Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3057 threat reports
Page 146 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 17411752 / 3057 reports
CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog
Impact· CRITICAL

CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2021-22054, a server-side request forgery in Omnissa Workspace One UEM; CVE-2025-26399, a deserialization flaw in SolarWinds Web Help Desk; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager. Exploitation of these vulnerabilities allows unauthorized access to sensitive information and remote code execution on affected systems. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by unpatched software flaws. Organizations are urged to apply the necessary patches promptly to mitigate potential risks associated with these actively exploited vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Unveiling 'Zombie ZIP': A New Frontier in Malware Evasion
Impact· MEDIUM

Unveiling 'Zombie ZIP': A New Frontier in Malware Evasion

In March 2026, security researcher Chris Aziz unveiled a novel malware evasion technique termed 'Zombie ZIP.' This method involves manipulating ZIP file headers to mislead antivirus and endpoint detection systems into treating compressed malicious payloads as uncompressed data. Consequently, security tools scan the files without detecting the embedded threats. The technique proved effective against 50 out of 51 antivirus engines tested on VirusTotal. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/?utm_source=openai)) The emergence of 'Zombie ZIP' underscores the evolving sophistication of malware delivery methods, highlighting the need for enhanced detection mechanisms capable of identifying such deceptive techniques. Organizations must stay vigilant and update their security protocols to counteract these advanced evasion strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Exploit Salesforce Experience Cloud Misconfigurations in 2026 Data Breach
Impact· MEDIUM

ShinyHunters Exploit Salesforce Experience Cloud Misconfigurations in 2026 Data Breach

In March 2026, Salesforce disclosed that the ShinyHunters cybercriminal group exploited misconfigured Experience Cloud sites to access sensitive data from approximately 100 high-profile companies. The attackers utilized a modified version of the open-source tool AuraInspector to identify and exploit overly permissive guest user configurations, enabling unauthorized data extraction. Salesforce emphasized that the breach resulted from customer misconfigurations rather than inherent platform vulnerabilities. This incident underscores the critical importance of adhering to security best practices when configuring cloud services. Misconfigurations can lead to significant data breaches, as demonstrated by the ShinyHunters' exploitation of Salesforce Experience Cloud sites. Organizations must regularly review and secure their cloud configurations to prevent unauthorized access and data exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft SharePoint 2025 ToolShell Zero-Day Exploitation
Impact· CRITICAL

Microsoft SharePoint 2025 ToolShell Zero-Day Exploitation

In July 2025, a critical zero-day vulnerability, CVE-2025-53770, was discovered in Microsoft SharePoint, allowing unauthenticated remote code execution. Dubbed 'ToolShell,' this exploit enabled attackers to gain full control over affected servers, leading to data exfiltration and deployment of ransomware. The vulnerability stemmed from an incomplete fix of a 2020 issue, CVE-2020-1147, and was actively exploited by Chinese state-affiliated groups, including Storm-2603, Linen Typhoon, and Violet Typhoon. Over 400 organizations worldwide, including U.S. federal agencies and the National Nuclear Security Administration, were compromised. Microsoft released emergency patches for SharePoint Server 2019 and SharePoint Subscription Edition, but SharePoint Enterprise Server 2016 remained unpatched at the time. Organizations were urged to apply patches, rotate machine keys, and implement additional security measures to mitigate the threat. ([windowscentral.com](https://www.windowscentral.com/software-apps/were-witnessing-an-urgent-and-active-threat-microsoft-sharepoint-toolshell-vulnerability-is-being-attacked-globally?utm_source=openai)) This incident underscores the escalating risk of zero-day vulnerabilities and the rapid exploitation timelines by sophisticated threat actors. The 'ToolShell' attacks highlight the critical need for organizations to maintain vigilant patch management, continuous monitoring, and robust incident response strategies to defend against evolving cyber threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LeakyLooker Vulnerabilities: A Wake-Up Call for Cloud Security
Impact· HIGH

LeakyLooker Vulnerabilities: A Wake-Up Call for Cloud Security

In March 2026, Tenable Research disclosed nine critical cross-tenant vulnerabilities, collectively termed 'LeakyLooker,' in Google Looker Studio. These flaws allowed attackers to execute arbitrary SQL queries on victims' databases, leading to potential data exfiltration, insertion, and deletion across Google Cloud Platform (GCP) services. The vulnerabilities affected organizations utilizing connectors such as Google Sheets, BigQuery, Spanner, PostgreSQL, MySQL, and Cloud Storage. Google addressed these issues following responsible disclosure in June 2025. The 'LeakyLooker' vulnerabilities underscore the evolving threat landscape in cloud environments, highlighting the necessity for robust security measures and continuous monitoring. Organizations must remain vigilant against cross-tenant vulnerabilities to safeguard sensitive data and maintain compliance with industry standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
Impact· CRITICAL

FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

In early 2026, threat actors exploited vulnerabilities and weak credentials in FortiGate Next-Generation Firewall (NGFW) appliances to breach networks across healthcare, government, and managed service providers. By accessing these devices, attackers extracted configuration files containing service account credentials and network topology information, enabling unauthorized access to Active Directory environments and the enrollment of rogue workstations. The breaches were detected during lateral movement phases, preventing further escalation. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure devices, as their compromise can lead to significant data breaches and operational disruptions. The exploitation of such devices highlights the evolving tactics of threat actors targeting essential security appliances to gain deeper access into organizational networks. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Odido's 2026 Data Breach: A Case Study in Social Engineering Attacks
Impact· HIGH

Odido's 2026 Data Breach: A Case Study in Social Engineering Attacks

In February 2026, Dutch telecom provider Odido experienced a significant data breach affecting over 6 million customer accounts. Attackers employed social engineering tactics, including phishing emails and impersonation of IT staff, to gain unauthorized access to Odido's customer relationship management system. This breach exposed sensitive personal information such as names, addresses, telephone numbers, bank account details, dates of birth, and government-issued ID numbers. The incident underscores the critical need for robust employee training and advanced security measures to prevent similar attacks. ([cybernews.com](https://cybernews.com/security/odido-hackers-phishing-attack/?utm_source=openai)) This breach highlights a growing trend of cybercriminals leveraging sophisticated social engineering techniques to infiltrate organizations. As these methods become more prevalent, companies must enhance their security protocols and employee awareness programs to mitigate the risk of such attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Beware of 'InstallFix' Attacks: Fake Claude Code Sites Spreading Malware
Impact· HIGH

Beware of 'InstallFix' Attacks: Fake Claude Code Sites Spreading Malware

In March 2026, a cyberattack campaign known as 'InstallFix' targeted developers by creating fake installation pages for Anthropic's Claude Code, an AI coding assistant. These counterfeit sites, promoted through Google-sponsored ads, closely mimicked legitimate pages and instructed users to execute malicious commands in their terminals. This led to the deployment of Amatera Stealer malware, which harvested sensitive information such as browser credentials and cryptocurrency wallets, potentially compromising enterprise development environments. This incident underscores the growing trend of attackers exploiting the widespread practice of copying and pasting commands from online sources. It highlights the urgent need for heightened vigilance and verification of software installation sources to prevent similar social engineering attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Three Known Exploited Vulnerabilities to Catalog

On March 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-22054, a Server-Side Request Forgery (SSRF) in VMware Workspace ONE UEM; CVE-2025-26399, an unauthenticated deserialization flaw in SolarWinds Web Help Desk's AjaxProxy component; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager (EPM). Each of these flaws presents significant risks, such as unauthorized access, remote code execution, and credential disclosure, potentially leading to full enterprise compromise. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate the risks associated with these actively exploited vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4
Impact· CRITICAL

Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4

In February 2026, a critical SQL injection vulnerability (CVE-2026-21643) was discovered in Fortinet's FortiClient Endpoint Management Server (EMS) version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet promptly released version 7.4.5 to address this issue, urging all users to upgrade immediately. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21643?utm_source=openai)) This incident underscores the persistent threat posed by SQL injection vulnerabilities, especially in widely used enterprise security solutions. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate such risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems
Impact· MEDIUM

AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems

In March 2026, Palo Alto Networks' Unit 42 researchers unveiled a critical vulnerability in AI 'judge' systems, which are large language models (LLMs) employed to enforce security policies and evaluate outputs. Utilizing a tool named AdvJudge-Zero, the researchers demonstrated that these AI judges could be manipulated through stealthy input sequences, a form of prompt injection, to bypass security controls. The attack exploits the models' decision-making processes, allowing unauthorized actions without detection. This vulnerability underscores the need for robust defenses against adversarial manipulations in AI systems. The discovery highlights the growing sophistication of prompt injection attacks, emphasizing the urgency for organizations to reassess and fortify their AI security measures. As AI integration deepens across industries, understanding and mitigating such vulnerabilities becomes paramount to maintaining trust and operational integrity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security
Impact· HIGH

ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security

In March 2026, the cybercriminal group ShinyHunters initiated a series of data theft attacks targeting misconfigured Salesforce Experience Cloud instances. By exploiting excessive permissions granted to guest user profiles, the attackers accessed sensitive data without authentication. Utilizing a modified version of the AuraInspector tool, they identified and exploited these vulnerabilities, compromising approximately 300 to 400 organizations, many within the cybersecurity sector. The breaches led to unauthorized access to vast amounts of customer and corporate data, raising significant concerns about data security and privacy. This incident underscores the critical importance of proper configuration and access control in cloud platforms. Organizations are urged to audit guest user permissions, adhere to the principle of least privilege, and monitor for unusual access patterns to mitigate such risks. The event highlights the evolving tactics of threat actors and the necessity for continuous vigilance in cybersecurity practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports