Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
ShadyPanda: 4.3 Million Impacted in Massive Malicious Browser Extension Attack (2024)
In early 2024, the ShadyPanda campaign targeted users of Chrome and Edge browsers by distributing over 4.3 million malicious extensions disguised as legitimate utilities. Attackers leveraged browser extension supply chains—often through fraudulent developer accounts and aggressive social engineering—to gain access to users’ browsing data, credentials, and sensitive online activity. The malware evolved over time, adapting to evade security controls and harnessing sophisticated capabilities to extract data, redirect web sessions, and facilitate persistent surveillance, affecting millions globally and highlighting gaps in browser marketplace vetting. This incident exemplifies a rapid escalation in supply-chain attacks focusing on widely used platforms like web browsers. The surge in malicious browser extension campaigns underscores the increasing sophistication of threat actors and the urgent need for organizations and individuals to be vigilant about third-party software, browser hygiene, and visibility into user-installed code.
8 months ago
Kill Chain
Coupang Data Breach 2024: 33 Million Customers Exposed in Massive Retail Incident
In early 2024, Coupang, South Korea's largest online retailer, reported a significant data breach affecting approximately 33.7 million customers. The incident involved unauthorized access to personal information, potentially including customer names, phone numbers, addresses, and partial payment details. Coupang disclosed the breach after detecting unusual access patterns and subsequently notified both customers and regulatory authorities. Initial investigations suggest attackers exploited vulnerabilities in Coupang's data management or access controls, raising concerns over the safeguarding of sensitive information in large-scale e-commerce environments. This breach is especially notable due to the unprecedented scale within the South Korean retail industry and highlights a broader trend of cybercriminals targeting high-profile, data-rich organizations. With customer trust and regulatory scrutiny at stake, organizations globally are urged to reassess their data security and compliance strategies.
8 months ago
Kill Chain
Glassworm Malware Returns: Third Wave Targets VS Code with Supply-Chain Attack (2024)
In early 2024, a new wave of the Glassworm malware campaign was discovered infiltrating the Microsoft Visual Studio Code and OpenVSX marketplaces with 24 malicious packages. These supply-chain attacks targeted software developers by masquerading as legitimate extensions, but upon installation delivered trojans capable of stealing sensitive files, authentication tokens, and establishing persistence for command-and-control activities. The campaign began in October 2023, with this third and most extensive wave compromising both trusted VS Code ecosystems and potentially impacting thousands who unknowingly downloaded tainted packages. The threat actors have not been formally attributed but demonstrated sophisticated understanding of both developer environments and software supply chains. This incident is a striking example of the increasing shift toward attacking upstream dependencies, leveraging trusted developer tools to gain footholds deeper in organizations. With open-source and third-party marketplaces under continuous attack, businesses face growing pressure to implement better package vetting and monitoring along with zero-trust segmentation and detection capabilities.
8 months ago
Kill Chain
Multi-Vector Breach: npm Worm, Firefox RCE, and M365 Email Raids Rock 2025
In December 2025, a coordinated multi-vector cyberattack was observed targeting organizations through the exploitation of critical zero-day vulnerabilities (CVEs), a resurgence of the npm InfoStealer Worm, a remote code execution flaw in Mozilla Firefox, and widespread credential compromise leading to Microsoft 365 email account takeovers. Attackers leveraged a blend of social engineering, poisoned open-source packages, and malicious links to infiltrate developer environments, gain access to corporate cloud accounts, and spread laterally via trusted supply chains. Impacted organizations faced the risk of sensitive data exfiltration, widespread internal compromise, and disruption of core IT services across software development and communications. This incident underscores the growing sophistication and scale of modern attack campaigns that blend supply chain, RCE, SaaS compromise, and worm tactics. The convergence of these vectors highlights the urgent need for zero trust segmentation, continuous threat detection, and cloud-specific defenses as attackers increasingly target developer and business collaboration tools.
8 months ago
Kill Chain
ShadyPanda: The 2024 Browser Extension Supply Chain Breach Impacting 4.3 Million Installs
In mid-2024, the threat actor group ShadyPanda executed a sophisticated supply chain attack by compromising five popular browser extensions, which had previously been legitimate and widely trusted. These extensions, with a cumulative total of over 4.3 million installs, were maliciously updated to include spyware functionality, enabling covert surveillance and data exfiltration from unsuspecting users. The malicious modifications went undetected for several months, enabling the attackers to harvest browser data, credentials, and potentially sensitive user files, impacting organizations and individuals globally before the extensions were finally removed following a report by Koi Security. This incident highlights the increasing trend of supply chain compromise via browser extension ecosystems, which often lack sufficient vetting and monitoring. The attack underscores growing regulatory and operational pressure to secure third-party components and software supply chains, especially as similar tactics proliferate across widely adopted digital platforms.
8 months ago
Kill Chain
Shai-hulud: npm Supply Chain Attack Hits Cloud Ecosystem
In early 2024, security researchers uncovered a major supply chain attack involving a new variant of the Shai-hulud malware worm, which propagated through poisoned npm packages targeting cloud-based development environments. The malware autonomously infiltrated thousands of systems, harvesting credentials and secrets from cloud infrastructure providers including AWS, Google Cloud Platform, and Azure. Attackers achieved persistence and lateral movement by exploiting weaknesses in east-west traffic controls, leveraging the npm ecosystem’s trust to escalate impact across enterprise CI/CD pipelines and critical workloads. The breach resulted in significant operational risks, requiring emergency remediation from affected organizations and cloud providers. This incident highlights the evolving sophistication of supply chain threats, especially in cloud-native environments where development speed often outpaces traditional security controls. Attackers are increasingly abusing open-source package repositories for automated, scalable attacks—raising concerns for both cloud security and compliance teams.
8 months ago
Kill Chain
November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure
In November 2025, the cybersecurity landscape was rocked by a surge of major incidents spanning data exposure at leading AI companies, a high-profile ransomware campaign by the Akira gang, and an unprecedented law enforcement operation targeting prolific malware families. Attackers leveraged advanced lateral movement and encryption bypass techniques, with Akira exfiltrating critical business data and setting new records for ransom hauls. Meanwhile, Operation Endgame—an international collaborative effort—dismantled several prominent malware botnets, arresting key operators and seizing digital infrastructure, all while organizations scrambled to contain threats and patch vulnerabilities across multi-cloud and hybrid environments. This period highlights a convergence of advanced extortion, data privacy, and large-scale coordinated response, reflecting escalating threat sophistication and the increasing pressure on organizations to meet evolving compliance and security demands.
8 months ago
Kill Chain
AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)
In early 2024, cybersecurity researchers observed a surge in the use of malicious, unrestricted large language models (LLMs) such as WormGPT 4 and KawaiiGPT. These AI-powered tools have been weaponized to generate sophisticated attack scripts—including ransomware encryptors and custom code for lateral movement—allowing even low-skilled threat actors to execute complex cyberattacks. Access to these malicious LLMs was facilitated via underground markets, democratizing advanced techniques and increasing the frequency and complexity of attacks targeting organizations across multiple sectors. This incident underscores a growing trend where AI-enabled cyber threats lower the barrier to entry for attackers. As malicious LLMs gain capabilities and proliferation increases, organizations face heightened risks from a new wave of adversaries and must adapt their defenses to address evolving, AI-driven tactics.
8 months ago
Kill Chain
Over 17,000 Secrets Exposed: Inside the 2024 GitLab Public Repository Incident
In early 2024, a security engineer conducting a large-scale scan of all 5.6 million public repositories hosted on GitLab Cloud uncovered more than 17,000 exposed secrets—such as API keys, credentials, and tokens—affecting over 2,800 unique domains. Although the incident did not involve a targeted cyberattack, the finding highlights the pervasive risk of accidental data exposure due to developer error or misconfiguration. The exposed secrets could have enabled threat actors to access sensitive services, launch attacks, or exfiltrate data unnoticed, exposing organizations to operational risk, reputational harm, and regulatory scrutiny. This discovery signals a growing trend as attackers increasingly automate scans for leaked credentials in public code repositories. With supply chain attacks, shadow IT, and cloud misconfigurations rising, such incidents underscore the urgency for automated secret scanning, centralized controls, and enhanced security training for development teams.
8 months ago
Kill Chain
Microsoft Teams Guest Access in 2025: Bypassing Defender Protections with Cross-Tenant Exploits
In late 2025, security researchers revealed a critical vulnerability in Microsoft Teams involving the platform's guest access feature. Attackers could exploit this cross-tenant blind spot by inviting victims to external Teams tenants, where Microsoft Defender for Office 365 protections set by the user’s home organization were bypassed. Instead, security controls depended on the external tenant’s environment, enabling malicious actors to deliver threats, such as phishing or malware, beyond the purview of corporate security policies. This weakness exposes organizations to significant business risk, allowing lateral phishing and potential data compromise through insufficient cloud policy enforcement. This incident underscores the ongoing risks inherent to cloud collaboration platforms where cross-tenant integrations are routine. The rapid adoption of hybrid work, increased SaaS reliance, and complex cloud permissions models are fueling new attack vectors that evade traditional endpoint and email security controls.
8 months ago
Kill Chain
Legacy Python Bootstrap Scripts Expose PyPI Supply Chain to Domain Takeover Risk
In June 2025, cybersecurity researchers at ReversingLabs uncovered a significant vulnerability in legacy Python packages distributed via PyPI. The weakness stems from outdated bootstrap scripts within the widely used zc.buildout automation tool, which reference external domains that have since become unregistered. This creates a supply chain attack risk: if an attacker registers one of these lapsed domains, they could host malicious code, which would be executed during package installation, compromising developer, CI/CD, or production environments. While there are no confirmed mass exploits yet, the affected ecosystem is large due to the extended usage of these packages. This incident is highly relevant as supply chain risks in open-source ecosystems continue to grow, and domain takeover remains a low-cost, high-impact attack vector. Increased attention to legacy codebases and dependency hygiene is essential as regulations tighten and attackers show rising interest in poisoning software development infrastructure.
8 months ago
Kill Chain
Gainsight-Salesforce 2025 Breach: A Wake-Up Call for SaaS Supply-Chain Security
In November 2025, Gainsight reported a security incident involving its SaaS applications integrated with Salesforce, after Salesforce observed suspicious API calls from non-allowlisted IP addresses linked to Gainsight services. This prompted Salesforce to revoke affected access tokens, limit integration capabilities, and initiate investigations, temporarily disrupting data flows for several customers and connected platforms such as Zendesk and HubSpot. Forensic analysis revealed threat activity tied to proxy/VPN infrastructure and IPs previously associated with the UNC6040 threat cluster, which had targeted Salesforce CRMs in past extortion campaigns, though no confirmed data exfiltration occurred. This incident exemplifies the persistent risk of supply-chain compromise through interconnected SaaS platforms, emphasizing how attackers can leverage trusted applications to pivot laterally and exploit enterprise data pipelines. With the steady rise in OAuth-based integrations and API dependency, businesses face mounting urgency to reevaluate third-party access, enforce zero-trust principles, and proactively monitor for anomalous behaviors within their SaaS ecosystems.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports