Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 10 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 109120 / 3054 reports
CareCam Pro IP Cameras Expose Critical Bootloader Vulnerability CVE-2026-85083
Impact· MEDIUM

CareCam Pro IP Cameras Expose Critical Bootloader Vulnerability CVE-2026-85083

CISA disclosed CVE-2026-85083, a critical vulnerability in CareCam Pro IP cameras (model ANJIA AJL33PC0801) that exposes hard-coded credentials in the bootloader authentication system. Attackers with physical access can exploit this weakness to gain privileged bootloader access, enabling unauthorized firmware modification and complete device compromise. The vulnerability affects devices deployed worldwide across commercial facilities, with CareCam reportedly unresponsive to coordination efforts from CISA. This incident highlights the persistent security challenges in IoT infrastructure where manufacturers continue to implement insecure authentication mechanisms. As organizations increasingly rely on IP cameras for security monitoring and operational visibility, such fundamental design flaws create significant attack surface expansion and compliance risks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical AI Security Gap: DeepSeek Harness Sandbox Escape Exposes Autonomous Agent Risks
Impact· CRITICAL

Critical AI Security Gap: DeepSeek Harness Sandbox Escape Exposes Autonomous Agent Risks

In August 2026, a critical vulnerability (CVE-2026-82533) was discovered in DeepSeek Harness, an open-source AI coding agent tool with over 216,000 GitHub stars. The flaw allowed sandboxed AI agents to disable their own security sandbox through a single command, bypassing file system protections designed to prevent untrusted code execution. Attackers could exploit this by supplying malicious text that prompted the agent to call the tool's local web interface, switching to 'danger-full-access' mode without approval prompts. The vulnerability stemmed from inadequate authentication on the local interface and improper host header validation, enabling both local sandbox escapes and potential remote exploitation through port forwarding. This incident highlights the growing security challenges in AI development tools as organizations increasingly adopt autonomous coding agents. The vulnerability demonstrates how AI agents can be manipulated to bypass their own safety mechanisms, representing a new class of security risks in the rapidly expanding AI development ecosystem.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Massive Infostealer Campaign Exposes Thousands of AI Service Tokens, Bypassing MFA Protection
Impact· HIGH

Massive Infostealer Campaign Exposes Thousands of AI Service Tokens, Bypassing MFA Protection

In August 2026, cybersecurity researchers analyzed a 7GB infostealer dump containing data from 5,871 infected machines across 162 countries, revealing thousands of unexpired authentication tokens for AI services including Google, OpenAI, Anthropic, and others. Information stealers like Lumma Stealer and Vidar harvested session tokens, API keys, and JSON Web Tokens (JWTs) that threat actors can replay to bypass credential-based authentication and multi-factor authentication, effectively gaining unauthorized access to premium AI services without traditional login processes. The stolen data included 555 AI-related JWTs and 2,937 encrypted tokens, with 17.7% containing plaintext personally identifiable information, enabling account takeovers, resource theft, and unauthorized AI service usage sold on underground markets. This incident highlights the growing cybercriminal focus on AI credential theft as premium model access costs create strong financial incentives for stealing rather than purchasing legitimate access, while the proliferation of anti-detect browsers and session replay tools makes monetizing these stolen tokens increasingly accessible to threat actors.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's Record-Breaking Patch Tuesday: Managing 974 Vulnerabilities in the AI Era
Impact· HIGH

Microsoft's Record-Breaking Patch Tuesday: Managing 974 Vulnerabilities in the AI Era

Microsoft released its largest-ever Patch Tuesday update in September 2026, addressing 974 vulnerabilities across its product suite, including two actively exploited zero-day vulnerabilities. The massive security update included CVE-2026-81963 affecting the Windows Update Stack and CVE-2026-85880 affecting Windows Advanced Local Procedure Call, both enabling privilege escalation attacks. Microsoft's use of AI-assisted vulnerability discovery has dramatically increased the volume of disclosed vulnerabilities, with over 100 rated as critical across Windows, Office, SQL Server, and developer tools. Despite the record-breaking number of vulnerabilities, security researchers noted that active exploitation rates have not increased proportionally. This incident highlights the growing challenge organizations face in vulnerability management as AI-driven discovery tools uncover more security flaws at an unprecedented pace. The massive patch volume reflects broader industry trends where automated security research is creating larger attack surfaces while simultaneously improving defensive capabilities through faster identification of potential weaknesses.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's Record-Breaking Windows 10 Security Update: 966 Vulnerabilities Patched
Impact· LOW

Microsoft's Record-Breaking Windows 10 Security Update: 966 Vulnerabilities Patched

Microsoft released Windows 10 KB5122878 as part of the September 2026 extended security update program, addressing a record-breaking 966 vulnerabilities including two actively exploited zero-day flaws. This update targets Windows 10 Enterprise LTSC users and ESU program participants, bringing systems to build 19045.7725 with critical security patches, Secure Boot certificate improvements, and fixes for Remote Desktop audio redirection issues. The massive patch release underscores the ongoing security challenges facing legacy Windows environments as Microsoft phases out mainstream support. This update highlights the critical importance of extended security programs as organizations struggle to migrate from Windows 10 amid escalating cyber threats and the growing attack surface of unpatched legacy systems.

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
PoisonedRefresh Rootkit: Advanced Threat Targets F5 BIG-IP Infrastructure
Impact· CRITICAL

PoisonedRefresh Rootkit: Advanced Threat Targets F5 BIG-IP Infrastructure

In September 2026, security researchers discovered a sophisticated Linux rootkit campaign targeting F5 BIG-IP APM devices. Attackers exploited CVE-2025-53521, a critical remote code execution vulnerability, to deploy the 'PoisonedRefresh' rootkit that injects fileless web shells directly into memory. The malware intercepts PHP file operations, modifies scripts in memory without altering disk files, and creates password-protected backdoors while maintaining persistence across system upgrades. This advanced attack demonstrates the evolution of infrastructure targeting, as threat actors increasingly focus on critical network appliances that provide extensive access to organizational traffic and systems. With 795 vulnerable endpoints still exposed online, this incident highlights the urgent need for robust patch management and enhanced monitoring of network infrastructure devices.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ClickFix Campaigns Weaponize Trust: How Attackers Abuse Legitimate Services
Impact· MEDIUM

ClickFix Campaigns Weaponize Trust: How Attackers Abuse Legitimate Services

ClickFix campaigns represent a sophisticated social engineering attack vector where threat actors disguise malicious PowerShell scripts as legitimate software fixes or updates. These campaigns typically begin with phishing emails or compromised websites that present users with fake error messages, prompting them to copy and execute PowerShell commands that appear to resolve technical issues. The attacks leverage trusted platforms like GitHub, Discord, and legitimate cloud services to host malicious payloads, making detection more challenging for traditional security tools. Once executed, the malicious scripts establish persistent access through various techniques including scheduled tasks, registry modifications, and deployment of remote access tools, allowing attackers to maintain long-term presence in compromised environments. ClickFix campaigns have gained significant traction in 2024 as organizations increasingly adopt cloud-first strategies and remote work models, creating expanded attack surfaces that threat actors exploit through social engineering rather than traditional technical vulnerabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy
Impact· HIGH

Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy

In September 2026, Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. class action lawsuit involving over 10,000 users whose sensitive personal data, including HIV status, was shared with third-party advertising companies Apptimize and Localytics between 2018-2020. The incident, originally exposed by Norwegian research group SINTEF in April 2018, occurred while Grindr was owned by Chinese gaming company Kunlun, before its 2020 acquisition by San Vicente Acquisition LLC. The settlement covers historical data practices that violated U.K. privacy laws through unauthorized sharing of location data, sexual orientation, and medical information for commercial advertising purposes. This incident highlights the ongoing regulatory scrutiny of data privacy violations in dating apps and social platforms, particularly as GDPR enforcement intensifies and class action lawsuits become more prevalent in addressing historical privacy breaches involving sensitive personal information.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical FreeIPA Vulnerability Exposes Enterprise Authentication Infrastructure to Anonymous Attackers
Impact· CRITICAL

Critical FreeIPA Vulnerability Exposes Enterprise Authentication Infrastructure to Anonymous Attackers

In September 2026, Red Hat disclosed a critical vulnerability chain in FreeIPA (CVE-2026-76578) with a CVSS score of 9.8 that allows anonymous clients to create reusable administrator credentials without authentication. The flaw exploits a weakness in FreeIPA's access control rules combined with a secondary vulnerability in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass authentication mechanisms and gain administrative privileges on Linux domain controllers. Red Hat successfully reproduced the attack chain twice on default installations, demonstrating how unauthenticated attackers can inject Kerberos identities and obtain administrator group membership. This vulnerability highlights the growing sophistication of identity-based attacks targeting enterprise authentication infrastructure, particularly as organizations increasingly rely on centralized identity management systems for zero trust architectures and cloud-native environments.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
When AI Attacks AI: The 2026 Autonomous Agent Credential Harvesting Campaign
Impact· HIGH

When AI Attacks AI: The 2026 Autonomous Agent Credential Harvesting Campaign

In September 2026, threat actors deployed autonomous AI agent frameworks to conduct large-scale credential harvesting operations, compromising thousands of third-party credentials in under six hours. Google Threat Intelligence Group identified multiple financially motivated groups, including TeamPCP, leveraging AI-assisted tools like DUSTMAKER malware to target AI coding assistants, cloud environments, and supply chains across PyPI, npm, and Docker Hub repositories. The attacks demonstrated unprecedented automation capabilities, with AI systems autonomously managing vulnerability scanning, real-time troubleshooting, and IP rotation without human intervention. This incident represents a critical escalation in AI-enabled cyber threats, coinciding with the rapid adoption of generative AI tools in enterprise environments and the emergence of 'abliterated' open-weight models that bypass safety guardrails.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ChatGPT Prompt Injection Flaw Exposed Gmail Data Through Hidden Cross-Account Channels
Impact· HIGH

ChatGPT Prompt Injection Flaw Exposed Gmail Data Through Hidden Cross-Account Channels

In September 2026, Check Point Research disclosed a critical vulnerability in OpenAI's ChatGPT that allowed attackers to inject malicious prompts that could silently exfiltrate user data from connected applications like Gmail. The attack exploited a shared internal JFrog Artifactory service used by ChatGPT's isolated containers, creating an unauthorized communication channel between different user accounts. Attackers could plant instructions through shared conversations, custom GPTs, or user-pasted prompts that would execute hidden data theft operations while displaying normal responses to victims. OpenAI confirmed the vulnerability and took the internal service offline after disclosure. This incident highlights the emerging risks of AI systems as attack vectors, particularly as organizations increasingly integrate AI tools with sensitive business applications and data sources, making prompt injection attacks a critical new threat category requiring immediate security attention.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI Reasoning Traces Theft: The 2026 Vulnerability That Exposed AI's Hidden Thoughts
Impact· HIGH

AI Reasoning Traces Theft: The 2026 Vulnerability That Exposed AI's Hidden Thoughts

In 2026, security researchers discovered a critical vulnerability affecting major AI providers including OpenAI, Anthropic, and Google, where encrypted reasoning traces from large language models could be stolen and decoded. The attack exploited the interchangeable nature of encrypted reasoning blocks across different sessions and models, allowing adversaries to inject traces into weaker models to extract proprietary reasoning in plaintext. This vulnerability enabled four distinct attack vectors: circumventing anti-distillation mechanisms, large-scale private data extraction, revealing hidden hazardous information, and executing invisible prompt injections. Researchers successfully extracted 367 PII artifacts and 182 credentials from 315,320 reasoning blocks scraped from public repositories, demonstrating the significant privacy and security implications. This incident highlights the emerging risks in AI security as organizations increasingly deploy autonomous AI agents and rely on cloud-based AI services, making AI-specific vulnerabilities a critical new attack surface that traditional security measures may not adequately address.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports