Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3058 threat reports
Page 132 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 15731584 / 3058 reports
NoVoice Malware: A Wake-Up Call for Android Security
Impact· CRITICAL

NoVoice Malware: A Wake-Up Call for Android Security

In early 2026, a sophisticated Android malware campaign named 'NoVoice' infiltrated over 50 applications on Google Play, amassing at least 2.3 million downloads. Disguised as legitimate utilities like cleaners, games, and image galleries, these apps functioned as advertised, concealing their malicious intent. Upon installation, the malware exploited known Android vulnerabilities to gain root access, enabling it to inject code into other applications and exfiltrate sensitive data, notably targeting WhatsApp sessions. The malware's persistence mechanisms allowed it to survive standard factory resets, posing a significant threat to user privacy and device integrity. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/?utm_source=openai)) This incident underscores the evolving sophistication of mobile malware and the critical importance of maintaining up-to-date device security. It highlights the necessity for users to exercise caution when downloading apps, even from trusted sources like Google Play, and for developers to adhere to stringent security practices to prevent such infiltrations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Blackpoint Cyber's 2026 Report: Credential Abuse and RMM Tool Exploitation
Impact· CRITICAL

Blackpoint Cyber's 2026 Report: Credential Abuse and RMM Tool Exploitation

In 2026, Blackpoint Cyber's annual threat report highlighted a significant shift in cyberattack methodologies, with a notable increase in the exploitation of legitimate access methods over traditional vulnerability exploits. The report revealed that 32.8% of incidents involved SSL VPN abuse, where attackers utilized valid but compromised credentials to establish seemingly legitimate sessions, facilitating rapid lateral movement within networks. Additionally, 30.3% of incidents featured the misuse of Remote Monitoring and Management (RMM) tools, particularly ScreenConnect, which was present in over 70% of rogue RMM cases. This trend underscores the evolving tactics of threat actors who are leveraging trusted IT tools to gain and maintain unauthorized access, thereby evading conventional security measures. The current relevance of this incident lies in the growing prevalence of identity-driven attacks and the strategic use of legitimate tools for malicious purposes. Organizations must recognize that traditional security controls may be insufficient against such tactics, necessitating enhanced monitoring of credential usage and the implementation of stringent access controls. The rise in these sophisticated methods highlights the urgent need for adaptive security strategies to effectively counteract the evolving threat landscape.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Volt Typhoon 2024: A Case Study in Living Off the Land Cyber Attacks
Impact· HIGH

Volt Typhoon 2024: A Case Study in Living Off the Land Cyber Attacks

In 2024, the Chinese state-sponsored hacker group known as Volt Typhoon executed a sophisticated Living Off the Land (LOTL) attack targeting critical infrastructure in the United States. By exploiting legitimate system tools and processes, they infiltrated networks without deploying traditional malware, thereby evading standard detection mechanisms. This approach allowed them to conduct prolonged surveillance and data exfiltration, significantly compromising national security and operational integrity. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3669159/combatting-cyber-threat-actors-perpetrating-living-off-the-land-intrusions/?utm_source=openai)) The incident underscores a growing trend among nation-state actors to utilize LOTL techniques, which leverage trusted system utilities to carry out malicious activities. This method not only complicates detection but also challenges traditional cybersecurity defenses, necessitating a shift towards behavior-based monitoring and advanced threat detection strategies.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chrome 2026 Dawn Use-After-Free Vulnerability
Impact· HIGH

Chrome 2026 Dawn Use-After-Free Vulnerability

In April 2026, Google identified and patched a high-severity zero-day vulnerability, CVE-2026-5281, in its Chrome browser. This use-after-free flaw in Dawn, Chrome's implementation of the WebGPU standard, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to versions 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux. ([thehackernews.com](https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html?utm_source=openai)) This incident underscores the increasing frequency of zero-day vulnerabilities targeting widely used software. It highlights the critical need for organizations to maintain up-to-date systems and implement robust security measures to mitigate the risks associated with such exploits.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
Impact· HIGH

Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

In late February 2026, Microsoft identified a sophisticated malware campaign leveraging WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. Upon execution, these scripts initiate a multi-stage infection chain, utilizing renamed Windows utilities to download additional payloads from trusted cloud services like AWS, Tencent Cloud, and Backblaze B2. The malware employs User Account Control (UAC) bypass techniques to escalate privileges, establish persistence, and deploy tools such as AnyDesk for remote access, enabling attackers to exfiltrate data or deploy further malware. This campaign underscores the evolving tactics of threat actors who exploit legitimate tools and platforms to evade detection and maintain control over compromised systems. Organizations must remain vigilant against such social engineering attacks and implement robust security measures to mitigate these threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CERT-UA Impersonation Campaign: UAC-0255's AGEWHEEZE Malware Attack
Impact· LOW

CERT-UA Impersonation Campaign: UAC-0255's AGEWHEEZE Malware Attack

In late March 2026, the threat actor group UAC-0255 launched a phishing campaign impersonating the Computer Emergency Response Team of Ukraine (CERT-UA). The attackers sent emails on March 26 and 27, 2026, posing as CERT-UA to distribute a password-protected ZIP archive hosted on Files.fm, urging recipients to install the 'specialized software.' The ZIP file ('CERT_UA_protection_tool.zip') is designed to download malware packaged as security software from the agency. The targets of the campaign included state organizations, medical centers, security companies, educational institutions, financial institutions, and software development companies. Some of the emails were sent from the email address 'incidents@cert-ua[.]tech.'

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Excessive Permissions in Google Vertex AI: A 2026 Security Wake-Up Call
Impact· MEDIUM

Excessive Permissions in Google Vertex AI: A 2026 Security Wake-Up Call

In March 2026, Palo Alto Networks' Unit 42 identified a critical security vulnerability in Google Cloud's Vertex AI platform. The issue stemmed from the platform's default service accounts, known as Per-Project, Per-Product Service Agents (P4SA), which were granted excessive permissions by default. This misconfiguration allowed attackers to exploit AI agents deployed on Vertex AI, enabling unauthorized access to sensitive data and internal cloud infrastructure. By extracting the service account credentials, malicious actors could escalate privileges, access proprietary container images, and potentially compromise Google's internal storage buckets. ([darkreading.com](https://www.darkreading.com/cyber-risk/googles-vertex-ai-over-privilege-problem?utm_source=openai)) This incident underscores the growing security challenges associated with AI deployments in cloud environments. As organizations increasingly integrate AI agents into their workflows, ensuring proper configuration and adherence to the principle of least privilege becomes paramount to prevent similar vulnerabilities and safeguard sensitive information.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical XSS and GhostScript RCE Vulnerabilities in Enterprise Document Processing Platform
Impact· CRITICAL

Critical XSS and GhostScript RCE Vulnerabilities in Enterprise Document Processing Platform

In 2026, a critical security assessment of an enterprise document processing platform revealed two severe vulnerabilities: an unauthenticated cross-site scripting (XSS) flaw and a GhostScript parameter injection leading to remote code execution (RCE). The XSS vulnerability allowed attackers to execute malicious scripts, bypassing HttpOnly cookie protections by exploiting an internal service endpoint that reflected session cookies in its response. This enabled full administrative access. Additionally, the GhostScript flaw permitted arbitrary command execution on the server by injecting parameters that disabled security features, leading to potential system compromise. ([praetorian.com](https://www.praetorian.com/blog/httponly-cookie-bypass-xss-ghostscript-rce/?utm_source=openai)) This incident underscores the persistent risks associated with XSS and RCE vulnerabilities, especially in applications handling sensitive data. It highlights the necessity for comprehensive security measures, including proper input validation, strict access controls, and regular security assessments to identify and mitigate such critical flaws.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Surge in Cyberattacks Targets Latin American Governments in 2026
Impact· CRITICAL

Surge in Cyberattacks Targets Latin American Governments in 2026

In early 2026, Latin American governments faced a significant surge in cyberattacks targeting critical infrastructure and sensitive data. Notably, Colombia's health ministry reported over 23 million cyberattacks and probes in March, while Mexico's government agencies suffered breaches compromising millions of identities and tax records. Puerto Rico's Department of Transportation also experienced disruptions due to cyber incidents. These attacks were primarily driven by financially motivated cybercriminals, with a notable increase in nation-state espionage and politically motivated hacktivism. The region's rapid digitalization, coupled with legacy systems and a shortage of cybersecurity professionals, has exacerbated vulnerabilities, making government networks prime targets for cyber adversaries. ([darkreading.com](https://www.darkreading.com/cyber-risk/latin-american-confidence-cyber-defenses-skills?utm_source=openai)) This escalation underscores the urgent need for Latin American governments to bolster their cybersecurity defenses. The convergence of AI acceleration, geopolitical fragmentation, and cyber-enabled fraud is reshaping the global risk landscape, necessitating enhanced threat intelligence, public-private cooperation, and investment in cybersecurity infrastructure to mitigate the growing threats. ([weforum.org](https://www.weforum.org/stories/2026/01/geopolitics-ai-fraud-global-cyber-cybersecurity-2026/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Navigating the Surge of AI-Driven Cyberattacks in 2025
Impact· MEDIUM

Navigating the Surge of AI-Driven Cyberattacks in 2025

In 2025, the cybersecurity landscape witnessed a significant surge in AI-driven offensive operations. Threat actors leveraged generative AI to automate and enhance attack vectors, including sophisticated phishing campaigns, deepfake-based social engineering, and rapid malware development. Notably, the average breakout time for cyberattacks decreased to just 29 minutes, a 65% acceleration from the previous year, underscoring the efficiency gains achieved through AI integration. ([itpro.com](https://www.itpro.com/security/crowdstrike-says-ai-is-officially-supercharging-cyber-attacks-average-breakout-times-hit-just-29-minutes-in-2025-65-percent-faster-than-in-2024-and-some-attacks-take-just-seconds?utm_source=openai)) This escalation in AI-powered threats has compelled organizations to reevaluate their defensive strategies. Traditional security measures are increasingly inadequate against the speed and complexity of AI-enhanced attacks. Consequently, there is a pressing need for adaptive, AI-driven defense mechanisms capable of real-time threat detection and response to mitigate the evolving risks posed by adversaries employing artificial intelligence. ([venturebeat.com](https://venturebeat.com/ai/outsmarting-ai-powered-cyber-attacks-endpoint-defense-2025?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Azure APIM Signup Bypass: A 2025 Security Wake-Up Call
Impact· HIGH

Azure APIM Signup Bypass: A 2025 Security Wake-Up Call

In September 2025, a critical vulnerability was discovered in Microsoft Azure API Management (APIM) Developer Portal, allowing unauthorized cross-tenant account creation even when administrators had disabled user signup via the portal's UI. This flaw stemmed from the backend API continuing to accept registration requests despite the UI indicating that signup was disabled. Exploiting this, attackers could create accounts, access internal API documentation, and potentially obtain API keys without any prior relationship to the target organization. Microsoft classified this behavior as 'by design' and did not release a patch, leaving organizations to implement their own mitigations. ([praetorian.com](https://www.praetorian.com/blog/azure-apim-signup-bypass/?utm_source=openai)) This incident underscores the importance of verifying that security controls function as intended, beyond their UI representations. Organizations relying solely on UI configurations may remain vulnerable to similar bypasses, emphasizing the need for comprehensive security assessments and proactive measures to secure API management platforms.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Mercor's 2026 Data Breach: A Wake-Up Call for Supply Chain Security
Impact· HIGH

Mercor's 2026 Data Breach: A Wake-Up Call for Supply Chain Security

In March 2026, AI recruiting startup Mercor confirmed a significant data breach resulting from the LiteLLM supply chain compromise orchestrated by the hacking group TeamPCP. The attackers infiltrated Mercor's systems via a compromised Tailscale VPN credential, leading to the exfiltration of approximately 4TB of sensitive data, including source code, user databases, and identity verification documents. This incident underscores the critical vulnerabilities in software supply chains and the cascading risks they pose to organizations relying on open-source components. The Mercor breach highlights the escalating threat of supply chain attacks targeting widely-used open-source projects. As organizations increasingly integrate such components into their infrastructure, the potential for widespread compromise grows, emphasizing the need for robust security measures and vigilant monitoring of third-party dependencies.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports