Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Google API Keys Expose Gemini AI Data in 2026
In February 2026, security researchers discovered that previously non-sensitive Google API keys embedded in client-side code could be exploited to access Google's Gemini AI services, leading to potential unauthorized data access and financial implications. This vulnerability arose when developers enabled the Gemini API in existing projects, inadvertently granting these exposed keys access to sensitive endpoints without any alerts or notifications. The issue affected numerous organizations, including major financial institutions and even Google's own infrastructure, with over 2,800 live API keys found publicly exposed. In response, Google implemented measures to detect and block leaked API keys attempting to access the Gemini API and advised developers to audit and rotate any exposed keys immediately. This incident underscores the critical importance of secure API key management and the need for developers to regularly review and update their security practices to prevent unauthorized access and potential data breaches.
6 months ago
Kill Chain
Trend Micro Apex One 2026 Critical RCE Vulnerabilities
In February 2026, Trend Micro identified and patched two critical vulnerabilities (CVE-2025-71210 and CVE-2025-71211) in its Apex One endpoint security platform. These flaws, both with a CVSS score of 9.8, allowed unauthenticated remote attackers to execute arbitrary code via path traversal weaknesses in the management console. Exploitation required access to the console, posing significant risks to organizations with externally exposed management interfaces. Trend Micro released Critical Patch Build 14136 to address these issues and advised customers to update promptly. This incident underscores the persistent threat posed by vulnerabilities in security management consoles, emphasizing the need for organizations to implement stringent access controls and maintain up-to-date systems to mitigate potential exploitation.
6 months ago
Kill Chain
Harvest Now, Decrypt Later: The Quantum Computing Threat
The 'Harvest Now, Decrypt Later' (HNDL) strategy involves adversaries collecting encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current cryptographic algorithms. This approach poses a significant threat to sensitive information with long-term confidentiality requirements, such as financial records, healthcare data, and intellectual property. Organizations must proactively transition to post-quantum cryptographic (PQC) algorithms to safeguard their data against future quantum-enabled decryption attacks. ([prnewswire.com](https://www.prnewswire.com/news-releases/harvest-now-decrypt-later-attacks-pose-a-security-concern-as-organizations-consider-implications-of-quantum-computing-301628445.html?utm_source=openai)) The urgency to address HNDL threats is underscored by the rapid advancements in quantum computing. Experts predict that cryptographically relevant quantum computers could emerge within the next decade, rendering existing encryption methods obsolete. ([docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/the-quantum-computing-threat?utm_source=openai))
6 months ago
Kill Chain
UAT-10027's Dohdoor Backdoor: A New Threat to U.S. Education and Healthcare
In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai)) This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai))
6 months ago
Kill Chain
Anthropic's Claude Code Vulnerabilities Expose Developers to Security Risks
In late 2025, security researchers identified critical vulnerabilities in Anthropic's AI-powered development tool, Claude Code. These flaws, specifically CVE-2025-59536 and CVE-2026-21852, allowed attackers to execute arbitrary code and steal API keys by exploiting project configuration files. By manipulating these files, malicious actors could trigger unauthorized actions when developers opened compromised repositories, potentially compromising developer machines and enterprise resources. Anthropic promptly addressed these issues by releasing patches to mitigate the risks. This incident underscores the evolving threat landscape as AI tools become integral to software development workflows. The exploitation of AI-driven tools for supply chain attacks highlights the need for enhanced security measures and vigilance in managing development environments. Organizations must adapt their security protocols to address the unique challenges posed by AI integration in their software supply chains.
6 months ago
Kill Chain
FBI Seizes RAMP Cybercrime Forum, Disrupting Ransomware Operations
In January 2026, the FBI, in coordination with the U.S. Attorney’s Office for the Southern District of Florida and the Department of Justice’s Computer Crime and Intellectual Property Section, seized the RAMP cybercrime forum. Established in July 2021, RAMP was a Russian-language platform that openly permitted ransomware-as-a-service (RaaS) operations, serving as a hub for ransomware groups like LockBit, ALPHV/BlackCat, and RansomHub. The forum facilitated the promotion of RaaS activities, recruitment of affiliates, and trading of initial network access. The seizure disrupted a significant coordination point for ransomware operators, potentially leading to a short-term decline in ransomware attacks. However, the long-term impact remains uncertain as cybercriminals may migrate to alternative platforms or establish new forums. Law enforcement's access to RAMP's user data could lead to further investigations and arrests, underscoring the ongoing efforts to combat cybercrime.
6 months ago
Kill Chain
Critical Cisco Catalyst SD-WAN Vulnerability Exploited in the Wild
In February 2026, a critical vulnerability (CVE-2026-20127) was discovered in Cisco Catalyst SD-WAN Controller and Manager, allowing unauthenticated remote attackers to bypass authentication and gain administrative privileges. Exploitation involves sending crafted requests to the affected systems, enabling attackers to manipulate network configurations via NETCONF. This vulnerability has been actively exploited since at least 2023 by a sophisticated threat actor identified as UAT-8616. ([socradar.io](https://socradar.io/blog/cve-2026-20127-cisco-catalyst-sd-wan-auth-bypass/?utm_source=openai)) The incident underscores the persistent threat posed by vulnerabilities in widely used network infrastructure. Organizations must prioritize timely patching and implement robust access controls to mitigate such risks. ([fortra.com](https://www.fortra.com/security/emerging-threats/critical-vulnerability-affecting-cisco-catalyst-sd-wan?utm_source=openai))
6 months ago
Kill Chain
Critical Zyxel Router Vulnerability (CVE-2025-13942) Exposes Networks to Remote Attacks
In February 2026, Zyxel identified a critical command injection vulnerability (CVE-2025-13942) in the UPnP function of several router models, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders. This flaw allows unauthenticated remote attackers to execute operating system commands on affected devices by sending specially crafted UPnP SOAP requests. While the vulnerability has a CVSS score of 9.8, its exploitation is contingent upon both UPnP and WAN access being enabled, with the latter disabled by default. Zyxel has released security patches to address this issue and strongly advises users to update their firmware promptly. The significance of this vulnerability is underscored by the widespread deployment of Zyxel devices, often provided by internet service providers as default equipment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is monitoring multiple Zyxel vulnerabilities, highlighting the ongoing risk to network security.
6 months ago
Kill Chain
OpenClaw Supply Chain Attack 2026: Lessons Learned
In February 2026, the OpenClaw AI assistant platform faced a significant supply chain attack. Malicious actors uploaded over 230 compromised 'skills' to ClawHub, OpenClaw's skill repository, between January 27 and 29. These skills, often disguised as crypto trading tools, were designed to exfiltrate sensitive user data, including cryptocurrency wallets and browser information. The attack exploited OpenClaw's extensive system permissions, allowing unauthorized access to users' local files and networks. Additionally, a vulnerability in the Cline CLI tool led to the unintended installation of OpenClaw on approximately 4,000 developer systems, further expanding the attack's reach. ([cyware.com](https://www.cyware.com/resources/threat-briefings/daily-threat-briefing/cyware-daily-threat-intelligence-february-03-2026?utm_source=openai)) This incident underscores the escalating risks associated with AI-powered automation tools and their plugin ecosystems. The rapid adoption of such platforms, combined with insufficient security vetting of third-party extensions, has created new avenues for supply chain attacks. Organizations must prioritize stringent security measures, including thorough code reviews and robust authentication protocols, to mitigate these emerging threats.
6 months ago
Kill Chain
Critical FileZen Vulnerability Exploited: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen, a secure file transfer solution. This flaw allows authenticated users to execute arbitrary commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Exploitation requires valid user credentials, potentially obtained through phishing or credential stuffing. The vulnerability affects FileZen versions 4.2.1 to 4.2.8 and 5.0.0 to 5.0.10. Soliton Systems has released version 5.0.11 to address this issue. Organizations are urged to update immediately and review logs for unauthorized access. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by command injection flaws, emphasizing the need for robust input validation and timely patch management. The incident highlights the importance of monitoring for unauthorized access and maintaining strict access controls to mitigate potential breaches.
6 months ago
Kill Chain
Cisco SD-WAN Authentication Bypass Vulnerability Exploited by UAT-8616
In February 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, exploited by the threat actor UAT-8616 since at least 2023. This flaw allowed unauthenticated remote attackers to gain administrative access, manipulate network configurations, and establish persistent control over affected systems. The exploitation involved downgrading software versions to exploit older vulnerabilities, further escalating privileges. The incident underscores the persistent targeting of network infrastructure by sophisticated actors, emphasizing the need for vigilant monitoring and timely patching of critical vulnerabilities.
6 months ago
Kill Chain
Critical Vulnerabilities in SolarWinds Serv-U: Immediate Action Required
In February 2026, SolarWinds addressed four critical vulnerabilities in its Serv-U file transfer software, identified as CVE-2025-40538 through CVE-2025-40541. These flaws, each with a CVSS score of 9.1, could allow attackers with administrative privileges to execute arbitrary code as root. The vulnerabilities include broken access control, type confusion, and insecure direct object reference issues. While no active exploitation has been reported, similar past vulnerabilities have been targeted by threat actors, notably the China-based group Storm-0322. Organizations using Serv-U are urged to update to version 15.5.4 promptly to mitigate potential risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=openai))
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports