Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Apollo Global Management Hit by BlackFile Social Engineering Attack: $1 Trillion Firm Discloses Data Breach
Apollo Global Management disclosed a data breach occurring between July 6-10, 2024, where attackers used social engineering tactics to gain unauthorized access to cloud platforms. The attack was attributed to BlackFile, a threat group affiliated with The Com collective, which has been targeting financial institutions, law firms, and medical technology companies. Personal data including names, Social Security numbers, dates of birth, and contact information were compromised, though Apollo found no evidence of data being posted online or used for identity theft. This incident exemplifies the growing threat of sophisticated social engineering campaigns targeting the financial sector, particularly as cybercriminals increasingly focus on high-value private equity firms and leverage voice-phishing techniques to bypass traditional security controls.
4 weeks ago
Kill Chain
SickKids Hospital Data Breach Exposes Critical Third-Party Security Gaps
In December 2024, Toronto's Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information of current and former employees and job applicants through a vulnerability in third-party software. The breach affected human resources data including names, addresses, phone numbers, and employment details, while clinical systems and patient records remained unaffected. SickKids immediately secured the compromised system, launched an investigation with cybersecurity experts, and began notifying affected individuals while implementing additional security measures. This incident highlights the growing trend of healthcare organizations facing data breaches through third-party vendor vulnerabilities, a critical concern as healthcare becomes increasingly digitized and regulatory scrutiny intensifies under frameworks like HIPAA and emerging privacy legislation.
4 weeks ago
Kill Chain
Novel FTP Banner Attack Delivers E4del and PINHOLE RATs in 2026 Campaign
In July 2026, threat actors developed a novel attack technique using FTP server banners as dead-drop resolvers to deliver two previously undocumented remote access trojans: E4del and PINHOLE. The campaign begins with phishing attacks distributing ZIP archives containing malicious LNK files that connect to compromised FTP servers to retrieve PowerShell commands embedded in server greeting banners. E4del masquerades as Discord using a digitally signed Electron application, while PINHOLE uses sophisticated evasion techniques including shellcode fluctuation and retrieval of C2 configurations from Pinterest and SurveyMonkey. SOCRadar researchers found this technique remained active through August 2026 with new infrastructure continuously deployed. This incident highlights the evolution of living-off-the-land techniques where attackers abuse legitimate protocols and services to evade detection, representing a broader trend toward more sophisticated command and control methods that bypass traditional security controls.
4 weeks ago
Kill Chain
Massive AWS Credential Leak Exposes 817 Corporate Accounts to Full Takeover
Between August 2022 and August 2026, Truffle Security discovered over 9,300 Amazon Web Services (AWS) access keys publicly exposed across code repositories, Git history, datasets, Docker images, and CI logs. Of these, 817 keys were linked to corporate accounts, with 526 being AWS root keys granting unrestricted administrative access. Researchers found that 242 keys belonged to IAM users with AdministratorAccess policies, effectively providing full control over corporate AWS environments. Hugging Face emerged as the largest single source with 8,482 exposed keys, many remaining active for years without rotation. This incident highlights the persistent challenge of credential management in cloud environments as organizations increasingly rely on Infrastructure as Code and automated deployment pipelines. With the median age of exposed keys being over five years and only 13.7% showing evidence of rotation, the findings underscore critical gaps in security hygiene that threat actors actively exploit for cryptomining operations, data exfiltration, and persistent access establishment.
4 weeks ago
Kill Chain
SynkLoader Malware Exploits Microsoft Teams Trust in 2026 Campaign
In July 2026, cybercriminals launched a sophisticated phishing campaign using Microsoft Teams to distribute a new malware family called SynkLoader. Attackers impersonated IT help desk personnel to trick victims into installing a fake 'PowerShell Cleaner' executable hosted on Microsoft Azure. The multi-language malware combines Python, PowerShell, C#, and C++ components to establish persistence, steal credentials through a convincing fake Windows lock screen, and create backdoor access for potential ransomware operations. The campaign demonstrates the growing abuse of trusted collaboration platforms and sophisticated social engineering tactics that bypass traditional email security measures. This incident highlights the evolving threat landscape where attackers increasingly target remote work infrastructure and exploit user trust in corporate communication tools, making traditional perimeter security insufficient against modern attack vectors.
4 weeks ago
Kill Chain
Microsoft Defender's Own Driver Weaponized for Endpoint Security Bypass
In August 2026, Check Point Research disclosed a technique that weaponizes Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems. The technique, dubbed 'BTR Reforged,' affects all Windows versions from Windows 7 through Windows 11 25H2 and exploits a built-in driver that cannot be blocked without disrupting Defender itself. Researchers demonstrated live deletion of the entire Defender stack on a fully updated Windows 11 system with Tamper Protection active, requiring only administrator privileges with SeLoadDriverPrivilege. Unlike traditional bring-your-own-vulnerable-driver attacks, this technique uses infrastructure present in every Windows installation, making it particularly concerning for endpoint security bypass scenarios. This discovery highlights the evolving sophistication of endpoint security bypass techniques, where attackers increasingly leverage legitimate system components rather than external vulnerable drivers that can be easily blocklisted by security vendors.
4 weeks ago
Kill Chain
RedC2 4.0 Supply Chain Attack: AI-Powered Backdoors Target npm Ecosystem
In August 2026, cybersecurity researchers discovered 14 trojanized npm packages masquerading as functional calendar and streak utilities that secretly deployed RedC2 4.0, an AI-powered Linux backdoor. The malicious packages, including streak-metrics-math and kit-map-vim, delivered the RedShell Linux beacon which establishes command and control communications for surveillance, credential theft, and payload delivery operations. The attack leveraged legitimate-seeming functionality to hide malicious binaries that execute automatically upon module import, requiring no installation hooks or explicit function calls to compromise target systems. This incident highlights the growing sophistication of supply chain attacks, particularly the integration of AI-assisted command and control frameworks that lower the barrier to entry for cybercriminals while increasing operational efficiency through natural language command processing.
4 weeks ago
Kill Chain
Paperclip AI Agent Attack Exposes Critical Gaps in Enterprise AI Security
In July 2026, cybercriminals orchestrated a sophisticated supply chain attack targeting the Paperclip agentic AI platform by registering a typosquatted domain and distributing malicious Python packages alongside weaponized AI skills. While automated scanners detected the compromised Python packages within hours, the malicious AI skills evaded detection and accumulated over 300,000 installations each, successfully compromising user machines and exfiltrating credentials and sensitive data. This incident demonstrates the emerging attack surface created by AI agent ecosystems and the inadequacy of current security controls for detecting malicious skills. This attack highlights the critical need for organizations to secure their AI agent deployments as agentic platforms become mainstream business tools, with skill repositories growing by over 30% in recent months and minimal security oversight.
4 weeks ago
Kill Chain
Medusa Ransomware Escalates Attacks on Critical Infrastructure: 500+ Organizations Compromised
The Medusa ransomware syndicate has systematically compromised over 500 critical infrastructure organizations across the United States since June 2021, targeting healthcare, manufacturing, defense, and financial sectors. Operating under a Ransomware-as-a-Service (RaaS) model, the group experienced massive operational growth in 2023 following the launch of their "Medusa Blog" leak site for double extortion tactics. The syndicate actively recruits initial access brokers on dark web forums, offering payments from $100 to $1 million for exclusive system access, demonstrating the industrialization of ransomware operations. This incident highlights the accelerating threat to critical infrastructure as ransomware groups increasingly target essential services through sophisticated affiliate networks. The dramatic increase from 300 to 500 victims in less than a year underscores the urgent need for enhanced security controls across critical sectors.
4 weeks ago
Kill Chain
Microsoft Entra ID Maximum-Severity Flaw Exploited: CVE-2026-69836 Analysis
Microsoft disclosed a maximum-severity vulnerability (CVE-2026-69836, CVSS 10.0) in Entra ID that allowed remote code execution through deserialization of untrusted data. The flaw, discovered by security engineer Robert Fitzpatrick, was actively exploited in the wild before Microsoft implemented full mitigation. The vulnerability affected Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory, enabling unauthorized attackers to execute code over a network without proper validation of user-controlled data. This incident highlights the continued targeting of identity infrastructure by sophisticated threat actors, coinciding with increased attacks on cloud authentication services and the growing adoption of zero-trust architectures across enterprise environments.
1 month ago
Kill Chain
GitLab CVE-2026-19478: When AI Attackers Turn Disclosure Into Exploitation in Days
CVE-2026-19478, a critical code injection vulnerability in GitLab with a CVSS score of 9.4, came under active exploitation within days of its August 2026 disclosure. The flaw allows unauthenticated attackers to modify, delete, or completely destroy publicly accessible GitLab projects through GraphQL directive exploitation, affecting versions 18.2 through 19.2.3. Security researchers at watchTowr observed real-world attacks against their honeypot infrastructure shortly after disclosure, with attackers capable of deleting entire repositories, forging merge records, and banning project maintainers without requiring credentials. This incident exemplifies how AI-enabled attackers are drastically compressing the time from vulnerability disclosure to widespread exploitation, transforming the traditional patch cycle expectations and forcing organizations to adopt more aggressive update timelines for internet-facing infrastructure.
1 month ago
Kill Chain
SANS Researchers Expose Massive Entra ID Password Spray Campaign
Security researchers at SANS Internet Storm Center have documented widespread password spray attacks targeting Microsoft Entra ID (formerly Azure AD) environments, with attackers systematically attempting authentication against multiple user accounts using common passwords. The attacks, detected through PowerShell-based log analysis of Entra ID audit logs, showed attackers leveraging rotating proxy services to evade IP-based blocking while targeting organizations that had migrated to cloud services but failed to implement proper monitoring. Multiple organizations were found to have inadequate conditional access policies, allowing attackers to probe authentication systems from unexpected geographic locations and compromise accounts through credential stuffing techniques. This incident highlights the critical gap many organizations face when transitioning to cloud infrastructure - abandoning the rigorous log monitoring practices they maintained for on-premises systems, creating blind spots that attackers actively exploit through automated credential attacks.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports