Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3058 threat reports
Page 128 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 15251536 / 3058 reports
Snowflake Data Breach 2026: Lessons in Third-Party Integration Security
Impact· MEDIUM

Snowflake Data Breach 2026: Lessons in Third-Party Integration Security

In April 2026, over a dozen companies experienced data theft attacks following a breach at a SaaS integration provider, leading to the theft of authentication tokens. The majority of these attacks targeted Snowflake, a cloud-based data platform. Snowflake detected unusual activity in a small number of customer accounts linked to a specific third-party integration and promptly initiated an investigation, securing the affected accounts and notifying impacted customers. The attacks did not involve any vulnerability or compromise of Snowflake's systems. The ShinyHunters extortion group claimed responsibility for the attacks, stating they had stolen data from dozens of companies and were demanding ransom payments to prevent the release of the stolen data. The group also attempted to steal data from Salesforce but were thwarted by AI detection mechanisms. This incident underscores the critical importance of securing third-party integrations and the growing threat posed by sophisticated cybercriminal groups like ShinyHunters.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Storm-1175's Rapid Exploitation of Zero-Days Leads to Medusa Ransomware Attacks
Impact· CRITICAL

Storm-1175's Rapid Exploitation of Zero-Days Leads to Medusa Ransomware Attacks

In early April 2026, the China-based cybercriminal group Storm-1175 executed a series of high-velocity attacks targeting vulnerable internet-facing systems across sectors such as healthcare, education, professional services, and finance in Australia, the United Kingdom, and the United States. By exploiting a combination of zero-day and N-day vulnerabilities, including CVE-2025-10035 in Fortra's GoAnywhere MFT and CVE-2026-23760 in SmarterMail, the group rapidly gained initial access. Post-compromise activities involved deploying web shells, creating new user accounts, and utilizing remote monitoring and management tools like SimpleHelp and MeshAgent for persistence and lateral movement. Within as little as 24 hours, Storm-1175 exfiltrated data and deployed Medusa ransomware, leading to significant operational disruptions for the affected organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the increasing sophistication and speed of financially motivated threat actors in exploiting newly disclosed vulnerabilities. The rapid transition from initial access to ransomware deployment highlights the critical need for organizations to promptly apply security patches, monitor for unauthorized activities, and implement robust incident response strategies to mitigate such high-tempo cyber threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian Hackers Exploit PLC Vulnerabilities in U.S. Critical Infrastructure
Impact· CRITICAL

Iranian Hackers Exploit PLC Vulnerabilities in U.S. Critical Infrastructure

In March 2026, Iranian-affiliated Advanced Persistent Threat (APT) actors initiated cyberattacks targeting internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including Government Services, Water and Wastewater Systems, and Energy. These attacks involved unauthorized access to PLCs, manipulation of project files, and alteration of data displayed on Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems, leading to operational disruptions and financial losses. This incident underscores the escalating cyber threat landscape, particularly in the context of geopolitical tensions. Organizations must prioritize securing internet-facing operational technology assets to mitigate risks associated with state-sponsored cyber activities.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Remote Code Execution Vulnerability in Flowise AI: CVE-2025-59528
Impact· CRITICAL

Critical Remote Code Execution Vulnerability in Flowise AI: CVE-2025-59528

In September 2025, a critical remote code execution (RCE) vulnerability, identified as CVE-2025-59528, was discovered in Flowise AI's version 3.0.5. This flaw resided in the CustomMCP node, which improperly executed user-supplied JavaScript code without validation, granting attackers full Node.js runtime privileges. Exploitation of this vulnerability could lead to complete system compromise, unauthorized command execution, and data exfiltration. Flowise addressed this issue by releasing version 3.0.6, which rectified the vulnerability. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-59528?utm_source=openai)) As of April 2026, active exploitation of CVE-2025-59528 has been observed, with over 12,000 Flowise instances exposed to potential attacks. This resurgence underscores the critical need for organizations to ensure their systems are updated to the latest secure versions to mitigate such high-severity threats. ([thehackernews.com](https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses
Impact· CRITICAL

FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses

In 2025, the FBI's Internet Crime Complaint Center (IC3) reported that Americans lost nearly $21 billion to cyber-enabled crimes, marking a 26% increase from the previous year. The most prevalent incidents included phishing attacks, extortion, and investment scams, with cryptocurrency-related fraud accounting for over $11 billion in losses. Notably, individuals over the age of 60 were disproportionately affected, reporting $7.7 billion in losses, a 37% rise from 2024. Additionally, the FBI highlighted the emergence of AI-driven scams, which resulted in 22,300 complaints and $893 million in losses, involving tactics such as voice cloning and deepfake videos. This surge underscores the evolving sophistication of cybercriminals, who are increasingly leveraging advanced technologies like artificial intelligence to enhance the effectiveness of their schemes. The significant financial impact on older adults highlights the urgent need for targeted education and robust cybersecurity measures to protect vulnerable populations from these emerging threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GPUBreach: Unveiling the 2026 NVIDIA GDDR6 RowHammer Vulnerability
Impact· HIGH

GPUBreach: Unveiling the 2026 NVIDIA GDDR6 RowHammer Vulnerability

In April 2026, researchers from the University of Toronto unveiled 'GPUBreach,' a sophisticated RowHammer attack targeting NVIDIA GPUs equipped with GDDR6 memory. This attack exploits bit-flips in GPU memory to corrupt page tables, granting an unprivileged process arbitrary read/write access to GPU memory. By leveraging vulnerabilities in the NVIDIA driver, attackers can escalate privileges to gain full control over the host system, even with IOMMU protections enabled. The implications are severe, particularly for cloud AI infrastructures and multi-tenant GPU deployments, as GPUBreach enables attackers to compromise entire systems without physical access. This development underscores the evolving nature of hardware-based attacks and the necessity for robust security measures in GPU environments. ([thehackernews.com](https://thehackernews.com/2026/04/new-gpubreach-attack-enables-full-cpu.html?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Docker Authorization Bypass Vulnerability (CVE-2026-34040) Discovered
Impact· HIGH

Critical Docker Authorization Bypass Vulnerability (CVE-2026-34040) Discovered

In March 2026, a high-severity vulnerability (CVE-2026-34040) was identified in Docker Engine, allowing attackers to bypass authorization plugins (AuthZ) by sending oversized HTTP request bodies. This flaw enables unauthorized users to perform privileged container operations, potentially leading to full host system compromise. The issue affects Docker Engine versions prior to 29.3.1 and is a result of an incomplete fix for a previous vulnerability (CVE-2024-41110) addressed in July 2024. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34040/?utm_source=openai)) The discovery of this vulnerability underscores the persistent risks associated with authorization bypass flaws in critical infrastructure. Organizations relying on Docker for container management must promptly update to version 29.3.1 or later to mitigate this threat. ([cyera.com](https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Driven Supply Chain Attack Compromises GitHub Repositories
Impact· CRITICAL

AI-Driven Supply Chain Attack Compromises GitHub Repositories

In March 2026, a threat actor utilized AI-assisted automation to execute over 450 exploit attempts against open-source repositories on GitHub. The campaign, identified as 'prt-scan,' specifically targeted repositories misconfigured with the 'pull_request_target' workflow trigger. While less than 10% of these attempts were successful, the attacker managed to compromise at least two NPM packages, leading to the exposure of ephemeral GitHub credentials. This incident underscores the growing trend of AI-enhanced supply chain attacks, where adversaries leverage automation to scale their operations and exploit common misconfigurations. Organizations are urged to review and secure their CI/CD pipelines to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert
Impact· CRITICAL

Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted API requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to apply them immediately. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The incident underscores the persistent targeting of Fortinet products by threat actors, highlighting the importance of timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Storm-1175's Rapid Exploitation of Web Vulnerabilities in 2026
Impact· CRITICAL

Storm-1175's Rapid Exploitation of Web Vulnerabilities in 2026

In early 2026, the financially motivated cybercriminal group Storm-1175 executed high-velocity ransomware campaigns by exploiting recently disclosed vulnerabilities in web-facing systems. The group rapidly transitioned from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. These attacks significantly impacted healthcare, education, professional services, and finance sectors across Australia, the United Kingdom, and the United States. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly apply security patches and enhance monitoring of web-facing assets. The rapid exploitation of vulnerabilities by threat actors like Storm-1175 highlights the importance of proactive defense measures to mitigate the risk of ransomware attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability
Impact· CRITICAL

Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability

In April 2026, Fortinet disclosed a critical improper access control vulnerability (CVE-2026-35616) in FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, leading to potential remote code execution and privilege escalation. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise immediate patching to mitigate the risk. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent targeting of Fortinet products by threat actors. Organizations are urged to apply the provided hotfixes promptly and monitor their systems for any signs of compromise to maintain robust security postures. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet's FortiClient EMS Zero-Day Vulnerability Exploited in 2026
Impact· CRITICAL

Fortinet's FortiClient EMS Zero-Day Vulnerability Exploited in 2026

In early April 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS), which was actively exploited in the wild. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted requests. Fortinet released an emergency hotfix for versions 7.4.5 and 7.4.6, with plans for a comprehensive patch in version 7.4.7. The vulnerability was added to CISA's known exploited vulnerability catalog, highlighting its severity and widespread impact. The rapid exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting zero-day vulnerabilities in widely used security solutions. Organizations must remain vigilant, ensuring timely application of patches and hotfixes to mitigate such threats. This incident also emphasizes the importance of robust access controls and continuous monitoring to detect and respond to unauthorized activities promptly.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports