✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
AI-Generated Phishing Attacks Surge in 2025
In 2025, cybercriminals significantly escalated their use of AI-generated phishing attacks, with 83% of phishing emails containing AI-generated content. This shift led to a 54% click rate on these emails, compared to 12% for traditional phishing attempts. The enhanced realism and personalization of these AI-driven attacks resulted in a 275% increase in phishing-related losses, totaling $70 billion annually, with small and medium-sized businesses being the primary targets. ([itpro.com](https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026?utm_source=openai)) The widespread adoption of AI in phishing campaigns underscores the urgent need for organizations to implement advanced, AI-driven email security solutions to detect and mitigate these sophisticated threats effectively.
4 months ago
Kill Chain
SmartApeSG Campaign 2026: Unveiling the ClickFix Multi-Stage Malware Attack
In March 2026, the SmartApeSG campaign employed the ClickFix technique to deliver a sequence of malware, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2). The attack began with a fake CAPTCHA page that tricked users into executing a malicious script, leading to the staged deployment of these remote access tools and information stealers over several hours. This multi-stage infection allowed attackers to establish persistent access and exfiltrate sensitive data from compromised systems. The SmartApeSG campaign underscores the evolving sophistication of social engineering tactics, particularly the use of ClickFix to bypass traditional security measures. Organizations must remain vigilant against such deceptive techniques, as they continue to be refined and pose significant threats to cybersecurity.
4 months ago
Kill Chain
DarkSword 2026 GitHub Leak: A New Era of iOS Exploits
In March 2026, a sophisticated iOS exploit framework known as DarkSword was leaked on GitHub, significantly lowering the barrier for cybercriminals to target iPhones. Originally utilized by nation-state actors, DarkSword exploits multiple vulnerabilities in iOS versions 18.4 to 18.7, enabling unauthorized access to sensitive user data. The public availability of this exploit has raised concerns about widespread attacks on hundreds of millions of iPhone users worldwide. The leak underscores a troubling trend where advanced hacking tools, once exclusive to government agencies, are increasingly accessible to a broader range of malicious actors. This development highlights the urgent need for users to update their devices promptly and for organizations to reassess their mobile security strategies to mitigate emerging threats.
4 months ago
Kill Chain
Yanluowang Ransomware Access Broker Sentenced to 81 Months
In March 2026, Russian national Aleksey Olegovich Volkov was sentenced to 81 months in prison for his role as an initial access broker for the Yanluowang ransomware group. Between July 2021 and November 2022, Volkov infiltrated at least eight U.S. companies' networks, selling access to ransomware operators who demanded ransoms ranging from $300,000 to $15 million. Volkov's activities resulted in significant financial and operational disruptions for the affected organizations. This case underscores the critical role of initial access brokers in the ransomware ecosystem and highlights the importance of robust cybersecurity measures to prevent unauthorized access. The sentencing also reflects increased international cooperation in prosecuting cybercriminals, signaling a stronger stance against such activities.
4 months ago
Kill Chain
Citrix 2025 CVE-2025-5777 Memory Overread Vulnerability
In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway, characterized by insufficient input validation leading to memory overread. This flaw allows unauthenticated attackers to extract sensitive information, including session tokens, from the memory of affected devices. Exploitation of this vulnerability can result in unauthorized access to systems and potential data breaches. Citrix released patches to address this issue and strongly urged customers to update their appliances promptly. ([support.citrix.com](https://support.citrix.com/external/article/CTX693420/netscaler-adc-and-netscaler-gateway-secu.html?utm_source=openai)) The urgency of addressing CVE-2025-5777 is underscored by active exploitation in the wild, with attackers leveraging this vulnerability to bypass authentication mechanisms. Organizations using affected Citrix products must prioritize patching to mitigate the risk of unauthorized access and data exfiltration. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/citrix-patches-vulns-netscaler-adc-gateway?utm_source=openai))
4 months ago
Kill Chain
TeamPCP's Exploitation of Checkmarx GitHub Actions: A 2026 Supply Chain Attack
In March 2026, the threat actor known as TeamPCP exploited misconfigured GitHub Actions workflows maintained by Checkmarx, specifically targeting the 'checkmarx/ast-github-action' and 'checkmarx/kics-github-action' repositories. By leveraging stolen continuous integration (CI) credentials, TeamPCP injected malicious code into these workflows, leading to unauthorized access and potential data exfiltration. This breach underscores the critical importance of securing CI/CD pipelines and the risks associated with exposed credentials in cloud-native environments. The incident highlights a growing trend of cybercriminals targeting development infrastructure to propagate attacks. Organizations must prioritize the security of their software supply chains, implement robust access controls, and continuously monitor for unauthorized activities to mitigate such threats.
4 months ago
Kill Chain
Yanluowang Ransomware Operator Sentenced to 6.75 Years in U.S. Prison
In March 2026, Russian national Aleksei Olegovich Volkov was sentenced to 6.75 years in U.S. federal prison for his role as an initial access broker for the Yanluowang ransomware group. Between July 2021 and November 2022, Volkov infiltrated at least eight U.S. companies, including financial institutions and engineering firms, providing unauthorized network access to the ransomware operators. This collaboration led to significant financial losses and operational disruptions for the affected organizations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/yanluowang-initial-access-broker-pleaded-guilty-to-ransomware-attacks/?utm_source=openai)) This case underscores the persistent threat posed by ransomware groups and their affiliates. Despite ongoing efforts to dismantle such operations, the involvement of skilled individuals like Volkov highlights the evolving tactics used to compromise corporate networks. Organizations must remain vigilant, continuously updating their cybersecurity measures to defend against sophisticated attacks.
4 months ago
Kill Chain
The Rise of AI-Powered Ransomware: A 2026 Threat Analysis
In early 2026, cybersecurity researchers identified a significant escalation in ransomware attacks leveraging artificial intelligence (AI). Threat actors utilized AI to automate reconnaissance, craft sophisticated phishing emails, and develop polymorphic malware capable of evading traditional detection methods. Notably, the 'PromptLock' ransomware employed local large language models to generate dynamic malicious scripts, enabling cross-platform attacks on Windows, macOS, and Linux systems. This AI-driven approach allowed attackers to rapidly identify vulnerabilities, exploit valid credentials, and execute data exfiltration and encryption operations with unprecedented speed and efficiency. The integration of AI into ransomware campaigns has dramatically reduced the time from initial compromise to full system encryption, with some attacks unfolding in mere minutes. This acceleration poses a critical challenge for organizations, as traditional security measures struggle to keep pace with the evolving threat landscape. The emergence of AI-powered ransomware underscores the urgent need for enhanced cybersecurity strategies that incorporate AI-driven defense mechanisms to effectively counter these sophisticated attacks.
4 months ago
Kill Chain
Trivy Supply Chain Attack Exposes Critical CI/CD Vulnerabilities
In March 2026, a sophisticated supply chain attack exploited the open-source security tool Trivy to infiltrate Continuous Integration/Continuous Deployment (CI/CD) pipelines. Attackers leveraged Trivy's integration within these pipelines to deploy an infostealer, exfiltrating sensitive assets such as cloud credentials, SSH keys, and API tokens. This breach underscores the vulnerabilities inherent in CI/CD environments, where trusted tools can become vectors for significant data exfiltration. This incident highlights a growing trend of adversaries targeting CI/CD pipelines to compromise software supply chains. As organizations increasingly rely on automated deployment processes, ensuring the security of these pipelines becomes paramount to prevent unauthorized access and data breaches.
4 months ago
Kill Chain
Emerging Threat: Rogue IP KVM Devices in 2026
In March 2026, security researchers identified a significant increase in the use of rogue IP-based Keyboard-Video-Mouse (KVM) devices by cybercriminals to gain unauthorized remote access to systems. These devices, when physically connected to target machines, allow attackers to control systems remotely, bypassing traditional network security measures. The exploitation of IP KVMs poses a substantial risk to organizations, as it enables persistent access and potential data exfiltration without detection by standard security tools. The current surge in rogue IP KVM usage underscores the evolving tactics of threat actors who are increasingly leveraging hardware-based attack vectors. This trend highlights the necessity for organizations to implement comprehensive physical security measures and to monitor for unauthorized hardware connections to mitigate such risks.
4 months ago
Kill Chain
AI-Driven Phishing Campaign Exploits Railway's Platform to Compromise Microsoft Cloud Accounts
In March 2026, a sophisticated phishing campaign exploited AI-generated lures to compromise Microsoft cloud accounts across hundreds of organizations. Attackers utilized Railway's Platform as a Service to deploy credential harvesting infrastructure, creating unique phishing emails that bypassed traditional security measures. The campaign targeted various sectors, including construction, law, healthcare, and government, leveraging Microsoft's device authentication flow to obtain OAuth tokens valid for up to 90 days without requiring passwords or multifactor authentication. This incident underscores the escalating use of AI in cyberattacks, enabling threat actors to scale operations and evade detection more effectively. Organizations must enhance their security protocols to address AI-driven threats and implement robust monitoring systems to detect and mitigate such sophisticated phishing campaigns.
4 months ago
Kill Chain
Handala Hackers Exploit Telegram for Malware Attacks in 2026
In March 2026, the FBI issued a warning about Iranian state-sponsored hackers, specifically the Handala group, utilizing Telegram as command-and-control infrastructure in malware attacks. These attacks targeted journalists critical of the Iranian government, dissidents, and opposition groups worldwide. The attackers employed social engineering tactics to infect Windows devices, enabling the exfiltration of screenshots and files from compromised systems. This activity led to intelligence collection, data leaks, and reputational harm to the victims. The incident underscores the evolving tactics of state-sponsored cyber actors, who are increasingly leveraging popular communication platforms like Telegram for malicious purposes. This trend highlights the need for heightened vigilance and robust cybersecurity measures to protect against sophisticated social engineering and malware deployment strategies.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports