Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3058 threat reports
Page 127 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 15131524 / 3058 reports
Critical Vulnerability in Ivanti EPMM: CVE-2026-1340
Impact· CRITICAL

Critical Vulnerability in Ivanti EPMM: CVE-2026-1340

In January 2026, a critical code injection vulnerability, CVE-2026-1340, was discovered in Ivanti Endpoint Manager Mobile (EPMM). This flaw allows unauthenticated remote code execution, enabling attackers to execute arbitrary code on affected systems without authentication. The vulnerability affects EPMM versions up to and including 12.7.0.0. Exploitation of this vulnerability can lead to complete system compromise, data theft, and potential lateral movement within enterprise networks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-1340/?utm_source=openai)) The inclusion of CVE-2026-1340 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. ([datacomm.com](https://www.datacomm.com/feed-post/cve-2026-1281-cve-2026-1340-ivanti-endpoint-manager-mobile-epmm-zero-day-vulnerabilities-exploited-2/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity
Impact· HIGH

Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity

In March 2026, Anthropic's AI model, Claude Mythos, identified thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented discovery included a 27-year-old bug in OpenBSD and a critical flaw in FFmpeg. Due to the model's potential for misuse, Anthropic restricted access to select organizations under Project Glasswing to facilitate responsible vulnerability remediation. ([techcrunch.com](https://techcrunch.com/2026/04/07/anthropic-mythos-ai-model-preview-security/?utm_source=openai)) The incident underscores the dual-use nature of advanced AI in cybersecurity, highlighting the need for stringent access controls and collaborative efforts to mitigate risks associated with powerful AI tools.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AWS AgentCore IAM God Mode Vulnerability Exposes Critical Security Risks
Impact· HIGH

AWS AgentCore IAM God Mode Vulnerability Exposes Critical Security Risks

In April 2026, a security analysis revealed that the Amazon Bedrock AgentCore Starter Toolkit's default IAM roles granted overly permissive access, allowing AI agents to perform actions across all resources within an AWS account. This misconfiguration enabled potential attackers to exfiltrate proprietary ECR images, access other agents' memories, invoke code interpreters, and extract sensitive data. The issue stemmed from the toolkit's auto-create logic, which favored deployment ease over the principle of least privilege. Following disclosure, AWS updated its documentation to warn users that the default roles are intended for development and testing purposes only and are not recommended for production deployments. This incident underscores the critical importance of adhering to the principle of least privilege in IAM configurations, especially as organizations increasingly deploy AI agents in cloud environments. Overly permissive roles can lead to significant security risks, including data breaches and unauthorized access to sensitive resources.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic
Impact· HIGH

Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic

In April 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-34197, was discovered in Apache ActiveMQ Classic, a widely used open-source message broker. This flaw, present for over 13 years, allows authenticated attackers to execute arbitrary commands on the broker's Java Virtual Machine (JVM) by exploiting the Jolokia JMX-HTTP bridge. The vulnerability affects versions before 5.19.4 and from 6.0.0 up to 6.2.3. Exploitation involves sending a crafted request that forces the broker to load a remote Spring XML file, leading to command execution during its initialization. The discovery underscores the importance of proactive vulnerability management and the potential of AI tools in identifying complex security flaws. Organizations using affected ActiveMQ versions are urged to upgrade to versions 5.19.5 or 6.2.3 to mitigate this risk. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-34197?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chaos Malware's New Variant Exploits Cloud Misconfigurations in 2026
Impact· HIGH

Chaos Malware's New Variant Exploits Cloud Misconfigurations in 2026

In March 2026, cybersecurity researchers identified a new variant of the Chaos malware targeting misconfigured cloud deployments, particularly 64-bit Linux servers. Previously known for compromising routers and edge devices, this evolution signifies a strategic shift by attackers to exploit cloud infrastructure vulnerabilities. The malware gains access through misconfigurations, establishes persistence via systemd services, and introduces a SOCKS5 proxy feature, enabling attackers to route malicious traffic through compromised servers. This development underscores the critical need for organizations to secure cloud environments against evolving threats. The inclusion of proxy capabilities in Chaos malware reflects a broader trend of botnets expanding functionalities beyond traditional DDoS attacks, facilitating more complex cybercriminal activities. This shift highlights the importance of robust security configurations and continuous monitoring in cloud deployments to mitigate emerging risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
Impact· CRITICAL

AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally

In early 2026, a sophisticated cyberattack leveraging artificial intelligence (AI) tools compromised over 600 FortiGate firewalls across 55 countries. The attackers utilized AI to automate reconnaissance, vulnerability scanning, and exploitation processes, significantly accelerating the attack timeline and reducing the need for human intervention. By exploiting weak security configurations and exposed management interfaces, the threat actors gained unauthorized access to critical network infrastructure, leading to potential data breaches and operational disruptions. This incident underscores the escalating threat posed by AI-enhanced cyberattacks, which enable adversaries to conduct large-scale operations with unprecedented speed and efficiency. Organizations must recognize the evolving capabilities of AI in the cyber threat landscape and implement robust security measures to defend against such advanced attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Storm-1175's High-Velocity Medusa Ransomware Attacks in 2026
Impact· CRITICAL

Storm-1175's High-Velocity Medusa Ransomware Attacks in 2026

In April 2026, the financially motivated cybercriminal group Storm-1175 launched rapid ransomware attacks targeting healthcare, education, professional services, and finance sectors across Australia, the UK, and the US. Exploiting both zero-day and recently disclosed vulnerabilities, the group moved swiftly from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. Their tactics included creating new user accounts, deploying remote monitoring tools, stealing credentials, and disabling security software to facilitate their operations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly patch vulnerabilities and enhance monitoring of web-facing assets. The speed and efficiency of Storm-1175's attacks highlight a growing trend among threat actors to exploit the narrow window between vulnerability disclosure and patch deployment, emphasizing the importance of proactive cybersecurity measures. ([darkreading.com](https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GrafanaGhost: Unveiling the AI Vulnerability Exposing Enterprise Data
Impact· HIGH

GrafanaGhost: Unveiling the AI Vulnerability Exposing Enterprise Data

In April 2026, a critical vulnerability named 'GrafanaGhost' was discovered in Grafana's AI components, allowing attackers to exfiltrate sensitive enterprise data through indirect prompt injection. By embedding malicious instructions within external web content, attackers could manipulate Grafana's AI to process these prompts as legitimate, leading to unauthorized data exposure without user interaction. This flaw was promptly patched by Grafana following responsible disclosure. The GrafanaGhost incident underscores the growing risks associated with integrating AI into enterprise systems. It highlights the necessity for robust security measures to prevent AI-specific vulnerabilities, as attackers increasingly exploit such weaknesses to access sensitive information.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Driven Ransomware Attack 2026: Lessons Learned
Impact· HIGH

AI-Driven Ransomware Attack 2026: Lessons Learned

In early 2026, a sophisticated AI-driven ransomware attack targeted multiple organizations, exploiting vulnerabilities in AI systems to gain unauthorized access. The attackers utilized autonomous AI agents to conduct reconnaissance, escalate privileges, and deploy ransomware, significantly reducing the time from initial breach to full system encryption. This rapid progression left organizations with minimal time to detect and respond, resulting in substantial operational disruptions and financial losses. This incident underscores the escalating threat posed by AI-enhanced cyberattacks, highlighting the need for organizations to adopt advanced, AI-driven defense mechanisms. The convergence of AI and cybercrime necessitates a proactive approach to cybersecurity, emphasizing rapid detection, response, and recovery strategies to mitigate the impact of such attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
LiteLLM Supply Chain Compromise: A Wake-Up Call for Open-Source Security
Impact· HIGH

LiteLLM Supply Chain Compromise: A Wake-Up Call for Open-Source Security

In March 2026, the LiteLLM Python package, widely used for routing large language model (LLM) API calls, was compromised through a supply chain attack. Malicious versions 1.82.7 and 1.82.8 were uploaded to the Python Package Index (PyPI) after attackers gained access to the maintainer's credentials via a compromised Trivy security scanner in LiteLLM's CI/CD pipeline. These versions contained a credential-stealing payload that executed automatically on Python startup, exfiltrating sensitive information such as SSH keys, cloud provider credentials, and Kubernetes secrets to an attacker-controlled server. The malicious packages were available for approximately three hours before being removed from PyPI. ([snyk.io](https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The rapid propagation of malicious code through widely used packages highlights the need for enhanced security measures in software development pipelines, including stringent credential management, regular security audits, and the implementation of tools like Software Bill of Materials (SBOMs) and SigStore for verifying package integrity. ([ionix.io](https://www.ionix.io/threat-center/litellm-supply-chain-compromise-backdoored-pypi-packages-1-82-7-1-82-8/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI's 2025 Internet Crime Report: A 26% Surge in Cybercrime Losses
Impact· CRITICAL

FBI's 2025 Internet Crime Report: A 26% Surge in Cybercrime Losses

In 2025, the FBI's Internet Crime Complaint Center (IC3) reported a significant surge in cybercrime, with total losses reaching $20.9 billion—a 26% increase from the previous year. The center received over one million complaints, marking a 17% rise compared to 2024. Investment-related fraud led to losses of nearly $8.65 billion, while business email compromise accounted for almost $3.05 billion. Phishing remained the most reported cybercrime, followed by extortion and personal data breaches. ([cyberscoop.com](https://cyberscoop.com/fbi-internet-crime-complaint-center-annual-cybercrime-report/?utm_source=openai)) This escalation underscores the growing sophistication of cybercriminals, who are increasingly leveraging artificial intelligence to enhance their attacks. The trend highlights the urgent need for organizations to bolster their cybersecurity measures and stay vigilant against evolving threats. ([forbes.com](https://www.forbes.com/sites/timkeary/2026/04/07/fbi-reports-208-billion-lost-to-cybercrime-as-hackers-turn-to-ai/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
German Authorities Unmask Leaders Behind REvil and GandCrab Ransomware Attacks
Impact· CRITICAL

German Authorities Unmask Leaders Behind REvil and GandCrab Ransomware Attacks

In April 2026, Germany's Federal Criminal Police Office (BKA) identified Russian nationals Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk as the leaders of the GandCrab and REvil ransomware operations between 2019 and 2021. Operating under aliases such as 'UNKN' or 'UNKNOWN,' Shchukin and Kravchuk orchestrated at least 130 cyberattacks targeting German companies, resulting in over $40 million in damages and approximately $2.2 million in ransom payments. Their operations popularized the 'double extortion' tactic, demanding payment for decrypting data and additional sums to prevent public release of stolen information. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/german-authorities-identify-revil-and-gangcrab-ransomware-bosses/?utm_source=openai)) This identification underscores the persistent threat posed by sophisticated ransomware groups and highlights the importance of international cooperation in combating cybercrime. The GandCrab and REvil models have influenced current ransomware tactics, emphasizing the need for robust cybersecurity measures and proactive threat intelligence to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports