Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Understanding CVE-2026-31431: The 'Copy Fail' Linux Privilege Escalation Vulnerability
On April 29, 2026, researchers disclosed a critical local privilege escalation vulnerability in the Linux kernel, identified as CVE-2026-31431, commonly referred to as 'Copy Fail'. This flaw allows unprivileged local users to escalate their privileges to root across major Linux distributions released since 2017, including Ubuntu, Red Hat Enterprise Linux, and SUSE. The vulnerability stems from a logic error in the kernel's cryptographic subsystem, specifically within the algif_aead module of the AF_ALG interface, enabling attackers to modify the in-memory cache of privileged executable files without altering the physical files on disk. This issue is particularly concerning in environments such as Kubernetes clusters and multi-tenant hosts, where it can facilitate container escapes and compromise of shared resources. Given the availability of a reliable proof-of-concept exploit and active exploitation in the wild, organizations are urged to apply vendor-issued kernel updates immediately to mitigate the risk.
4 months ago
Kill Chain
New Rowhammer Attacks Compromise NVIDIA GPUs, Leading to Full System Control
In April 2026, independent research teams unveiled novel Rowhammer attacks targeting NVIDIA's Ampere-generation GPUs, specifically the RTX 3060 and RTX 6000 models. These attacks, named GDDRHammer and GeForge, exploit vulnerabilities in GDDR6 memory to induce bit flips, granting attackers arbitrary read/write access to CPU memory and leading to full system compromise. The attacks are particularly effective when IOMMU memory management is disabled, a common default in BIOS settings. ([arstechnica.com](https://arstechnica.com/security/2026/04/new-rowhammer-attacks-give-complete-control-of-machines-running-nvidia-gpus/?utm_source=openai)) The emergence of these GPU-focused Rowhammer attacks signifies a critical evolution in hardware-based vulnerabilities, extending beyond traditional CPU memory exploits. This development underscores the urgent need for enhanced security measures in GPU architectures, especially as GPUs play pivotal roles in cloud computing and AI applications. Organizations must reassess their hardware security protocols to mitigate these advanced threats.
4 months ago
Kill Chain
Latvian National Sentenced for Ransomware Attacks by Former Conti Leaders
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in prison for his role in a series of ransomware attacks orchestrated by former leaders of the Conti ransomware group. Between June 2021 and August 2023, Zolotarjovs and his co-conspirators extorted nearly $16 million from over 54 companies, employing multiple aliases such as Conti, Karakurt, Royal, TommyLeaks, SchoolBoys Ransomware, and Akira. Notably, Zolotarjovs pressured victims by threatening to leak sensitive data, including children's health records, to coerce ransom payments. ([cyberscoop.com](https://cyberscoop.com/latvian-russia-ransomware-conti-sentenced/?utm_source=openai)) This case underscores the persistent threat posed by rebranded ransomware groups and highlights the importance of robust cybersecurity measures. Organizations must remain vigilant against evolving tactics employed by cybercriminals, especially those targeting sensitive data to maximize leverage.
4 months ago
Kill Chain
Karakurt Extortion Gang Member Sentenced to 8.5 Years in Prison
In May 2026, Deniss Zolotarjovs, a Latvian national and member of the Russian Karakurt ransomware group, was sentenced to 8.5 years in prison in the United States. Operating under the alias "Sforza_cesarini," Zolotarjovs specialized in "cold case" negotiations, re-engaging with victims who had ceased communication without paying ransoms. Between August 2021 and November 2023, he was linked to at least six extortion cases against American organizations, contributing to over $56 million in losses, including approximately $2.8 million in ransom payments. His tactics included leveraging stolen personal and health information to intensify pressure on victims. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/?utm_source=openai)) This sentencing marks the first conviction of a Karakurt member in the U.S., potentially paving the way for further prosecutions within the group. The case underscores the persistent threat posed by ransomware and extortion groups, highlighting the necessity for robust cybersecurity measures and international cooperation in combating cybercrime. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/?utm_source=openai))
4 months ago
Kill Chain
CloudZ Malware Exploits Microsoft Phone Link to Steal SMS and OTPs
In May 2026, cybersecurity researchers identified a new variant of the CloudZ remote access tool (RAT) that employs a malicious plugin named Pheno to exploit Microsoft's Phone Link application. This malware monitors active Phone Link sessions on Windows 10 and 11 systems, accessing the application's local SQLite database to intercept SMS messages and one-time passwords (OTPs) without compromising the associated mobile device. The attack chain begins with a fake ScreenConnect update, leading to the deployment of a Rust-based loader, followed by a .NET loader that installs CloudZ RAT and establishes persistence via a scheduled task. The .NET loader includes anti-analysis checks to evade detection. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/?utm_source=openai)) This incident underscores the evolving tactics of threat actors who are increasingly targeting desktop applications that bridge connections to mobile devices. By compromising the Phone Link application, attackers can bypass traditional mobile security measures and directly access sensitive authentication codes, highlighting the need for enhanced security protocols in cross-device applications. ([csoonline.com](https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html?utm_source=openai))
4 months ago
Kill Chain
Critical Spring Security Vulnerability CVE-2026-22732: What You Need to Know
In March 2026, a critical vulnerability identified as CVE-2026-22732 was discovered in Spring Security versions 5.7.0 through 7.0.3. This flaw causes HTTP response headers specified for servlet applications to be omitted, potentially exposing applications to attacks such as Cross-Site Scripting (XSS) and clickjacking. The vulnerability affects applications using the default lazy writing of HTTP headers, leading to the absence of essential security headers in responses. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai)) The omission of these headers undermines client-side protections, increasing the risk of sensitive data exposure and other security breaches. Organizations utilizing affected versions of Spring Security are urged to upgrade to the latest patched versions or apply recommended workarounds to mitigate this risk. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai))
4 months ago
Kill Chain
DAEMON Tools Supply Chain Attack: A Wake-Up Call for Software Security
In April 2026, a sophisticated supply chain attack compromised the official installers of DAEMON Tools, a widely used virtual drive emulation software. Attackers injected malicious code into the software's installers, which were distributed from the legitimate DAEMON Tools website and signed with valid digital certificates. This allowed the malware to execute arbitrary commands and remotely control infected devices. The compromised versions, ranging from 12.5.0.2421 to 12.5.0.2434, have been in circulation since April 8, 2026. The attack has affected users in over 100 countries, with significant impacts in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Approximately 10% of the affected systems belong to businesses and organizations, exposing enterprise networks to severe risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software is exploited to distribute malware. The DAEMON Tools compromise highlights the need for organizations to implement stringent software procurement protocols, conduct regular security audits, and enforce strict administrative privileges to mitigate such risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai))
4 months ago
Kill Chain
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
In May 2026, the Apache Software Foundation disclosed a critical vulnerability (CVE-2026-23918) in Apache HTTP Server version 2.4.66, involving a double-free error in the HTTP/2 protocol handling. This flaw allows attackers to execute denial-of-service attacks and potentially achieve remote code execution by sending specific HTTP/2 frames. The issue was identified by researchers Bartlomiej Dmitruk and Stanislaw Strzalkowski and has been addressed in version 2.4.67. Organizations using affected versions are urged to upgrade immediately to mitigate the risk. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-23918?utm_source=openai)) The widespread adoption of HTTP/2 and the default inclusion of mod_http2 in many deployments amplify the urgency of this vulnerability. Exploitation could lead to significant service disruptions and unauthorized access, underscoring the importance of prompt patching and vigilant monitoring of server configurations.
4 months ago
Kill Chain
Unitree Go1 Robot Backdoor Vulnerability Exposes Critical Security Flaws
In March 2025, security researchers uncovered a critical backdoor vulnerability in Unitree Robotics' Go1 quadruped robot, designated as CVE-2025-2894. This flaw allowed unauthorized remote control of the robots via the CloudSail service, posing significant risks to operational integrity and safety. Exploiting this backdoor, attackers could access live camera feeds, manipulate robot movements, and potentially exfiltrate sensitive data without the operator's knowledge. The discovery highlighted the urgent need for robust security measures in the rapidly evolving field of embodied AI systems. The incident underscores the growing cybersecurity challenges associated with integrating autonomous robots into critical workflows. As these systems become more prevalent, ensuring their security against unauthorized access and control is paramount to prevent potential operational disruptions and data breaches.
4 months ago
Kill Chain
VENOMOUS#HELPER: Phishing Campaign Leveraging RMM Tools Targets 80+ Organizations
Since April 2025, the VENOMOUS#HELPER phishing campaign has targeted over 80 organizations, primarily in the United States, by exploiting legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—to establish persistent remote access. Attackers initiate the campaign with phishing emails impersonating the U.S. Social Security Administration, leading victims to download malicious executables that install these RMM tools, thereby bypassing traditional security defenses. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai)) This incident underscores a growing trend of cybercriminals leveraging trusted software to evade detection, highlighting the need for organizations to scrutinize the use of legitimate tools within their networks and enhance employee awareness to recognize sophisticated phishing attempts. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai))
4 months ago
Kill Chain
Microsoft Edge's Cleartext Password Storage: A Security Wake-Up Call
In May 2026, security researcher Tom Jøran Sønstebyseter Rønning disclosed that Microsoft Edge decrypts and stores all saved user passwords in cleartext within process memory upon browser launch, retaining them throughout the session. This design allows attackers with administrative privileges to access these credentials, posing significant risks in shared and enterprise environments. Microsoft confirmed this behavior is intentional, stating it is 'by design.' This incident underscores the critical need for organizations to reassess their reliance on browser-based password storage solutions. The exposure of credentials in memory highlights vulnerabilities that can be exploited, emphasizing the importance of adopting dedicated password management tools and implementing robust security policies to mitigate such risks.
4 months ago
Kill Chain
Microsoft Phishing Campaign April 2026: A Deep Dive into AiTM Credential Theft
In April 2026, Microsoft identified a sophisticated phishing campaign that targeted over 35,000 users across 13,000 organizations in 26 countries, with 92% of the targets located in the United States. The attackers employed code of conduct-themed lures, using polished HTML templates and legitimate email services to enhance credibility. Victims were directed through multiple CAPTCHA and intermediate pages, culminating in adversary-in-the-middle (AiTM) phishing tactics that harvested Microsoft credentials and authentication tokens, effectively bypassing multi-factor authentication (MFA). The campaign primarily targeted sectors such as healthcare, financial services, professional services, and technology. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=openai)) This incident underscores the evolving sophistication of phishing attacks, highlighting the need for organizations to enhance their security measures. The use of legitimate services and advanced techniques like AiTM phishing to bypass MFA indicates a significant escalation in threat actor capabilities, necessitating continuous vigilance and adaptation of security protocols. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports