697616f99&utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to update to version 7.4.7. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The rapid exploitation of CVE-2026-35616 underscores the increasing trend of attackers targeting endpoint management solutions to gain unauthorized access and control over enterprise networks. Organizations must prioritize timely patching and robust access controls to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182
Impact· CRITICAL

React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182

In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed, affecting React Server Components in versions 19.0.0 through 19.2.0. This flaw allowed unauthenticated remote code execution, enabling attackers to execute arbitrary JavaScript code on vulnerable servers. Exploiting this vulnerability, threat actors initiated a large-scale campaign targeting Next.js applications, compromising at least 766 hosts across various cloud providers. The attackers utilized an automated framework named NEXUS Listener to harvest sensitive data, including database credentials, SSH private keys, API keys, cloud tokens, and environment secrets. The operation was attributed to a threat cluster tracked as UAT-10608. ([articles.uvnetware.com](https://articles.uvnetware.com/news/react2shell-cve-2025-55182/?utm_source=openai)) The React2Shell incident underscores the critical importance of promptly addressing server-side vulnerabilities in widely used frameworks. The rapid exploitation by sophisticated threat actors highlights the need for organizations to implement robust security measures, including timely patching, comprehensive monitoring, and adherence to secure coding practices to mitigate the risk of similar attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency patches and advise immediate application of hotfixes or upgrading to version 7.4.7 upon its release. This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely patch management. Organizations are reminded to maintain robust security practices, including regular software updates and monitoring for unauthorized activities, to mitigate risks associated with such critical flaws.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In early April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, effectively bypassing API authentication and authorization mechanisms. The vulnerability has been actively exploited in the wild, prompting Fortinet to release out-of-band hotfixes and advise customers to upgrade to version 7.4.7 upon its release. ([thehackernews.com](https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html?utm_source=openai)) The exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting management interfaces to gain elevated privileges within enterprise environments. This incident highlights the critical need for organizations to promptly apply security patches and maintain vigilant monitoring of their network infrastructure to mitigate potential breaches.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Impact· CRITICAL

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

In April 2026, cybersecurity researchers identified 36 malicious npm packages masquerading as Strapi CMS plugins. These packages exploited Redis and PostgreSQL databases to deploy reverse shells, harvest credentials, and establish persistent implants. The malicious code was embedded within the postinstall script hook, executing upon installation without user interaction, thereby compromising systems with root access in CI/CD environments and Docker containers. The attackers utilized various payloads, including remote code execution via Redis, Docker container escapes, and credential harvesting, indicating a sophisticated and evolving threat. This incident underscores the escalating risks associated with software supply chain attacks, particularly within open-source ecosystems. The attackers' ability to infiltrate widely-used package repositories highlights the urgent need for enhanced security measures in software development pipelines. Organizations are advised to audit their dependencies, implement strict access controls, and monitor for anomalous activities to mitigate such threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 2026 Surge in Device Code Phishing Attacks
Impact· HIGH

Understanding the 2026 Surge in Device Code Phishing Attacks

In early 2026, device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant flow surged by over 37 times. Attackers initiated device authorization requests to service providers, obtained codes, and deceived victims into entering these codes on legitimate login pages, thereby granting unauthorized access to their accounts. This method, originally designed for devices lacking standard input options, was co-opted by cybercriminals to bypass traditional authentication mechanisms. The proliferation of phishing-as-a-service kits, notably EvilTokens, has significantly contributed to the widespread adoption of this technique, enabling even low-skilled attackers to execute sophisticated phishing campaigns. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/?utm_source=openai)) The rapid escalation of device code phishing underscores a critical shift in cyberattack strategies, emphasizing the need for organizations to reassess and fortify their authentication processes. The commoditization of such attack methods through services like EvilTokens highlights the urgency for enhanced security measures and user education to mitigate the risks associated with these evolving threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Surge in Multi-Extortion Ransomware Attacks in 2026
Impact· HIGH

Surge in Multi-Extortion Ransomware Attacks in 2026

In early 2026, the University of Mississippi Medical Center (UMMC) and payment processing network BridgePay were severely impacted by multi-extortion ransomware attacks. UMMC's Epic electronic health record system was taken offline across 35 clinics and over 200 telehealth sites, leading to the cancellation of critical medical procedures. Similarly, BridgePay's services were disrupted, affecting numerous financial transactions. These incidents underscore the escalating threat posed by ransomware groups employing double and triple extortion tactics, which involve encrypting data, exfiltrating sensitive information, and threatening public disclosure to pressure victims into paying ransoms. The increasing sophistication of these attacks highlights the urgent need for organizations to implement robust data encryption and access control measures to protect sensitive information and ensure rapid recovery in the event of a breach.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Insider Threat Extortion: Lessons from the 2023 Daniel Rhyne Case
Impact· HIGH

Insider Threat Extortion: Lessons from the 2023 Daniel Rhyne Case

In November 2023, Daniel Rhyne, a former core infrastructure engineer at a New Jersey-based industrial company, executed an unauthorized access to the company's network. Utilizing an administrator account, Rhyne altered passwords for 13 domain administrator accounts and 301 domain user accounts to 'TheFr0zenCrew!', effectively locking out legitimate users. He also scheduled tasks to change local administrator passwords on 3,284 workstations and 254 servers, and planned shutdowns of random servers and workstations over multiple days in December 2023. On November 25, Rhyne sent a ransom email demanding 20 Bitcoin (approximately $750,000 at the time), threatening to shut down 40 random servers daily over ten days if the ransom was not paid. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/man-admits-to-extortion-plot-locking-coworkers-out-of-thousands-of-windows-devices/amp/?utm_source=openai)) This incident underscores the persistent risk of insider threats, particularly from individuals with elevated access privileges. The case highlights the necessity for organizations to implement robust access controls, continuous monitoring, and comprehensive insider threat detection programs to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports