Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 227 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 27132724 / 3054 reports
F5 BIG-IP Breach 2024: Nation-State Attackers Exploit Zero-Day Flaws
Impact· medium

F5 BIG-IP Breach 2024: Nation-State Attackers Exploit Zero-Day Flaws

In June 2024, F5 Networks disclosed a significant security breach impacting its BIG-IP application delivery products. The incident involved a nation-state threat actor exploiting previously unknown (zero-day) vulnerabilities to gain unauthorized access to F5’s internal systems. Attackers reportedly obtained proprietary source code and, in some cases, limited customer information. Sophisticated post-exploitation techniques were used to move laterally and exfiltrate sensitive data, highlighting the attacker’s expertise and persistence. The breach raises concerns around the supply-chain risk for organizations deploying F5 BIG-IP solutions, as exploitation of this trusted infrastructure could jeopardize downstream customer networks. This incident underscores the escalating trend of nation-state actors targeting critical infrastructure and supply-chain vendors through advanced, stealthy attack methods. Given the widespread use of F5 products in enterprise and government IT environments, the breach has heightened industry awareness around zero-day vulnerabilities and supply-chain security best practices.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Harvard University Breached by Clop Ransomware: Oracle Zero-Day Attack Exposes Data
Impact· high

Harvard University Breached by Clop Ransomware: Oracle Zero-Day Attack Exposes Data

In the first half of 2024, Harvard University fell victim to a significant cyberattack orchestrated by the Clop ransomware group, exploiting a zero-day vulnerability in Oracle software. The threat actors gained unauthorized access to sensitive university data, exfiltrating large volumes as part of a broader campaign that targeted Oracle customers worldwide. The breach showcases how sophisticated ransomware groups leverage software supply chain weaknesses, often exploiting vulnerabilities before patches become available. As a result, Harvard faced disruption of operations, regulatory scrutiny, and potential exposure of sensitive academic and financial data. This incident underscores the escalating trend of ransomware operations exploiting zero-day flaws to target major institutions, particularly in the education sector. The attack highlights urgent needs for advanced segmentation, rapid patching, and proactive lateral movement prevention as ransomware groups become more aggressive and opportunistic.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft VS Code Marketplace Plugins Leak Sensitive Secrets: Supply Chain Alert
Impact· medium

Microsoft VS Code Marketplace Plugins Leak Sensitive Secrets: Supply Chain Alert

In early 2024, security researchers uncovered over 550 unique authentication secrets (such as API keys and credentials) leaking from extensions published on Microsoft's Visual Studio Code Marketplace. The exposed secrets, embedded within third-party extensions, created a major supply chain risk by potentially allowing attackers to compromise developer environments or escalate access to sensitive systems. Microsoft responded by enhancing its security review process, warning affected publishers, and initiating additional controls to prevent similar exposures in the future. This incident highlights the growing risks tied to open software ecosystems, where attackers increasingly target supply chain dependencies. With developer tools and plugin marketplaces at the core of modern workflows, secret leakage could enable widespread compromise, pushing organizations to urgently strengthen code supply chain security and compliance.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Surge Exposes Password Manager Vulnerabilities: Lessons from the 2024 LastPass Incident
Impact· low

Phishing Surge Exposes Password Manager Vulnerabilities: Lessons from the 2024 LastPass Incident

In early 2024, a series of highly targeted phishing campaigns were launched against users of LastPass and other leading password managers. Threat actors masqueraded as trusted service communications to exploit user trust, distributing convincing emails and fraudulent alerts to trick victims into providing master credentials or installing malicious software. Despite existing security controls, the attackers leveraged sophisticated social engineering and exploited the single point of failure inherent to password vaults, putting sensitive enterprise and personal accounts at risk. The attack underscores the vulnerability of credential management platforms to phishing-driven infiltration and the potential for widespread credential compromise. This incident highlights a surge in credential phishing tactics aimed at circumventing advanced security measures by exploiting human error. As password managers become more widespread, attackers are evolving methods to target the trust users place in these tools, emphasizing the need for continuous security awareness, robust MFA adoption, and proactive anomaly detection around high-value authentication solutions.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft Halts Rhysida Ransomware Campaign Abusing Azure Certificates
Impact· high

Microsoft Halts Rhysida Ransomware Campaign Abusing Azure Certificates

In early 2024, Microsoft uncovered and disrupted a sophisticated ransomware campaign in which attackers abused more than 200 stolen or forged Azure Active Directory certificates to sign malicious Microsoft Teams binaries. This campaign, attributed to the Rhysida ransomware group, enabled threat actors to appear as legitimate Microsoft services, bypassing security controls and delivering the final ransomware payloads to targeted enterprise environments. Following detection, Microsoft swiftly revoked the malicious certificates and worked with affected customers to mitigate the threat, limiting further operational and financial damage. This incident underscores the increased attacker focus on abusing trusted cloud identities and supply chain trust mechanisms to facilitate stealthy lateral movement and ransomware deployment. Organizations are now under greater pressure to strengthen certificate governance, cloud identity monitoring, and east-west traffic security controls as threat actors escalate the abuse of cloud-native infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
How Flawed Vendor Guidance Led to Oracle WAF Attacks in 2024
Impact· high

How Flawed Vendor Guidance Led to Oracle WAF Attacks in 2024

In 2024, Oracle E-Business Suite customers became vulnerable after the company released flawed guidance on deploying its Web Application Firewall (WAF), failing to mitigate a critical zero-day vulnerability. The lack of effective instructions enabled threat actors to exploit the misconfiguration, leading to ransomware attacks and potential data breaches for numerous enterprises. Attackers leveraged the window before official patches or updated configurations, gaining lateral movement and access to sensitive business operations. This incident highlighted how vendor missteps in supply-chain security can cascade across customer environments, amplifying operational risk and compliance exposure. The breach underscores the increasing risk associated with supply-chain vulnerabilities and misaligned vendor guidance. As sophisticated threats target misconfigurations and third-party solutions, organizations must reassess their reliance on default vendor instructions and proactively harden their environments against emerging TTPs.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
MuddyWater Hits Middle East Governments: Phishing, Phoenix Backdoor & VPN Abuse
Impact· low

MuddyWater Hits Middle East Governments: Phishing, Phoenix Backdoor & VPN Abuse

In early 2024, the Iranian state-sponsored group MuddyWater orchestrated a large-scale spear-phishing campaign targeting over 100 government entities across the Middle East and Africa. Attackers leveraged a compromised mailbox and NordVPN to distribute phishing emails enticing recipients to enable malicious macros. This led to the deployment of the Phoenix backdoor, providing attackers with persistent access and the ability to move laterally within targeted organizations’ networks, thereby raising concerns over significant data exposure and long-term espionage. The MuddyWater incident exemplifies the growing sophistication and scale of nation-state phishing campaigns. Recent trends show attackers are rapidly adapting credential theft and post-exploitation tactics to bypass traditional defenses. Government entities face mounting regulatory and operational pressure to address advanced persistent threats exploiting email and remote access.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Scattered LAPSUS$ Hunters Target Encrypted Traffic in 2024 Hybrid Cloud Breach
Impact· medium

Scattered LAPSUS$ Hunters Target Encrypted Traffic in 2024 Hybrid Cloud Breach

In early 2024, the cybercrime group Scattered LAPSUS$ Hunters was observed launching a series of attacks targeting high-performance encrypted traffic between enterprise environments. Leveraging advanced tactics such as packet sniffing and lateral movement across hybrid and multicloud networks, the group exploited weak internal segmentation and gaps in east-west traffic controls. The attackers circumvented some organizations’ use of line-rate encryption by targeting less-protected internal flows and using sophisticated threat detection evasion techniques. Operational impacts included service disruptions, potential data exfiltration, and compromised cloud environments. This incident underscores the evolution of cybercrime actors as they adopt more advanced methods to breach environments assumed to be protected by conventional encryption or traditional network segmentation. The trend highlights growing risks for enterprises relying on hybrid and multicloud infrastructure, and illustrates the urgent need for zero trust approaches and enhanced east-west traffic security.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Remote Code Execution Flaw in Abandoned Rust Library Exposes Global Supply Chain
Impact· medium

Remote Code Execution Flaw in Abandoned Rust Library Exposes Global Supply Chain

In August 2024, Edera researchers discovered CVE-2025-62518, a high-severity remote code execution vulnerability in the abandoned async-tar library for the Rust programming language. This logic flaw, named "TARmageddon," was unwittingly propagated to millions of users through downstream forks like tokio-tar and widely used build tools such as uv and testcontainers. The systemic risk arises because the vulnerability was replicated across a deep lineage of forks, making it very difficult to detect and patch comprehensively. Exploitation allows attackers to achieve remote code execution by overwriting files via malicious tar archives—a threat amplified by the lack of direct visibility into indirect dependencies in modern supply chains. The incident is especially impactful as it highlights the persistent risks of open-source abandonware and insufficient maintenance of foundational software libraries. It underscores growing industry focus on supply-chain security, indirect dependency management, and the need for rapid, coordinated vulnerability disclosure and remediation.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Velociraptor Misused: LockBit Ransomware & Storm-2603 Weaponize DFIR Tools in 2025 Attacks
Impact· high

Velociraptor Misused: LockBit Ransomware & Storm-2603 Weaponize DFIR Tools in 2025 Attacks

In October 2025, cybersecurity researchers uncovered that threat actors associated with Storm-2603 (also known as Gold Salem or CL-CRI-1040) leveraged Velociraptor, a legitimate open-source digital forensics and incident response (DFIR) tool, to facilitate a series of LockBit ransomware attacks. Adversaries exploited Velociraptor’s capabilities to gather intelligence and move laterally within target environments, evading detection by blending in with regular security operations. The attacks led to significant data encryption events and operational disruptions, primarily impacting organizations with insufficient internal security segmentation and monitoring. This incident marks a significant evolution in attacker tradecraft, as it demonstrates that widely trusted security tools—often present for defensive use—can be repurposed as offensive weapons. Increased regulatory scrutiny and the recurrent rise of double extortion ransomware attacks highlight the urgent need for organizations to monitor tool usage and improve east-west visibility.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SonicWall VPN Breach 2025: Over 100 Customer Accounts Compromised via Stolen Credentials
Impact· low

SonicWall VPN Breach 2025: Over 100 Customer Accounts Compromised via Stolen Credentials

In October 2025, a widespread compromise targeted SonicWall SSL VPN devices, enabling attackers to gain unauthorized access to at least 100 customer accounts across various organizations. Security firm Huntress noted that threat actors rapidly authenticated using valid credentials on multiple devices, suggesting credential theft or data leaks rather than brute-force attacks. Attackers leveraged VPN access to infiltrate corporate environments, enabling lateral movement and potentially exfiltrating sensitive data. This campaign demonstrates the heightened risk posed by stolen credentials, especially when VPN infrastructure is directly exposed to the internet. This incident is highly relevant as credential-focused attacks and VPN compromises continue to surge, exploiting weaknesses in remote access systems. The event underscores the urgent need for zero trust strategies and stronger authentication measures to defend against evolved attacker tactics targeting perimeter defenses.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Oracle E-Business Suite Hit by Critical Unauthenticated Data Exposure Vulnerability
Impact· low

Oracle E-Business Suite Hit by Critical Unauthenticated Data Exposure Vulnerability

In October 2025, Oracle disclosed a high-severity vulnerability (CVE-2025-61884) affecting E-Business Suite versions 12.2.3 through 12.2.14. This flaw allows unauthenticated attackers to access sensitive data without login, leveraging a network-exploitable bug rated CVSS 7.5. Organizations running impacted Oracle EBS versions are at risk of data compromise, business disruption, and regulatory exposure if left unpatched. Oracle issued a security alert and urgent patch to address the issue as exploitation attempts in the wild are anticipated. This disclosure underscores the growing trend of unauthenticated, remote data access flaws targeting ERP platforms. Critical business applications present attractive targets for threat actors, especially as organizations expand interconnectivity. Prompt detection and segmentation of east-west traffic remain essential as ERP vulnerabilities increasingly underpin large-scale, compliance-relevant breaches.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports