Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Mythic: The Growing Threat of Post-Exploitation C2 Frameworks in Network Traffic
In early 2024, cybersecurity researchers revealed the widespread use of the Mythic post-exploitation framework by multiple threat actors to gain persistent control of compromised networks. Mythic, a versatile multi-platform C2 (command and control) toolkit, has enabled adversaries to evade endpoint detection tools while moving laterally, collecting data, and exfiltrating sensitive assets. By leveraging covert channels such as HTTP(S), SMB, WebSocket, Discord, and GitHub APIs, attackers have masked their traffic from traditional network security defenses. Incident response teams observed tailored communication modules, pivoting tactics, and sophisticated data encoding, resulting in delayed detection and prolonged dwell time within targeted organizations. This incident highlights the growing challenge for defenders as open-source offensive frameworks become more advanced and widely adopted. The surge of network-based C2 detection evasion tactics underscores the need for enhanced behavioral analysis, encrypted traffic inspection, and updated NDR/IDS capabilities, especially as regulatory and compliance scrutiny intensifies.
8 months ago
Kill Chain
Varex Imaging 2025: Privilege Escalation Vulnerability in Dental Imaging Software
In December 2025, Varex Imaging disclosed a critical privilege escalation vulnerability (CVE-2024-22774, CVSS v4 8.5) affecting its Panoramic Dental Imaging Software (versions prior to 6.6.1.490). The flaw, caused by an uncontrolled search path element (CWE-427) in the SDK, could enable a standard user to gain NT Authority/SYSTEM privileges through DLL hijacking. While the vulnerability cannot be exploited remotely and no active exploitation has been reported, successful compromise could give attackers unrestricted system access in affected healthcare environments, with the potential to disrupt or manipulate sensitive imaging processes. This incident underscores the persistent risks of local privilege escalation vulnerabilities in healthcare software, especially where operational technology and patient systems converge. With increasing regulatory requirements and a rising focus on vertical-specific threats, incidents like this highlight the urgent need for robust patch management, secure software development practices, and vigilant network segmentation in healthcare environments.
8 months ago
Kill Chain
CISA’s 2025 ICS Advisories Expose Critical OT Vulnerabilities
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) published 12 critical advisories detailing multiple vulnerabilities affecting industrial control systems (ICS) from major vendors including Johnson Controls, Siemens, and Varex Imaging. These advisories highlight flaws exposed by threat assessments in device firmware, authentication mechanisms, remote access features, and legacy software within widely deployed ICS/OT products. An exploitation of these vulnerabilities could give adversaries access to critical operations, enable lateral movement within secure networks, or disrupt essential physical processes that underpin energy, healthcare, and manufacturing sectors. The occurrence underscores the ongoing risks posed by legacy and unpatched OT technology in critical infrastructure. A surge in targeted attacks against ICS environments, evolving regulatory requirements, and new threat intelligence guidance are elevating urgency for rapid remediation, modern zero trust approaches, and the adoption of robust segmentation and visibility controls.
8 months ago
Kill Chain
Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows
In December 2025, a significant vulnerability was disclosed in the Grassroots DICOM (GDCM) library, a critical open-source imaging component widely used in healthcare systems worldwide. Identified as CVE-2025-11266, this out-of-bounds write vulnerability could be triggered by simply opening a specially-crafted DICOM file, potentially crashing affected applications such as SimpleITK and medInria. The flaw, present in versions GDCM 3.0.24 and earlier, allows for denial-of-service and partial data and integrity impacts, increasing operational risk for healthcare environments that rely on medical imaging interoperability. This incident highlights the persistent risk posed by vulnerable third-party libraries in regulated industries like healthcare. The rise in supply chain threats and software dependencies magnifies the urgency for organizations to maintain rigorous patching practices and robust segmentation, as attackers increasingly target widely-deployed open-source components to disrupt critical services.
8 months ago
Kill Chain
Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal
In May 2024, security researchers uncovered an emerging Packer-as-a-Service (PaaS) called Shanya, designed to help ransomware operators evade modern enterprise defenses. Shanya provides advanced payload obfuscation capabilities to threat actors, enabling the delivery of ransomware that bypasses endpoint detection and response (EDR) solutions. Attackers using Shanya can rapidly pack malware before deployment, making it harder to analyze and detect. Early incidents showed Shanya-packed ransomware used to swiftly gain lateral movement across compromised environments, disrupt business operations, and facilitate significant data encryption and extortion campaigns. The rise of packers like Shanya signals a growing trend: ransomware groups are leveraging SaaS-style services to increase automation, evasion, and reach. With increased regulatory scrutiny on incident response and a surge in ransomware targeting sectors with critical operations, businesses must urgently strengthen detection and response strategies to address evolving malware delivery techniques.
8 months ago
Kill Chain
CISA & MITRE Unveil 2025 CWE Top 25: The Most Dangerous Software Weaknesses
On December 11, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) and MITRE's HSSEDI jointly released the 2025 CWE Top 25 Most Dangerous Software Weaknesses advisory. This annual compilation highlights the most critical security flaws that are routinely exploited by adversaries to gain unauthorized access, exfiltrate sensitive data, or disrupt operations. The advisory urges software vendors, developers, and enterprise security teams to integrate the Top 25 into their vulnerability management, procurement, and secure development practices, as the listed weaknesses are a leading cause of breaches and operational disruptions sector-wide. The 2025 iteration of the list arrives amid a surge in high-profile breaches linked to software supply chain vulnerabilities and regulatory pressure for Secure by Design practices. Organizations that fail to address these prevalent weaknesses remain at heightened risk of data compromise, operational downtime, and non-compliance with modern security frameworks.
8 months ago
Kill Chain
Microsoft’s 2024 Zero-Day Exploitation: What Security Leaders Must Know
In June 2024, Microsoft released security updates addressing a critical zero-day vulnerability (CVE-2024-30051) that was actively exploited in the wild, targeting Windows operating systems. Threat actors leveraged this privilege escalation flaw to bypass security controls and gain elevated access privileges on compromised systems, potentially enabling further malware deployment and lateral movement. Nearly 50 vulnerabilities were patched in this cycle, with public proof-of-concept code available for several, raising the risk of rapid exploitation by cybercriminal groups and nation-state actors before widespread patch deployment. This incident underscores the persistent threat of zero-day vulnerabilities, the speed at which exploits circulate once publicly disclosed, and the substantial business risk posed to enterprises delaying patch management. Increasing regulatory scrutiny and evolving attack techniques demand urgent, proactive defense strategies.
8 months ago
Kill Chain
Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks
In early 2024, threat actor Storm-0249 launched a series of stealthy attacks by weaponizing Endpoint Detection and Response (EDR) platforms alongside native Windows utilities. As an initial access broker, the group circumvented traditional EDR defenses to gain persistent entry into multiple enterprise environments. Leveraging legitimate EDR processes for their own activities, Storm-0249 was able to evade security monitoring, escalate privileges, and facilitate lateral movement. These tactics led to compromised data and footholds that were subsequently sold to other cybercriminal groups, increasing the overall risk for targeted organizations. The emergence of sophisticated actors repurposing security tools for malicious objectives highlights an urgent industry focus on advanced detection, segmentation, and the continual evolution of zero trust strategies. This incident reflects a growing trend: motivated threat groups exploiting trusted processes to blend in and extend dwell time inside modern network environments.
8 months ago
Kill Chain
AI Domain Impersonation Fuels 2024 ClickFix-Style Malware Surge
In early 2024, a cyberattack campaign known as the 'ClickFix Style Attack' emerged, exploiting cutting-edge social engineering and SEO poisoning techniques. Attackers leveraged widely searched AI-related domains such as Grok and ChatGPT, using search engine manipulation to lure unsuspecting users to weaponized websites. Once on these compromised pages, visitors were tricked into downloading malware under the guise of legitimate AI tools and browser extensions, enabling threat actors to gain persistent access to systems and exfiltrate sensitive data. The campaign highlights the growing sophistication and agility of attackers in blending trusted brands with social engineering ploys, ultimately threatening business operations and data integrity. This incident is particularly relevant as it showcases the convergence of AI hype, manipulated search results, and advanced social engineering, which increases the likelihood of successful malware delivery. Security teams must remain vigilant as attackers continue to target the widespread adoption of AI-driven tools and blur lines between legitimate and malicious sources.
8 months ago
Kill Chain
Microsoft December 2025 Patch Tuesday: Critical & Exploited Vulnerabilities Exposed
In December 2025, Microsoft addressed 57 vulnerabilities as part of its Patch Tuesday update, including three critical flaws and one (CVE-2025-62221) already being actively exploited. The vulnerabilities spanned across numerous Microsoft products such as Office, Outlook, Exchange, PowerShell, and the Windows Cloud Files Mini Filter driver. Notably, CVE-2025-64671 affected GitHub Copilot plugins for JetBrains, potentially enabling remote code execution via AI-driven code assistance. Attackers exploited privilege escalation and remote-code execution vectors, posing significant risks to system integrity and user data. The rapid disclosure and exploitation of some flaws before patches were available highlighted increasing attacker sophistication and speed. Incidents such as this emphasize the urgent need for timely patch management, especially as software supply chains and AI integrations become more prevalent. Security teams must remain vigilant against fast-emerging threats, as even mainstream platforms like Microsoft continue to face ongoing and complex exploitation attempts.
8 months ago
Kill Chain
Kubernetes NodeLogQuery (CVE-2024-9042): Command Injection Exploit Hits Windows Nodes
In late 2024, a command injection vulnerability in Kubernetes' NodeLogQuery feature (CVE-2024-9042) was actively exploited, primarily impacting clusters running Windows nodes with log read permissions enabled. Attackers leveraged the '/logs/' API endpoint, injecting operating system commands via GET parameters or path elements to gain unauthorized system access. Victims included enterprise environments utilizing the beta NodeLogQuery feature, which was not enabled by default. The exploit techniques involved turning Kubernetes' logging capabilities into a remote code execution avenue, exposing sensitive workloads to further compromise and potential lateral movement. This incident underscores a broader trend in targeting Kubernetes clusters at the API layer, as adversaries evolve their exploitation of cloud-native misconfigurations and insecure default settings. The attack highlights the need for enhanced east-west traffic controls, static analysis of cluster policies, and real-time anomaly detection to intercept emerging exploitation patterns in cloud and hybrid infrastructure.
8 months ago
Kill Chain
Microsoft Patches Critical Zero-Day in Windows: December 2025 Security Update
In December 2025, Microsoft issued patches for 57 vulnerabilities across its product suite as part of its final Patch Tuesday of the year. Notably, the release addressed an actively exploited zero-day vulnerability, CVE-2025-62221, impacting the Windows Cloud Files Mini Filter Driver. This use-after-free flaw, with a CVSS score of 7.8, allowed attackers to potentially gain system-level privileges when chained with code execution bugs. Affecting all supported versions of Windows, the vulnerability drew immediate attention from CISA and the cybersecurity community due to its presence in production environments and ongoing exploitation. The incident underscores a persistent trend of attackers targeting foundational Windows components through privilege escalation and memory management bugs. With the rising complexity of Microsoft’s ecosystem and a continued increase in vulnerabilities—especially as AI-related issues proliferate—organizations face growing pressure to rapidly deploy patches and strengthen monitoring against sophisticated exploits.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports