Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 12 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 133144 / 3054 reports
Critical VMware VM Escape Vulnerability CVE-2026-59346: Security Analysis and Response
Impact· CRITICAL

Critical VMware VM Escape Vulnerability CVE-2026-59346: Security Analysis and Response

Broadcom patched two critical vulnerabilities in VMware Workstation and Fusion in September 2026, including CVE-2026-59346 (CVSS 9.3), an integer overflow flaw allowing local attackers with elevated VM privileges to execute arbitrary code on the host system. The second vulnerability, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow in HGFS that enables code execution as the VMX process. Both flaws affect versions 25H2 and 26H1, requiring administrative access within a guest VM for exploitation, though such privileges can be obtained through separate compromise vectors like phishing or weak configurations. This incident highlights the continued targeting of VMware infrastructure by threat actors, following recent active exploitation of vCenter vulnerabilities by suspected China-nexus APT groups that compromised 361 unique victims across 47 countries within days of public disclosure.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Flags Critical Chrome V8 Vulnerability CVE-2026-85046 for Active Exploitation
Impact· HIGH

CISA Flags Critical Chrome V8 Vulnerability CVE-2026-85046 for Active Exploitation

CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog on September 4, 2026, based on evidence of active exploitation. Type confusion vulnerabilities in browser engines allow attackers to bypass memory protections and achieve arbitrary code execution, making them highly valuable for threat actors targeting end users. The vulnerability poses significant risks to federal enterprises and requires immediate patching under BOD 26-04. Browser-based attacks continue to represent a critical threat vector as organizations increasingly rely on web applications and remote work environments. V8 engine vulnerabilities are particularly concerning due to Chrome's widespread adoption and the potential for supply chain attacks through compromised websites.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft Warns of Critical Security Gaps in Edge AI Deployments
Impact· MEDIUM

Microsoft Warns of Critical Security Gaps in Edge AI Deployments

Microsoft published a comprehensive security advisory in September 2024 addressing critical vulnerabilities in Edge AI deployments where machine learning models execute on customer-owned infrastructure. The advisory highlights fundamental security model changes when AI systems move from centralized cloud services to edge environments, exposing organizations to prompt injection attacks, model tampering, and malicious firmware updates. Customer-owned Edge AI deployments face increased attack surfaces as models, credentials, and sensitive data operate in potentially hostile environments outside cloud providers' direct security controls. This advisory emerges as organizations rapidly adopt Edge AI for cost optimization, data sovereignty, and reduced latency, creating new attack vectors that traditional software security controls cannot adequately address.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Chrome Zero-Day CVE-2026-85046: Enterprise Defense Against Browser Exploitation
Impact· HIGH

Chrome Zero-Day CVE-2026-85046: Enterprise Defense Against Browser Exploitation

In September 2026, Google patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome's V8 JavaScript engine that was actively exploited in the wild. The zero-day flaw, discovered by security researcher Salvatore Gulizia, could be triggered through specially crafted HTML pages containing malicious JavaScript, potentially enabling remote code execution within Chrome's sandboxed renderer process. This marked the sixth actively exploited Chrome zero-day patched by Google in 2026, highlighting an escalating pattern of browser-based attacks targeting the widely-used V8 engine across multiple incidents throughout the year. This incident underscores the current surge in browser exploitation campaigns as attackers increasingly target client-side vulnerabilities to establish initial access, particularly through JavaScript engines that process untrusted web content at scale across millions of users daily.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CrowdStrike FalconFlank Zero-Day Exposes Critical Endpoint Security Risks
Impact· HIGH

CrowdStrike FalconFlank Zero-Day Exposes Critical Endpoint Security Risks

In September 2026, security researcher 'Nightmare Eclipse' disclosed FalconFlank, a zero-day privilege escalation vulnerability affecting CrowdStrike Falcon's endpoint security platform on Windows 11 and Windows Server systems. The exploit abuses the Office malicious macros remediation feature to spawn command prompts with SYSTEM privileges, allowing attackers to gain administrative control over protected endpoints. CrowdStrike acknowledged the vulnerability and advised customers to disable the Microsoft Office File Suspicious Macro Removal policy setting while maintaining protection through Cloud Anti-malware settings. This disclosure was part of a broader campaign by the researcher targeting multiple security vendors including Kaspersky, Avast, and Nvidia with similar zero-day exploits. The incident highlights ongoing challenges in endpoint security software becoming attack vectors themselves, particularly as organizations increasingly rely on comprehensive security suites for protection.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
39 New Attack Methods Compromise Passkey Authentication Security
Impact· MEDIUM

39 New Attack Methods Compromise Passkey Authentication Security

Security researchers have documented 39 distinct methods for compromising passkey authentication systems, revealing critical vulnerabilities in the infrastructure surrounding FIDO2 cryptography. These attack vectors include assertion mining, prompt flooding, credential interface deception, synced vault compromise, and malicious enrollment processes. While the core FIDO2 cryptography remains intact, attackers are successfully exploiting weaknesses in browsers, operating systems, cloud synchronization services, and user interfaces to bypass authentication controls. This research highlights the urgent need for enterprises to reassess their passwordless authentication strategies, as attackers are increasingly targeting the ecosystem around passkeys rather than the cryptographic protocols themselves.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Citrix NetScaler Authentication Bypass Under Active Exploitation
Impact· HIGH

Critical Citrix NetScaler Authentication Bypass Under Active Exploitation

In September 2026, attackers began exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler appliances configured as AAA virtual servers or Gateway services. Security researchers at Previdian detected exploitation attempts from Australia, United States, and Germany targeting this flaw that allows unprivileged threat actors to bypass authentication remotely. With over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online according to Shadowserver, this represents a significant attack surface for organizations relying on these critical infrastructure components. This incident highlights the accelerating timeline between vulnerability disclosure and active exploitation, as attackers quickly weaponized publicly available proof-of-concept code. The pattern mirrors previous Citrix vulnerabilities that have been extensively abused by ransomware groups, making immediate patching critical for preventing potential breaches.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Recorded Future's AI-Powered Signature Creation Transforms Vulnerability Defense
Impact· HIGH

Recorded Future's AI-Powered Signature Creation Transforms Vulnerability Defense

Recorded Future announced Automated Signature Creation within their Attack Surface Intelligence (ASI) platform to combat AI-accelerated vulnerability exploitation. The capability automatically generates detection signatures for newly discovered vulnerabilities in as little as 31 minutes, addressing the dramatic reduction in exploit timelines from 45 days in 2010 to mere hours in 2025. This development responds to AI models now capable of automatically discovering zero-day vulnerabilities in major systems, a capability previously limited to advanced government cyber units. This advancement is particularly relevant as organizations face an unprecedented acceleration in threat actor capabilities driven by AI automation. The weaponization timeline for vulnerabilities has compressed dramatically, making traditional manual signature creation processes inadequate for modern defense requirements.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Zero Trust Stopped ShinyHunters: The ReliaQuest Vishing Attack Analysis
Impact· LOW

How Zero Trust Stopped ShinyHunters: The ReliaQuest Vishing Attack Analysis

In September 2026, the notorious ShinyHunters threat group targeted ReliaQuest through a vishing attack that compromised an employee's credentials via a fake single sign-on (SSO) page. The attackers gained limited read-only access to ReliaQuest's Okta SSO portal and taunted the cybersecurity vendor on social media with screenshots of the compromised system. However, ReliaQuest's zero trust security controls successfully prevented lateral movement and blocked access to sensitive applications or data, demonstrating effective breach containment despite the initial compromise. This incident highlights the evolving sophistication of social engineering attacks and the critical importance of implementing robust zero trust architectures that assume breach scenarios and limit post-compromise damage through strict access controls and continuous verification.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Mythos 5 AI Demonstrates Autonomous Cyber Attacks: The 6-Month Countdown Begins
Impact· LOW

Mythos 5 AI Demonstrates Autonomous Cyber Attacks: The 6-Month Countdown Begins

In September 2026, Booz Allen Hamilton confirmed that Anthropic's Mythos 5 AI model achieved autonomous end-to-end network compromise capabilities, scoring 80 on their new Cyber Weapon Index. The model successfully executed complete attack chains without human intervention, demonstrating reconnaissance, exploitation, and lateral movement across production-grade enterprise networks. This milestone represents a fundamental shift in cybersecurity threats, as AI-powered attacks can now operate at machine speed and scale, compressing traditional multi-week attack timelines into days or hours. The emergence of autonomous AI attackers marks a critical inflection point where traditional human-speed defenses become inadequate against machine-speed offensive operations.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
The AI Vulnpocalypse: How Machine Learning Is Exposing Hidden Security Flaws at Scale
Impact· MEDIUM

The AI Vulnpocalypse: How Machine Learning Is Exposing Hidden Security Flaws at Scale

The cybersecurity industry is experiencing an unprecedented surge in vulnerability discovery driven by AI-powered research tools, dubbed the 'vulnpocalypse.' Large language models have automated and accelerated bug hunting processes, with platforms like HackerOne reporting doubled vulnerability reports year-over-year. This has overwhelmed software vendors' remediation capabilities, creating massive backlogs with critical vulnerabilities increasing 30-fold in some cases. The phenomenon exposes fundamental secure-by-design failures across the software industry, as AI doesn't sleep and can systematically find vulnerabilities at scale that were previously hidden. The AI-driven vulnerability discovery revolution is reshaping the economics of cybersecurity, forcing a reckoning with decades of insecure software development practices. Organizations are struggling to adapt their disclosure processes and remediation workflows to handle the exponential increase in discovered vulnerabilities, creating new bottlenecks in the security ecosystem.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Chrome V8 Zero-Day CVE-2026-85046: Critical Browser Security Incident Analysis
Impact· CRITICAL

Chrome V8 Zero-Day CVE-2026-85046: Critical Browser Security Incident Analysis

Google patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome's V8 JavaScript engine, actively exploited in the wild. The zero-day flaw allowed remote attackers to execute arbitrary code through crafted HTML pages, representing the sixth Chrome zero-day addressed by Google in 2026. Security researcher Salvatore Gulizia discovered the bug in V8's compilers that led to array element type confusion, enabling arbitrary read/write operations on the JavaScript heap. This incident highlights the continued targeting of browser engines by threat actors seeking code execution capabilities through web-based attack vectors, emphasizing the critical importance of rapid patch deployment for client-side security vulnerabilities.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports