Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
n8n Webhooks Exploited in Phishing Campaigns Since October 2025
In October 2025, threat actors began exploiting n8n, a widely-used AI workflow automation platform, to conduct sophisticated phishing campaigns. By creating malicious webhooks on n8n's trusted infrastructure, attackers were able to bypass traditional security filters and deliver malware or perform device fingerprinting through automated emails. This abuse allowed them to distribute malicious payloads and gather sensitive information from targeted devices. ([thehackernews.com](https://thehackernews.com/2026/04/n8n-webhooks-abused-since-october-2025.html?utm_source=openai)) The exploitation of legitimate automation platforms like n8n underscores a growing trend where attackers leverage trusted services to evade detection. This incident highlights the need for organizations to scrutinize third-party integrations and enhance monitoring of automated workflows to prevent similar abuses. ([blog.talosintelligence.com](https://blog.talosintelligence.com/the-n8n-n8mare/?utm_source=openai))
5 months ago
Kill Chain
Microsoft's April 2026 Patch Tuesday: Addressing Critical Vulnerabilities and Zero-Day Exploits
In April 2026, Microsoft released a substantial Patch Tuesday update addressing 167 vulnerabilities across its product suite, marking it as the second-largest patch release in the company's history. This update included two zero-day vulnerabilities: CVE-2026-32201, a spoofing flaw in Microsoft SharePoint Server that was actively exploited in the wild, and CVE-2026-33825, an elevation of privilege issue in Microsoft Defender that had been publicly disclosed prior to patching. Additionally, eight critical vulnerabilities were addressed, affecting components such as Windows Internet Key Exchange (IKE) Service Extensions and Microsoft Word. The prevalence of elevation of privilege vulnerabilities, accounting for 57% of the patches, underscores the critical need for organizations to prioritize these updates to mitigate potential security risks. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai)) The urgency of this update is heightened by the active exploitation of CVE-2026-32201 and the public disclosure of CVE-2026-33825, which could lead to increased targeting by threat actors. Organizations are advised to promptly apply these patches to protect their systems from potential attacks leveraging these vulnerabilities. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai))
5 months ago
Kill Chain
Strengthening Defenses Against the Rise of EDR Killers Utilizing BYOVD Techniques
In early 2026, security researchers observed a significant increase in the use of EDR (Endpoint Detection and Response) killers employing the Bring Your Own Vulnerable Driver (BYOVD) technique. This method involves attackers introducing legitimate, signed drivers with known vulnerabilities into target systems to disable security defenses. ESET's analysis identified nearly 90 unique EDR killer tools exploiting 35 vulnerable drivers, enabling ransomware groups to neutralize security measures before deploying their payloads. The proliferation of these tools, available through underground marketplaces and public proof-of-concept exploits, has heightened concerns among cybersecurity professionals. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/edr-killer-ecosystem-expansion-requires-stronger-byovd-defenses/?utm_source=openai)) The current relevance of this incident lies in the evolving threat landscape, where the commodification of EDR killers has made sophisticated attack techniques accessible to a broader range of cybercriminals. This trend underscores the urgent need for organizations to implement robust defenses against BYOVD attacks, including monitoring for unauthorized driver installations and enhancing endpoint security measures. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/edr-killer-ecosystem-expansion-requires-stronger-byovd-defenses/?utm_source=openai))
5 months ago
Kill Chain
Protecting AI Infrastructure: Lessons from the March 2026 Reconnaissance Scans
In March 2026, cybersecurity researchers identified a series of reconnaissance scans targeting AI model-related files and services, including Claude, OpenClaw, Hugging Face, and OpenAI. These scans, originating from IP address 81.168.83.103, began on March 10, 2026, and have been ongoing. The activity involves probing for specific AI model configuration and credential files, as well as scanning ports commonly associated with web content. While no active exploitation has been reported, the scans appear aimed at discovering AI model deployments or related sensitive files. ([isc.sans.edu](https://isc.sans.edu/diary/Scanning%2Bfor%2BAI%2BModels/32896/?utm_source=openai)) This incident underscores the growing interest of threat actors in AI infrastructure, highlighting the need for organizations to secure AI model deployments and associated files. The trend of targeting AI systems is expected to continue, necessitating proactive measures to protect sensitive AI-related data.
5 months ago
Kill Chain
Microsoft's April 2026 Patch Tuesday: Addressing Critical SharePoint Vulnerabilities
In April 2026, Microsoft released a significant Patch Tuesday update addressing 167 vulnerabilities across its product suite, including an actively exploited zero-day in SharePoint Server (CVE-2026-32201). This spoofing vulnerability allowed unauthorized attackers to perform cross-site scripting (XSS) attacks, potentially leading to data exfiltration and unauthorized access. The update also included fixes for another zero-day in Microsoft Defender and several critical remote code execution flaws. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-April-2026-Patch-Tuesday-fixes-167-vulnerabilities-and-two-zero-days.1274388.0.html?utm_source=openai)) The scale and severity of this update underscore the increasing sophistication and frequency of cyber threats targeting widely used enterprise platforms. Organizations are urged to prioritize patching to mitigate risks associated with these vulnerabilities, especially given the active exploitation of the SharePoint flaw. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2026/?utm_source=openai))
5 months ago
Kill Chain
April 2026 Patch Tuesday: Addressing Critical Vulnerabilities Across Major Platforms
In April 2026, multiple critical vulnerabilities were disclosed across major software vendors, including Microsoft, Adobe, SAP, and Fortinet. Notably, Microsoft addressed 167 security flaws, among them an actively exploited zero-day in SharePoint Server (CVE-2026-32201) allowing spoofing attacks, and a publicly disclosed privilege escalation vulnerability in Microsoft Defender (CVE-2026-33825). SAP patched a severe SQL injection vulnerability (CVE-2026-27681) in its Business Planning and Consolidation and Business Warehouse products, which could lead to arbitrary database command execution. Adobe released fixes for critical vulnerabilities in Acrobat Reader, including an actively exploited remote code execution flaw (CVE-2026-34621). Fortinet addressed critical issues in FortiSandbox, such as an authentication bypass (CVE-2026-39813) and an OS command injection vulnerability (CVE-2026-39808). These vulnerabilities, if exploited, could lead to unauthorized access, data exfiltration, and system compromise, underscoring the importance of timely patching and vigilant security practices. The current threat landscape is characterized by immediate, real-world exploitation of these vulnerabilities, highlighting the urgency for organizations to apply these patches promptly to mitigate potential risks.
5 months ago
Kill Chain
Anthropic's Claude Mythos Preview: A Game-Changer in AI-Driven Cybersecurity
In April 2026, Anthropic unveiled Claude Mythos Preview, an advanced AI model capable of autonomously identifying thousands of zero-day vulnerabilities across major operating systems and web browsers. This model discovered critical flaws, some existing for decades, and demonstrated the ability to chain multiple vulnerabilities into sophisticated exploits. Due to its potential for misuse, Anthropic restricted access to select organizations under Project Glasswing, aiming to bolster defensive cybersecurity measures. The emergence of AI models like Claude Mythos Preview signifies a paradigm shift in cybersecurity, where AI can both uncover and potentially exploit vulnerabilities at an unprecedented scale. This development underscores the urgency for organizations to adopt continuous, AI-augmented security testing and to reassess their remediation strategies to keep pace with rapidly evolving threats.
5 months ago
Kill Chain
Microsoft's April 2026 Patch Tuesday: A Critical Security Update
In April 2026, Microsoft released a substantial Patch Tuesday update addressing 165 vulnerabilities across its product suite, marking the second-largest patch release in the company's history. Notably, this update included a zero-day vulnerability in Microsoft Office SharePoint (CVE-2026-32201) that was actively exploited, allowing unauthenticated attackers to perform spoofing over a network. Additionally, a high-severity vulnerability in Microsoft Defender (CVE-2026-33825) was publicly disclosed prior to patching, potentially enabling unauthorized privilege escalation. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-april-2026/?utm_source=openai)) The scale and severity of this update underscore the increasing complexity and volume of security threats facing organizations. The active exploitation of SharePoint and the public disclosure of the Defender vulnerability highlight the critical need for timely patch management and proactive security measures to mitigate potential breaches and data compromises.
5 months ago
Kill Chain
Windows 11 April 2026 Security Update: Critical Fixes and Enhancements
In April 2026, Microsoft released cumulative updates KB5083769 and KB5082052 for Windows 11 versions 25H2/24H2 and 23H2, respectively. These mandatory updates addressed 165 security vulnerabilities, including one actively exploited zero-day in Microsoft SharePoint Server (CVE-2026-32201) and one publicly disclosed zero-day in Microsoft Defender (CVE-2026-33825). The updates also introduced enhancements such as the ability to toggle Smart App Control without a clean install, improved Narrator features, and refined Settings app design. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5083769-and-kb5082052-released/amp/?utm_source=openai)) The release underscores the critical importance of timely patch management, as threat actors increasingly exploit known vulnerabilities shortly after disclosure. Organizations are urged to apply these updates promptly to mitigate potential risks associated with these vulnerabilities. ([crowdstrike.com](https://www.crowdstrike.com/content/crowdstrike-www/locale-sites/us/en-us/blog/patch-tuesday-analysis-april-2026.html?utm_source=openai))
5 months ago
Kill Chain
Microsoft Bolsters RDP Security to Thwart Phishing Threats
In April 2026, Microsoft released security updates for Windows 10 and Windows 11 to enhance protections against phishing attacks exploiting Remote Desktop Protocol (RDP) files. These updates introduce new security warnings and disable risky shared resources by default when opening RDP files, aiming to prevent unauthorized access and data theft facilitated through malicious RDP configurations. ([learn.microsoft.com](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings?utm_source=openai)) This initiative addresses the increasing abuse of RDP files in phishing campaigns, where attackers use them to gain control over victims' systems and access sensitive information. By implementing these protections, Microsoft aims to mitigate the risks associated with such attacks and enhance overall system security. ([learn.microsoft.com](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings?utm_source=openai))
5 months ago
Kill Chain
Critical Command Injection Vulnerabilities Discovered in PHP Composer's Perforce Driver
In April 2026, two critical command injection vulnerabilities were identified in PHP's Composer package manager, specifically within its Perforce VCS driver. These flaws, designated as CVE-2026-40176 and CVE-2026-40261, allowed attackers to execute arbitrary commands on systems running vulnerable versions of Composer. The vulnerabilities stemmed from improper input validation and insufficient escaping of user-supplied parameters, enabling command execution in the context of the user running Composer. Immediate patches were released in versions 2.9.6 and 2.2.27 to address these issues. This incident underscores the persistent risks associated with software supply chains, particularly in widely-used development tools. It highlights the necessity for developers to remain vigilant, promptly apply security updates, and scrutinize third-party dependencies to mitigate potential threats.
5 months ago
Kill Chain
Adobe Acrobat Reader Zero-Day Exploit CVE-2026-34621: What You Need to Know
In April 2026, Adobe addressed a critical zero-day vulnerability (CVE-2026-34621) in Acrobat Reader, which had been actively exploited since at least December 2025. This flaw allowed attackers to execute arbitrary code on both Windows and macOS systems when users opened maliciously crafted PDF files. The vulnerability stemmed from a prototype pollution issue, enabling unauthorized code execution within the context of the current user. ([techcrunch.com](https://techcrunch.com/2026/04/14/adobe-fixes-pdf-zero-day-security-bug-that-hackers-have-exploited-for-months/?utm_source=openai)) The exploitation of this vulnerability highlights the persistent targeting of widely used software by threat actors. Organizations are urged to prioritize timely patching and to educate users on the risks associated with opening files from untrusted sources to mitigate similar threats.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports