Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 238 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 28452856 / 3054 reports
CometJacking: How a Single Click Turned Perplexity's Comet AI Browser into a Data Thief
Impact· medium

CometJacking: How a Single Click Turned Perplexity's Comet AI Browser into a Data Thief

In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools. This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Oracle EBS Exploited in Clop Ransomware Extortion Campaign (2025)
Impact· high

Oracle EBS Exploited in Clop Ransomware Extortion Campaign (2025)

In September 2025, Oracle confirmed that customers running E-Business Suite (EBS) were targeted by extortion emails attributed to the Clop ransomware gang, following exploitation of security vulnerabilities addressed in the July 2025 Critical Patch Update. Multiple executives at affected companies received emails demanding ransom, with Clop claiming to have exfiltrated confidential data from unpatched Oracle EBS instances. While Oracle has not formally verified the data theft, the vulnerabilities—three of which were remotely exploitable without authentication—enabled attackers to potentially access sensitive business documents and threaten public disclosure if ransoms were not paid. This incident highlights a continued and escalating trend of ransomware groups leveraging zero-day and freshly patched vulnerabilities to target critical enterprise software. Organizations dependent on ERP and business process applications are increasingly at risk, underscoring the urgent need for rapid patching and advanced network-layer security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CometJacking Attack: How Prompt Injection Exposed Comet AI Browser Users in 2025
Impact· medium

CometJacking Attack: How Prompt Injection Exposed Comet AI Browser Users in 2025

In October 2025, security researchers from LayerX uncovered a novel 'CometJacking' attack affecting Perplexity's Comet AI browser. This prompt injection attack leverages URL parameters to deliver hidden instructions that compel the browser to access and exfiltrate sensitive data—such as Gmail messages and Google Calendar information—from connected services, without any need for user credentials or interaction. The technique exploits the 'collection' URL parameter to insert malicious prompts, instructing the AI agent to gather and encode user data (e.g., using base64) before surreptitiously transmitting it to attacker-controlled endpoints. Despite being informed, Perplexity dismissed the security risk, highlighting concerns about unmitigated AI agent behaviors.This incident surfaces amid growing adoption of agentic AI browsers and illustrates the ease with which prompt injection tactics can sidestep controls, particularly in tools integrated with sensitive personal or enterprise accounts. The attack underscores the increasing threat from adversarial prompt engineering as AI agent usage expands rapidly.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Signal Launches SPQR: A Quantum-Safe Encryption Upgrade for 2025
Impact· low

Signal Launches SPQR: A Quantum-Safe Encryption Upgrade for 2025

In October 2025, Signal introduced a major upgrade to its encryption suite by deploying the Sparse Post-Quantum Ratchet (SPQR), designed to secure user communications against present and future quantum computing threats. Developed in collaboration with leading academic and industry partners, SPQR brings a 'triple ratchet' protocol leveraging hybrid cryptography based on both traditional and quantum-resistant key exchange mechanisms. This system provides continual key rotation, forward secrecy, and robust post-compromise security, ensuring that even if current keys are compromised, future messages remain protected. The rollout will be gradual and backward-compatible, affecting Signal’s 100 million global users without requiring manual intervention. The launch of SPQR is a landmark response to the rise of quantum computing, which threatens conventional encryption schemes. Its introduction reflects mounting industry urgency to adopt advanced cryptographic standards and maintain trust in privacy-critical communications platforms amid rapid shifts in the threat landscape.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SORVEPOTEL: New WhatsApp-Driven Malware Campaign Hits Brazil
Impact· high

SORVEPOTEL: New WhatsApp-Driven Malware Campaign Hits Brazil

In late 2025, cybersecurity researchers identified a rapid outbreak of a self-spreading malware targeting Brazilian Windows users through WhatsApp, labeled SORVEPOTEL and tracked as the Water Saci campaign. The malware leverages the inherent trust and widespread popularity of WhatsApp by delivering malicious payloads via chat messages, which entice users to download infected files. Once inside a system, SORVEPOTEL propagates by messaging victims’ contacts, enabling swift lateral movement and widespread distribution. Notably, the campaign appears engineered for rapid proliferation rather than for data theft or ransomware deployment, showcasing evolving malware propagation tactics. This incident highlights the increasing sophistication and speed of messaging app-based malware and reflects a broader trend of social engineering campaigns capitalizing on trusted digital platforms. Organizations should re-examine endpoint protections and user awareness in light of emerging threats exploiting popular communications channels.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Detour Dog Exposes DNS-Powered Stealer Risk: A 2025 Campaign Analysis
Impact· high

Detour Dog Exposes DNS-Powered Stealer Risk: A 2025 Campaign Analysis

In October 2025, threat intelligence researchers revealed that the actor known as Detour Dog orchestrated wide-scale campaigns to deliver the Strela Stealer information stealer using DNS-powered malware infrastructure. Detour Dog’s operation involved maintaining control over a network of malicious domains, enabling initial delivery of a backdoor named StarFish, which then facilitated deployment of Strela Stealer. This campaign leveraged covert DNS traffic and evasion techniques, making threat detection and containment difficult for enterprise defenders. Victimized organizations faced increased risk of credential theft, data exfiltration, and operational disruption as a result. This incident highlights the rising trend of weaponizing benign protocols like DNS for malware delivery and lateral movement, as well as the emergence of advanced information stealers targeting enterprise networks and cloud environments. Organizations must adapt controls and detection strategies to defend against increasingly sophisticated, protocol-abusing threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Rhadamanthys Stealer 2025: Device Fingerprinting, Steganography, and the New Face of Data Theft
Impact· medium

Rhadamanthys Stealer 2025: Device Fingerprinting, Steganography, and the New Face of Data Theft

In October 2025, cybersecurity researchers uncovered significant new capabilities in the Rhadamanthys Stealer malware, including advanced device fingerprinting and the use of PNG steganography to distribute malicious payloads. Initially spread via cybercrime forums, the malware author has expanded its ecosystem with additional tools like Elysium Proxy Bot and Crypt Service, targeting organizations worldwide. Threat actors leveraged these upgrades to collect detailed browser and system data while evading detection, resulting in an uptick of credential, financial, and sensitive data thefts across enterprise environments. The evolution of Rhadamanthys Stealer highlights a broader trend of information stealer malware using novel evasion tactics and multi-tool ecosystems. Its modularity and innovative payload delivery have driven increased attention from security teams and regulators, as businesses seek to defend against ever-more-sophisticated data exfiltration methods.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft AI Voice Cloning: A New SaaS Security Exposure in 2024
Impact· medium

Microsoft AI Voice Cloning: A New SaaS Security Exposure in 2024

In early 2024, Microsoft’s ‘Speak for Me’ AI-powered voice cloning technology emerged as a significant security risk when researchers and privacy advocates highlighted its potential for abuse. Attackers could exploit the deep integration of this feature into productivity platforms like Teams, enabling the creation of near-perfect voice replicas for use in live calls or AI-driven agent interactions across SaaS environments. The risk is compounded by the platform’s capability to reproduce voices without comprehensive enrollment checks, opening avenues for sophisticated impersonation attacks and social engineering, ultimately undermining trust in corporate communications and user authentication. This incident underscores an urgent trend: as generative AI technologies become embedded in mainstream communications platforms, attackers are adopting new TTPs focused on identity and voice deception. Enterprises must address these risks proactively, with regulatory scrutiny growing over AI misuse in both authentication and privacy contexts.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Clop Ransomware Targets Oracle E-Business Suite Customers in 2025 Extortion Campaign
Impact· high

Clop Ransomware Targets Oracle E-Business Suite Customers in 2025 Extortion Campaign

In late September 2025, the Clop ransomware group launched a targeted extortion campaign against Oracle E-Business Suite customers. Using compromised third-party email accounts, attackers sent personalized emails to executives, claiming to have exfiltrated sensitive corporate data via known vulnerabilities in Oracle's ERP software. The emails provided 'proof' offers, imposed a payment deadline, and threatened public exposure or resale of stolen data if demands were not met. Oracle acknowledged the incident, referencing vulnerabilities patched in the July 2025 update, but did not confirm direct data exfiltration or specify the flaws under exploitation. This incident highlights the evolution of ransomware-as-a-service models that blend data theft, psychological pressure, and supply-chain targeting. It underscores urgent enterprise risk around unpatched ERP systems, the danger of credential compromise, and the increasing sophistication of financially motivated threat actors such as Clop.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Clop Ransomware Claims Oracle E-Business Suite Data Breach in 2025 Extortion Wave
Impact· high

Clop Ransomware Claims Oracle E-Business Suite Data Breach in 2025 Extortion Wave

In late September 2025, a widespread extortion campaign was detected targeting companies using Oracle E-Business Suite, with the Clop ransomware group (also tracked as FIN11) claiming to have exfiltrated sensitive data. Attackers used hundreds of compromised email accounts to send extortion messages to executives, demanding payment to prevent data leaks on Clop's darknet site. While links to previous Clop activity were identified through reused email accounts and familiar tactics, as of early October, no definitive evidence of a successful Oracle E-Business Suite breach has been confirmed by investigators (Mandiant, Google Cloud, and GTIG). As a result, organizations remain on alert as the situation develops, and incident response efforts continue. This attack underscores a continuing trend of cyber extortion groups leveraging data theft and email-based threats rather than traditional encryption. The campaign's timing and targeting highlight rapidly evolving attacker sophistication and the ongoing vulnerability of enterprise applications, emphasizing the importance of robust lateral movement controls and proactive monitoring in the face of persistent ransomware and extortion campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Red Hat Hit by GitLab Breach: Crimson Collective Steals Sensitive Consulting Data
Impact· high

Red Hat Hit by GitLab Breach: Crimson Collective Steals Sensitive Consulting Data

In September 2025, Red Hat confirmed a security incident involving unauthorized access to a GitLab instance used by its consulting business. The threat group, Crimson Collective, claims to have exfiltrated nearly 570GB of compressed data from approximately 28,000 internal repositories, including around 800 Customer Engagement Reports (CERs) containing sensitive infrastructure details, authentication tokens, and database URIs. The attackers allegedly leveraged these credentials to potentially access downstream customer environments. Red Hat stated that no other company services or products were affected and initiated remediation steps shortly after detecting the breach. This incident highlights a growing trend of threat actors targeting source code management systems and leveraging poorly secured credentials to escalate access. It underscores the importance of robust secrets management, Zero Trust segmentation, and stringent access controls across cloud-native development environments.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Service Desk Social Engineering Attack Exposes Enterprise Vulnerabilities in 2025
Impact· medium

Service Desk Social Engineering Attack Exposes Enterprise Vulnerabilities in 2025

In October 2025, organizations witnessed a sharp rise in successful social engineering attacks targeting enterprise service desks. Threat actors such as Scattered Spider exploited help desk processes by impersonating employees and manipulating support staff into resetting credentials or granting privileged access. These attacks bypassed traditional technical defenses by leveraging persuasive phone or chat conversations, resulting in significant business disruptions, data exposure, and potential operational outages. Notable events, such as those at MGM Resorts and Clorox, demonstrated the devastating financial and reputational impact of a single compromised support interaction, with recovery efforts spanning weeks and incurring nine-figure damages. This trend highlights the evolving threat landscape where the human element is now the primary entry vector. The urgency to adopt robust, workflow-driven identity verification, bypassing agent discretion, is underscored by regulatory scrutiny and mounting pressure to align with NIST and similar frameworks. Organizations must shift from relying on staff intuition to standardized, audited processes to mitigate these high-impact risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports