Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Critical Reverse Proxy Vulnerabilities in Fabio and OAuth2-Proxy Expose Web Applications to Attacks
In 2025, critical vulnerabilities were identified in two widely used reverse proxy applications: Fabio and OAuth2-Proxy. CVE-2025-48865 in Fabio allowed attackers to manipulate the Connection header, enabling the removal of security-critical X-Forwarded headers, potentially leading to unauthorized access to backend systems. Similarly, CVE-2025-64484 in OAuth2-Proxy permitted authenticated users to inject underscore variants of X-Forwarded-* headers, bypassing the proxy's filtering logic and potentially escalating privileges in upstream applications. Both vulnerabilities stemmed from improper handling and normalization of HTTP headers, exposing significant security risks in web architectures. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48865?utm_source=openai)) These incidents underscore the systemic issues in reverse proxy implementations, highlighting the need for rigorous validation and normalization of HTTP headers to prevent similar exploits. Organizations must prioritize updating affected systems and implementing robust security measures to mitigate such vulnerabilities.
6 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for the Medical Tech Industry
In March 2026, Stryker Corporation, a leading U.S.-based medical technology company, suffered a significant cyberattack orchestrated by the Iran-linked group Handala Hack. The attackers infiltrated Stryker's network, deploying wiper malware that erased data from over 200,000 devices and exfiltrated more than 50 terabytes of sensitive information. This breach disrupted operations across 79 countries, affecting both corporate and personal devices connected through Stryker's mobile device management software. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/iran-hacking-group-claims-attack-on-med-tech-company-stryker-says-over-200-000-devices-have-been-wiped-clean-and-over-50tb-of-data-extracted?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks targeting critical infrastructure and private sector entities. The use of wiper malware by nation-state actors highlights the need for robust cybersecurity measures and proactive defense strategies to mitigate such risks.
6 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
In March 2026, Stryker, a leading U.S. medical technology company, experienced a significant cyberattack attributed to the Iranian-linked hacking group Handala. The attackers claimed to have wiped over 200,000 systems and extracted 50 terabytes of critical data, leading to widespread operational disruptions across Stryker's global network. The attack was reportedly in retaliation for U.S. military actions in Iran. ([techradar.com](https://www.techradar.com/pro/security/an-unprecedented-blow-us-medtech-giant-stryker-suffers-global-outage-after-apparent-iranian-cyberattack?utm_source=openai)) This incident underscores the escalating cyber threats targeting critical healthcare infrastructure, highlighting the need for robust cybersecurity measures to protect sensitive data and ensure operational continuity in the face of nation-state-sponsored cyberattacks.
6 months ago
Kill Chain
DigitalMint 2023 BlackCat Ransomware Insider Attack
In 2023, former employees of DigitalMint and Sygnia, cybersecurity firms specializing in ransomware incident response, exploited their positions to collaborate with the BlackCat (ALPHV) ransomware group. They conducted multiple ransomware attacks against U.S. organizations, including a medical device company that paid approximately $1.2 million in ransom. The perpetrators utilized their insider knowledge to infiltrate systems, encrypt data, and extort victims, sharing a portion of the ransoms with BlackCat administrators. This case underscores the critical risk posed by insider threats within cybersecurity firms. The incident highlights the necessity for robust internal controls and continuous monitoring to prevent such breaches. Organizations must remain vigilant against the evolving tactics of ransomware groups and the potential for trusted insiders to become malicious actors.
6 months ago
Kill Chain
Veeam's 2026 Critical RCE Vulnerabilities: Immediate Action Required
In March 2026, Veeam Software disclosed and patched multiple critical remote code execution (RCE) vulnerabilities in its Backup & Replication (VBR) solution, specifically CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, and CVE-2026-21708. These flaws allowed low-privileged domain users to execute remote code on vulnerable backup servers, posing significant risks to data integrity and system security. The vulnerabilities were addressed in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067. The disclosure underscores the persistent targeting of backup solutions by ransomware groups, as compromised VBR servers can facilitate lateral movement within networks and impede data restoration efforts. Organizations are urged to promptly apply the patches to mitigate potential exploitation and enhance their cybersecurity posture.
6 months ago
Kill Chain
Critical n8n RCE Vulnerability (CVE-2025-68613) Leads to System Compromise
In December 2025, a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2025-68613, was discovered in n8n, an open-source workflow automation platform. This flaw, present in versions from 0.211.0 up to but not including 1.120.4, 1.121.1, and 1.122.0, allows authenticated users to execute arbitrary code with the privileges of the n8n process. Exploitation can lead to full system compromise, including unauthorized data access and workflow manipulation. Despite patches being released, as of early February 2026, over 24,700 unpatched instances remain exposed online, with significant concentrations in North America and Europe. The inclusion of CVE-2025-68613 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to address this issue. The widespread exposure highlights the critical need for prompt patching and vigilant security practices to mitigate potential exploitation risks.
6 months ago
Kill Chain
AI-Generated Slopoly Malware Facilitates Interlock Ransomware Attack in 2026
In March 2026, a new malware strain named Slopoly, likely created using generative AI tools, was utilized in an Interlock ransomware attack. The breach began with a ClickFix social engineering tactic, leading to the deployment of Slopoly as a PowerShell script acting as a client for the command-and-control framework. This allowed the threat actor to maintain access to the compromised server for over a week, during which data was exfiltrated prior to encryption. The attack was attributed to Hive0163, a financially motivated group focused on extortion through large-scale data exfiltration and ransomware. The use of AI-generated malware like Slopoly indicates a significant evolution in cyber threats, enabling attackers to develop custom malware rapidly and potentially evade traditional detection mechanisms. This incident underscores the urgent need for organizations to enhance their cybersecurity defenses against increasingly sophisticated and AI-assisted attack vectors.
6 months ago
Kill Chain
Phishing Attack Trends 2026: Rising Threats and Evolving Tactics
In 2025, phishing attacks surged by over 20%, with attackers leveraging advanced social engineering techniques and AI-generated content to craft highly convincing lures. This evolution led to a significant increase in successful breaches, resulting in substantial financial losses and compromised sensitive data across various sectors. The proliferation of Phishing-as-a-Service kits enabled even less-skilled cybercriminals to execute large-scale campaigns, further exacerbating the threat landscape. ([trustnetinc.com](https://trustnetinc.com/resources/phishing-threats-2026/?utm_source=openai)) The current relevance of this trend is underscored by the continuous refinement of phishing tactics, including the use of AI to automate and personalize attacks, making them more effective and harder to detect. Organizations must remain vigilant and adapt their security measures to counter these evolving threats effectively. ([cloudsek.com](https://www.cloudsek.com/knowledge-base/top-phishing-attack-trends?utm_source=openai))
6 months ago
Kill Chain
Phishing Campaigns Overwhelm SOC Analysts in 2026
In early 2026, cybersecurity firms observed a surge in sophisticated phishing campaigns designed not only to deceive employees but also to inundate Security Operations Centers (SOCs) with an overwhelming volume of alerts. Attackers utilized automated tools to dispatch thousands of phishing emails, many of which were low-sophistication lures intended to flood SOCs with reports. Amidst this deluge, highly targeted spear-phishing emails were sent to individuals with critical system access, effectively camouflaging these high-risk threats within the noise. This tactic led to significant delays in threat detection and response, increasing the likelihood of successful breaches. This trend underscores a critical shift in cyberattack strategies, where adversaries exploit the operational limitations of SOCs, particularly their capacity to process high volumes of alerts. The effectiveness of these campaigns highlights the urgent need for organizations to enhance their SOC capabilities, incorporating advanced automation and AI-driven tools to manage alert triage efficiently and mitigate the risk of alert fatigue among analysts.
6 months ago
Kill Chain
Hive0163's AI-Generated Slopoly Malware: A New Era of Ransomware Attacks
In early 2026, the financially motivated threat actor Hive0163 executed a ransomware attack utilizing an AI-generated malware named Slopoly. The attack began with a social engineering tactic called ClickFix, tricking victims into executing a PowerShell command that downloaded NodeSnake, a known malware associated with Hive0163. NodeSnake established persistence and facilitated the deployment of Interlock RAT, which in turn delivered Slopoly. Slopoly, developed with the assistance of a large language model, functioned as a backdoor, maintaining persistent access to the compromised server for over a week. It communicated with a command-and-control server, enabling the execution of commands and exfiltration of data. This incident underscores the evolving threat landscape where AI is leveraged to expedite malware development, reducing the time required for threat actors to create and deploy sophisticated attacks. The use of AI in malware creation signifies a shift towards more efficient and scalable cyber threats, necessitating enhanced defensive measures and vigilance.
6 months ago
Kill Chain
Cyberhaven's 2024 Chrome Extension Breach: A Supply Chain Attack Case Study
In December 2024, Cyberhaven, a data-loss prevention company, experienced a significant security breach when attackers compromised their Chrome Web Store account through a phishing attack. This allowed the publication of a malicious update (version 24.10.4) to their Chrome extension, which was automatically distributed to users. The compromised extension exfiltrated sensitive data, including authenticated sessions and cookies, to an attacker-controlled domain. The malicious version was available for approximately 25 hours before detection and removal. ([techcrunch.com](https://techcrunch.com/2024/12/27/cyberhaven-says-it-was-hacked-to-publish-a-malicious-update-to-its-chrome-extension/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting browser extensions. With the increasing reliance on browser-based tools in enterprise environments, such attacks can lead to widespread data breaches and operational disruptions. Organizations must enhance their security protocols to mitigate such risks.
6 months ago
Kill Chain
INC Ransomware Group's 2025 Assault on Oceania's Healthcare Sector
Between July 2024 and December 2025, the INC Ransomware Group orchestrated a series of attacks targeting healthcare organizations across Australia, New Zealand, and Tonga. Utilizing tactics such as spear-phishing, exploitation of unpatched systems, and leveraging credentials from initial access brokers, the group infiltrated networks, exfiltrated sensitive data, and deployed ransomware to encrypt critical systems. Notably, in June 2025, INC disrupted Tonga's Ministry of Health, effectively shutting down core national services. ([darkreading.com](https://www.darkreading.com/threat-intelligence/inc-ransomware-healthcare-oceania?utm_source=openai)) This incident underscores the escalating threat of ransomware attacks on the healthcare sector, emphasizing the need for robust cybersecurity measures, timely patch management, and comprehensive incident response strategies to safeguard patient data and ensure the continuity of essential health services.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports