Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering
In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.
6 months ago
Kill Chain
VoidStealer Malware Exploits Debugger Trick to Bypass Chrome's Encryption
In March 2026, the VoidStealer malware emerged, employing a novel technique to bypass Google Chrome's Application-Bound Encryption (ABE). By utilizing hardware breakpoints, VoidStealer extracts the v20_master_key directly from the browser's memory during decryption operations, allowing it to access sensitive data such as cookies and stored passwords without requiring privilege escalation or code injection. This method represents a significant advancement in infostealer capabilities, as it circumvents security measures introduced in Chrome 127 to protect user data. The emergence of VoidStealer underscores the continuous evolution of malware tactics in response to browser security enhancements. Organizations must remain vigilant, as threat actors rapidly adapt to new defenses, developing sophisticated methods to access protected information. This incident highlights the importance of implementing comprehensive security strategies that go beyond relying solely on browser-based protections.
6 months ago
Kill Chain
Trivy Supply Chain Attack Leads to CanisterWorm Infection in 47 npm Packages
In March 2026, a sophisticated supply chain attack targeted the Trivy vulnerability scanner, leading to the compromise of 47 npm packages through a self-propagating worm named CanisterWorm. The attackers infiltrated Trivy's codebase, embedding malicious code that, upon execution, harvested developer credentials and propagated itself by injecting into other npm packages. This resulted in widespread exposure of sensitive information and potential unauthorized access to numerous development environments. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The use of self-replicating malware like CanisterWorm highlights the need for enhanced security measures, including rigorous code audits, robust access controls, and continuous monitoring of software dependencies to mitigate the risk of similar attacks in the future.
6 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager (CVE-2025-61757)
In October 2025, Oracle disclosed a critical vulnerability (CVE-2025-61757) in Oracle Identity Manager, a key component of Oracle Fusion Middleware. This flaw, with a CVSS score of 9.8, allows unauthenticated remote code execution via HTTP, enabling attackers to fully compromise affected systems. The vulnerability arises from missing authentication checks in the REST WebServices component, permitting unauthorized access and control over the Identity Manager. ([hipaajournal.com](https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/?utm_source=openai)) The exploitation of this vulnerability has been observed in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog and mandate federal agencies to apply patches by December 12, 2025. Organizations using Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are urged to apply the October 2025 Critical Patch Update immediately to mitigate potential risks. ([securityweek.com](https://www.securityweek.com/cisa-confirms-exploitation-of-recent-oracle-identity-manager-vulnerability/?utm_source=openai))
6 months ago
Kill Chain
Oracle Fusion Middleware 2026 Critical RCE Vulnerability
In January 2026, Oracle disclosed a critical remote code execution (RCE) vulnerability, CVE-2026-21962, affecting Oracle Fusion Middleware components, including Oracle HTTP Server and WebLogic Server Proxy Plug-ins. This flaw allows unauthenticated attackers with network access via HTTP to compromise affected servers, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of the affected components. Oracle released patches as part of their January 2026 Critical Patch Update to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unauthenticated RCE flaws in widely used enterprise software. Organizations are urged to apply the provided patches promptly to mitigate potential risks associated with this vulnerability.
6 months ago
Kill Chain
Ubiquiti UniFi Access Vulnerability: Unauthenticated API Exposure
In October 2025, Ubiquiti's UniFi Access Application was found to have a critical vulnerability (CVE-2025-52665) that exposed a management API without proper authentication. This flaw, present in versions 3.3.22 through 3.4.31, allowed attackers with access to the management network to gain unauthorized control over door access systems, posing significant risks to physical security. Ubiquiti addressed the issue by releasing version 4.0.21, which rectified the misconfiguration. This incident underscores the importance of promptly updating software to mitigate security vulnerabilities. Organizations are advised to review their access control systems and ensure that all applications are updated to the latest secure versions to prevent unauthorized access and potential breaches.
6 months ago
Kill Chain
Cisco FMC 2026: Interlock Ransomware's Exploitation of Insecure Deserialization
In early 2026, a critical vulnerability (CVE-2026-20131) was discovered in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allowed unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. The Interlock ransomware group actively exploited this vulnerability as a zero-day since late January 2026, targeting several high-profile organizations, including DaVita, Kettering Health, the Texas Tech University System, and the city of Saint Paul, Minnesota. The exploitation of CVE-2026-20131 underscores the persistent threat posed by sophisticated ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching and robust security measures to mitigate such risks.
6 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager: Immediate Action Required
In March 2026, Oracle released an out-of-band security update to address a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-21992, in Oracle Identity Manager and Oracle Web Services Manager. This flaw, with a CVSS score of 9.8, allows remote attackers to execute arbitrary code without authentication, posing significant risks to enterprise identity and access management systems. Organizations are strongly advised to apply the provided patches immediately to mitigate potential exploitation. The urgency of this update underscores the increasing trend of attackers targeting identity management systems, which serve as gateways to sensitive enterprise resources. Ensuring the security of such systems is paramount, as their compromise can lead to widespread unauthorized access and data breaches.
6 months ago
Kill Chain
Apple iOS 2026: Addressing the Threat of Coruna and DarkSword Exploit Kits
In early 2026, Apple identified and patched critical vulnerabilities in iOS that were actively exploited by sophisticated exploit kits, notably 'Coruna' and 'DarkSword'. These kits targeted older iPhone models running outdated iOS versions, enabling attackers to execute arbitrary code and steal sensitive data through malicious web content. The 'Coruna' exploit kit, in particular, contained 23 exploits spanning four years of iOS versions, posing a significant threat to users who had not updated their devices. ([macrumors.com](https://www.macrumors.com/2026/03/05/ios-exploit-kit-lockdown-mode-stops-it/?utm_source=openai)) The exploitation of these vulnerabilities underscores the evolving tactics of cybercriminals and the importance of timely software updates. The incidents highlight the necessity for organizations and individuals to maintain up-to-date systems to mitigate the risk of such sophisticated attacks.
6 months ago
Kill Chain
The Rise of AI-Enabled Cyberattacks in 2026
In 2025, organizations worldwide faced a record 1,968 cyber attacks per week—a 70% increase since 2023—driven by attackers leveraging AI and automation. AI has enabled more scalable, personalized, and coordinated attacks, resulting in widespread operational disruption and harm to organizations across multiple sectors. ([oecd.ai](https://oecd.ai/fr/incidents/2026-01-27-5416?utm_source=openai)) The rapid adoption of AI by cybercriminals has led to a significant escalation in the speed and sophistication of attacks. The average breakout time—how fast attackers move within a network after initial access—has dropped to just 29 minutes, a 65% increase from the previous year. ([techradar.com](https://www.techradar.com/pro/security/crowdstrike-says-attackers-are-moving-through-networks-in-under-30-minutes?utm_source=openai))
6 months ago
Kill Chain
Critical Langflow Vulnerability CVE-2026-33017: Immediate Action Required
In March 2026, a critical vulnerability (CVE-2026-33017) was discovered in Langflow, an AI workflow platform, allowing unauthenticated remote code execution via the /api/v1/validate/code endpoint. Exploitation began within 20 hours of disclosure, leading to potential full system compromise. Organizations using Langflow are urged to update to version 1.8.0 immediately to mitigate this risk. This incident underscores the rapid weaponization of newly disclosed vulnerabilities and the necessity for prompt patching to protect AI infrastructure.
6 months ago
Kill Chain
Beast Ransomware's SMB Port Scanning Tactics in 2025
In February 2025, the Beast ransomware group emerged as a Ransomware-as-a-Service (RaaS) platform, evolving from the earlier Monster ransomware strain. By August 2025, they had publicly disclosed attacks on 16 organizations across the United States, Europe, Asia, and Latin America, targeting sectors such as manufacturing, construction, healthcare, business services, and education. The group's primary distribution method involves scanning for active Server Message Block (SMB) ports within compromised networks, facilitating rapid lateral movement and widespread encryption of shared resources. This aggressive propagation strategy has led to significant operational disruptions and data breaches for affected organizations. The Beast ransomware's focus on exploiting SMB vulnerabilities underscores the critical need for organizations to secure internal network protocols and implement robust segmentation strategies. As ransomware tactics continue to evolve, understanding and mitigating such sophisticated attack vectors remain paramount for maintaining cybersecurity resilience.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports