✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Tycoon2FA Phishing Platform Resurfaces After Law Enforcement Takedown
In early March 2026, an international law enforcement operation coordinated by Europol disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform responsible for tens of millions of phishing emails monthly. The operation led to the seizure of 330 domains integral to Tycoon2FA's infrastructure, including control panels and phishing pages. Despite this significant intervention, the platform resumed its operations within days, returning to pre-disruption activity levels. Tycoon2FA employs adversary-in-the-middle techniques to bypass multi-factor authentication (MFA), enabling cybercriminals to compromise accounts across various sectors, including government institutions, schools, and healthcare organizations. The platform's resilience underscores the challenges in permanently dismantling sophisticated cybercrime services. The swift resurgence of Tycoon2FA highlights the adaptability of cybercriminal networks and the limitations of infrastructure-focused takedown efforts. This incident emphasizes the need for comprehensive strategies that include legal actions against operators and continuous monitoring to effectively combat persistent cyber threats.
4 months ago
Kill Chain
Quest KACE SMA Authentication Bypass Exploited in 2026
In March 2026, threat actors exploited a critical authentication bypass vulnerability (CVE-2025-32975) in unpatched Quest KACE Systems Management Appliances (SMA). This flaw, residing in the Single Sign-On (SSO) mechanism, allowed attackers to impersonate legitimate users without valid credentials, leading to potential administrative control over affected systems. The vulnerability was initially identified in June 2025, with patches released shortly thereafter. However, organizations that delayed applying these updates remained susceptible to exploitation. This incident underscores the persistent risk posed by unpatched vulnerabilities, even after fixes are made available. It highlights the importance of timely patch management and continuous monitoring to prevent exploitation of known security flaws.
4 months ago
Kill Chain
AWS Bedrock SCP Bypass Vulnerability Resolved in 2026
Between December 4, 2025, and January 26, 2026, AWS Bedrock experienced a security vulnerability where Service Control Policies (SCPs) were not fully enforced when using long-term API keys on the bedrock-mantle endpoint. This flaw allowed unauthorized actions that could bypass established security controls. AWS has since resolved the issue and confirmed that no customers were impacted. ([sonraisecurity.com](https://sonraisecurity.com/blog/cracks-in-the-bedrock/?utm_source=openai)) This incident underscores the critical importance of continuous monitoring and timely patching in cloud environments. Organizations must remain vigilant to ensure that security policies are effectively enforced to prevent potential breaches.
4 months ago
Kill Chain
North Korean Hackers Exploit VS Code to Infiltrate Developer Systems
In January 2026, North Korean state-sponsored hackers, notably the Lazarus Group, launched a campaign targeting software developers by distributing malicious Visual Studio Code (VS Code) projects. These projects, often shared via platforms like GitHub and GitLab, contained manipulated task configuration files that, upon opening and granting trust in VS Code, executed obfuscated JavaScript code. This code established backdoors on macOS systems, enabling remote code execution, system fingerprinting, and continuous communication with command-and-control servers. The attackers employed social engineering tactics, posing as recruiters offering fake job opportunities to lure developers into cloning and opening these repositories. This method allowed the malware to blend seamlessly into standard development workflows, making detection challenging. The campaign's sophistication underscores the evolving tactics of DPRK-linked threat actors, who consistently adapt their methods to exploit legitimate developer tools and processes. ([securityweek.com](https://www.securityweek.com/north-korean-hackers-target-macos-developers-via-malicious-vs-code-projects/?utm_source=openai))
4 months ago
Kill Chain
Phishing Campaign Targets Multiple Sectors with Advanced Evasion Techniques
In early 2026, a sophisticated phishing campaign targeted the healthcare, government, hospitality, and education sectors across multiple countries. Attackers employed advanced evasion techniques, including the use of hidden text and zero-font tactics, to bypass traditional email security measures. The campaign involved sending emails that appeared to be from legitimate sources, such as internal IT departments or trusted vendors, tricking recipients into clicking malicious links or downloading malware. Once compromised, attackers gained unauthorized access to sensitive information, leading to data breaches and operational disruptions. This incident underscores the increasing sophistication of phishing attacks and the need for organizations to enhance their cybersecurity defenses. The use of advanced evasion techniques highlights the importance of continuous monitoring, employee training, and the implementation of multi-factor authentication to mitigate such threats.
4 months ago
Kill Chain
Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering
In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.
4 months ago
Kill Chain
VoidStealer Malware Exploits Debugger Trick to Bypass Chrome's Encryption
In March 2026, the VoidStealer malware emerged, employing a novel technique to bypass Google Chrome's Application-Bound Encryption (ABE). By utilizing hardware breakpoints, VoidStealer extracts the v20_master_key directly from the browser's memory during decryption operations, allowing it to access sensitive data such as cookies and stored passwords without requiring privilege escalation or code injection. This method represents a significant advancement in infostealer capabilities, as it circumvents security measures introduced in Chrome 127 to protect user data. The emergence of VoidStealer underscores the continuous evolution of malware tactics in response to browser security enhancements. Organizations must remain vigilant, as threat actors rapidly adapt to new defenses, developing sophisticated methods to access protected information. This incident highlights the importance of implementing comprehensive security strategies that go beyond relying solely on browser-based protections.
4 months ago
Kill Chain
Trivy Supply Chain Attack Leads to CanisterWorm Infection in 47 npm Packages
In March 2026, a sophisticated supply chain attack targeted the Trivy vulnerability scanner, leading to the compromise of 47 npm packages through a self-propagating worm named CanisterWorm. The attackers infiltrated Trivy's codebase, embedding malicious code that, upon execution, harvested developer credentials and propagated itself by injecting into other npm packages. This resulted in widespread exposure of sensitive information and potential unauthorized access to numerous development environments. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The use of self-replicating malware like CanisterWorm highlights the need for enhanced security measures, including rigorous code audits, robust access controls, and continuous monitoring of software dependencies to mitigate the risk of similar attacks in the future.
4 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager (CVE-2025-61757)
In October 2025, Oracle disclosed a critical vulnerability (CVE-2025-61757) in Oracle Identity Manager, a key component of Oracle Fusion Middleware. This flaw, with a CVSS score of 9.8, allows unauthenticated remote code execution via HTTP, enabling attackers to fully compromise affected systems. The vulnerability arises from missing authentication checks in the REST WebServices component, permitting unauthorized access and control over the Identity Manager. ([hipaajournal.com](https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/?utm_source=openai)) The exploitation of this vulnerability has been observed in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog and mandate federal agencies to apply patches by December 12, 2025. Organizations using Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are urged to apply the October 2025 Critical Patch Update immediately to mitigate potential risks. ([securityweek.com](https://www.securityweek.com/cisa-confirms-exploitation-of-recent-oracle-identity-manager-vulnerability/?utm_source=openai))
4 months ago
Kill Chain
Oracle Fusion Middleware 2026 Critical RCE Vulnerability
In January 2026, Oracle disclosed a critical remote code execution (RCE) vulnerability, CVE-2026-21962, affecting Oracle Fusion Middleware components, including Oracle HTTP Server and WebLogic Server Proxy Plug-ins. This flaw allows unauthenticated attackers with network access via HTTP to compromise affected servers, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of the affected components. Oracle released patches as part of their January 2026 Critical Patch Update to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unauthenticated RCE flaws in widely used enterprise software. Organizations are urged to apply the provided patches promptly to mitigate potential risks associated with this vulnerability.
4 months ago
Kill Chain
Ubiquiti UniFi Access Vulnerability: Unauthenticated API Exposure
In October 2025, Ubiquiti's UniFi Access Application was found to have a critical vulnerability (CVE-2025-52665) that exposed a management API without proper authentication. This flaw, present in versions 3.3.22 through 3.4.31, allowed attackers with access to the management network to gain unauthorized control over door access systems, posing significant risks to physical security. Ubiquiti addressed the issue by releasing version 4.0.21, which rectified the misconfiguration. This incident underscores the importance of promptly updating software to mitigate security vulnerabilities. Organizations are advised to review their access control systems and ensure that all applications are updated to the latest secure versions to prevent unauthorized access and potential breaches.
4 months ago
Kill Chain
Cisco FMC 2026: Interlock Ransomware's Exploitation of Insecure Deserialization
In early 2026, a critical vulnerability (CVE-2026-20131) was discovered in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allowed unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. The Interlock ransomware group actively exploited this vulnerability as a zero-day since late January 2026, targeting several high-profile organizations, including DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota. The exploitation of CVE-2026-20131 underscores the persistent threat posed by sophisticated ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching and robust security measures to mitigate such risks.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports