Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
CISA Warns of Critical 2025 ICS Vulnerabilities in WHILL C2 and AzeoTech DAQFactory
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) publicly released advisories highlighting multiple serious vulnerabilities in two industrial control systems: the WHILL C2 Wheelchairs and AzeoTech DAQFactory software. These advisories outlined critical flaws that could permit unauthorized access, remote code execution, or control manipulation within industrial and healthcare environments if left unmitigated. Attackers exploiting these gaps could compromise patient safety with wheelchairs or disrupt automation and process monitoring within industrial facilities, directly impacting operational continuity and patient care. This disclosure underscores intensifying cybersecurity scrutiny of industrial and medical control systems, which are increasingly targeted due to digitization and legacy design shortcomings. The rapid emergence of similar threats and increased regulatory focus make swift mitigation and robust ICS security controls more vital than ever.
8 months ago
Kill Chain
SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers
In December 2025, Singapore's Cyber Security Agency (CSA) issued an alert concerning a critical pre-authentication vulnerability (CVE-2025-52691) in SmarterTools SmarterMail email servers. The flaw allows unauthenticated remote attackers to upload arbitrary files to any location on the server, leveraging an unvalidated GUID parameter for path traversal via the '/api/upload' endpoint. An attacker could exploit this for remote code execution, potentially resulting in full compromise of the server, with malicious files executed under system privileges. Although no in-the-wild exploitation has been confirmed, more than 16,000 vulnerable public-facing servers were identified globally. This incident underscores growing risks from exposed infrastructure and rapid exploitation of high-severity application flaws. With threat actors increasingly targeting business-critical communication platforms, organizations face mounting pressure to quickly remediate vulnerabilities and bolster segmentation and detection capabilities in line with zero trust frameworks.
8 months ago
Kill Chain
Critical Bluetooth Vulnerability Exposes WHILL Medical Wheelchairs
In December 2025, a critical IoT vulnerability (CVE-2025-14346) was disclosed in WHILL Model C2 Electric Wheelchairs and Model F Power Chairs, widely used in healthcare and public health sectors. Researchers discovered that these devices failed to enforce authentication for Bluetooth connections, enabling attackers within physical range to pair, take full control, issue movement commands, bypass safety restrictions, and alter configuration profiles with no user credentials required. The issue impacted all device versions, prompting emergency firmware mitigations from WHILL Inc. to restrict unauthorized access and manipulation. This incident underscores urgent risks associated with the growing attack surface in medical IoT and connected healthcare devices. Increasing reliance on wireless interfaces heightens exposure to exploitation, mandating stronger security and authentication measures as the threat landscape evolves.
8 months ago
Kill Chain
MongoBleed 2025: Global Memory Leak Puts MongoDB Data at Risk
In December 2025, a high-severity vulnerability named MongoBleed (CVE-2025-14847) was identified in multiple MongoDB versions with default settings, allowing unauthenticated attackers to leak sensitive server memory, including credentials and access tokens. Public disclosure and proof-of-concept code triggered a surge in exploitation, leaving more than 75,000 vulnerable instances exposed globally. Security researchers highlight the ease of exploitation, scale of potentially affected organizations, and absence of forensic evidence, which complicates post-incident investigations and raises the risk of undetected data exposure. Countries most affected include China, the United States, and several European and Asian nations. This incident underscores the urgent risk posed by memory-leak vulnerabilities in widely deployed open-source technologies and highlights the accelerating cycle from disclosure to weaponization. It also signals how reduced staffing during holiday periods can hinder detection and response, contributing to lingering risks and delayed mitigation.
8 months ago
Kill Chain
Coupang’s $1.17B Insider Data Breach Puts Spotlight on Retail Security
In June 2024, Coupang, South Korea’s largest online retailer, announced a data breach impacting 33.7 million customers after discovering unauthorized access to customer data in May 2024. The breach, attributed to an insider threat, exposed sensitive information including names, contact details, and purchase histories. Coupang committed $1.17 billion (1.685 trillion KRW) in compensation, underlining the massive scale and business impact. Investigations revealed misuse of privileged access led to the data exfiltration, making this one of Korea’s most significant consumer data breaches. This incident highlights escalating risks from insider threats amid expanding data footprints in retail and e-commerce. In the wake of regulatory scrutiny and increasing consumer privacy demands, organizations face mounting pressure to implement advanced east-west traffic monitoring, zero trust segmentation, and comprehensive anomaly detection to protect sensitive customer data.
8 months ago
Kill Chain
KMSAuto Malware Campaign Leads to 2.8 Million Infections: Lithuanian Hacker Arrested
In early 2024, authorities arrested a Lithuanian national in connection with a large-scale malware campaign leveraging a trojanized version of KMSAuto, a popular software activation tool. The suspect is accused of distributing clipboard-stealing infostealer malware, which disguised itself as a utility for activating Windows and Office software. Over roughly two years, it is estimated that over 2.8 million downloads led to widespread infections, enabling the theft of sensitive data, including cryptocurrency wallet credentials, through malicious clipboard monitoring. This case highlights the persistent risk of malware-laden software masquerading as gray-market utilities, particularly where users bypass official software channels. The campaign demonstrates how threat actors continue to exploit user trust in widely circulated but unofficial tools, underlining the urgent need for supply chain vigilance and robust endpoint protection.
8 months ago
Kill Chain
When Threats Collide: 2025's Multi-Vector Breach Exposes Gaps from Database to Wallet
In December 2025, a rapid succession of cyber incidents targeted multiple sectors, blending attacks on exposed MongoDB instances, large-scale cryptocurrency wallet breaches, Android device spyware campaigns, and insider threat activity within enterprises. Attackers exploited both unpatched vulnerabilities and legitimate remote access mechanisms, leveraging high-speed lateral movements and targeting cloud infrastructures, regulated data, and financial assets. The breaches compromised sensitive customer data and business-critical systems, highlighting a coordinated pivot between vectors such as cloud misconfiguration, mobile malware, and abuse of internal access privileges. This wave underscores a growing convergence of threat vectors and the urgent need for unified defense frameworks. With attackers accelerating their use of automation, targeting east-west traffic, and blending traditional and emerging attack paths, organizations face mounting pressure to enhance multicloud visibility, segmentation, and real-time anomaly response.
8 months ago
Kill Chain
CISA Adds MongoDB CVE-2025-14847 to KEV Catalog Amid Active Exploitation
In December 2025, CISA added CVE-2025-14847 to its Known Exploited Vulnerabilities (KEV) Catalog following confirmation of active exploitation in the wild. The vulnerability, found in MongoDB and MongoDB Server, involves improper handling of length parameter inconsistencies, potentially enabling attackers to compromise data confidentiality and integrity through specially crafted requests. This flaw has become an attractive initial attack vector for threat actors targeting federal and private sector systems. The KEV listing triggers urgent remediation directives for federal agencies and strongly recommends private organizations act quickly to mitigate system and data risks. The designation of this MongoDB vulnerability underlines the continued focus of both attackers and defenders on widely used open-source software. As exploitation of unpatched vulnerabilities accelerates, industry and government face mounting regulatory and operational pressure to prioritize swift vulnerability management amid a rapidly evolving attack landscape.
8 months ago
Kill Chain
MongoDB Global Breach: Exploiting MongoBleed (CVE-2025-14847) for Data Exposure
In December 2025, a major security vulnerability (CVE-2025-14847), dubbed MongoBleed, was exploited globally across more than 87,000 MongoDB instances. This high-severity flaw in the default zlib compression feature of MongoDB servers enabled unauthenticated attackers to remotely leak sensitive information, including credentials and API keys, by sending specially crafted network packets that expose uninitialized heap memory. First disclosed by OX Security and corroborated by Wiz, the vulnerability’s impact is magnified in cloud environments and internet-exposed infrastructure, prompting urgent mitigation actions worldwide. The MongoBleed incident marks a significant escalation in memory exposure and pre-authentication exploitation methods targeting widely adopted cloud database technologies. The attack's broad reach and urgency have galvanized regulators and security teams, emphasizing the need for timely patching, network exposure reduction, and enhanced security policies for infrastructure software.
8 months ago
Kill Chain
n8n Workflow Automation Hit by Critical RCE Vulnerability (CVE-2025-68613)
In December 2025, a critical vulnerability (CVE-2025-68613) was disclosed in the popular open-source workflow automation tool n8n, allowing unauthenticated attackers to execute arbitrary code remotely under specific conditions. The flaw, rated CVSS 9.9, was identified by security researcher Fatih Çelik and reportedly affects thousands of publicly accessible n8n instances globally. By exploiting weak access controls and improper sanitization of user input, threat actors could gain control over affected servers, leading to potential data theft, lateral movement within networks, and disruption of workflow automations. This incident highlights the persistent risks posed by software supply chain vulnerabilities and the urgent need for organizations to monitor and remediate critical flaws in automation platforms. With workflow automation tools increasingly integrated into business operations, their exploitation represents a growing vector for both targeted and opportunistic cyberattacks.
8 months ago
Kill Chain
MongoBleed 2025: Critical MongoDB Vulnerability Exposes Data on 87K Servers
In early June 2025, the MongoBleed vulnerability (CVE-2025-14847) was actively exploited against MongoDB servers worldwide, exposing sensitive database secrets and credentials on over 87,000 publicly accessible systems. Attackers exploited a flaw present in multiple MongoDB versions, allowing unauthorized access to in-transit data and internal database secrets without authentication. The exposure occurred as a result of inadequate encryption and misconfiguration, providing an entry point for lateral movement, data exfiltration, and potentially further compromise of enterprise networks. Organizations in finance, healthcare, SaaS, and retail sectors have been especially impacted by this incident, given their widespread MongoDB adoption for critical workloads. This breach highlights an increasingly common pattern of weaponizing newly disclosed database vulnerabilities at scale by sophisticated threat actors. The incident underscores the urgent need for robust encryption practices, Zero Trust segmentation, and vigilant patch management to protect highly sensitive data and prevent large-scale exposure as regulatory scrutiny and attacker sophistication intensify.
8 months ago
Kill Chain
CISA Alerts: Digiever NVR Botnet Exploitation via CVE-2023-52163
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited vulnerability (CVE-2023-52163, CVSS 8.8) in Digiever DS-2105 Pro network video recorders. Attackers exploited a missing authorization flaw to perform remote code execution via command injection, requiring authentication. Security researchers confirmed that this vulnerability enabled the deployment of IoT botnets such as Mirai and ShadowV2, allowing attackers to gain persistent control and leverage compromised devices for further attacks. The product’s end-of-life status means no patch is available, compounding organizational risk for operators of affected models. This incident is part of a broader trend of threat actors targeting unpatched and unsupported IoT devices for malware delivery and botnet growth. With critical infrastructure and surveillance systems at risk, timely mitigation is paramount amid surging exploitation and regulatory pressure for proactive defense.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports