Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
CISA Adds Critical TrueConf Server Vulnerabilities to Known Exploited Vulnerabilities Catalog
CISA has added two critical TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-72529 involves missing authentication for critical functions, while CVE-2026-72530 represents a code injection vulnerability, both allowing attackers to gain total control of affected systems. These vulnerabilities pose significant risks to federal enterprises and private organizations using TrueConf's video conferencing solutions, with threat actors actively leveraging these flaws to establish persistent access and execute unauthorized commands on compromised servers. This incident highlights the growing trend of attackers targeting collaboration and communication platforms, particularly as hybrid work environments continue to expand the attack surface of enterprise networks and create new pathways for initial compromise and lateral movement.
1 month ago
Kill Chain
Cisco Patches Nine Critical Vulnerabilities Including Five CVSS 10.0 Flaws in Network Infrastructure
In August 2026, Cisco released critical security patches addressing nine severe vulnerabilities across its Crosswork platforms and Secure Workload software. The flaws included five vulnerabilities scoring CVSS 10.0, affecting network management and workload security products used extensively in enterprise environments. Four vulnerabilities impacted Crosswork Data Gateway, Network Controller, and Planning platforms, including SQL injection and missing authentication issues. Five additional vulnerabilities affected Cisco Secure Workload deployments, encompassing improper access control, authentication bypass, and command injection flaws. These vulnerabilities were discovered during internal security testing and were not known to be actively exploited at the time of disclosure. The widespread deployment of Cisco infrastructure in enterprise networks makes these vulnerabilities particularly concerning, as they could provide attackers with significant access to critical network management and security monitoring systems if exploited.
1 month ago
Kill Chain
Active Exploitation of Critical Zimbra RCE Vulnerability Threatens Email Infrastructure Worldwide
In August 2026, CERT Polska warned that attackers are actively exploiting CVE-2026-73570, a critical remote code execution vulnerability in Zimbra Collaboration Suite. The flaw allows unauthenticated attackers to execute arbitrary commands through improper sanitization in the SNMP monitoring component. With over 12,100 Zimbra servers exposed online globally, this vulnerability poses significant risks to hundreds of millions of users across businesses and government agencies worldwide. The Zimbra security team released a patch in version 10.1.20 on July 20, 2026. This incident highlights the ongoing trend of nation-state actors and cybercriminals targeting collaboration platforms for initial access and credential harvesting. Zimbra vulnerabilities have been consistently exploited by Russian APT groups including Winter Vivern, APT29, and APT28, making rapid patching and monitoring critical for organizations.
1 month ago
Kill Chain
Critical MLflow AI Platform Vulnerability Exploited for Cloud Credential Theft
CISA added CVE-2026-64849, a critical DNS-rebinding server-side request forgery vulnerability in MLflow's webhook delivery system, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows unauthenticated attackers to remotely access internal services and cloud metadata configurations on unpatched MLflow instances, enabling theft of AWS IAM credentials and other sensitive data. MLflow, an open-source AI engineering platform with over 30 million monthly downloads, patched the vulnerability in version 3.15.0, but federal agencies have only two weeks to secure their systems under BOD 26-04. This incident highlights the growing attack surface created by AI infrastructure components as organizations rapidly adopt machine learning platforms without adequate security hardening, making AI systems prime targets for credential theft and lateral movement.
1 month ago
Kill Chain
Critical Citrix NetScaler Authentication Bypass Vulnerabilities Demand Immediate Action
On August 20, 2026, Citrix disclosed two critical vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The most severe flaw, CVE-2026-19490, allows remote unauthenticated attackers to bypass authentication when appliances are configured as AAA virtual servers or Gateway services with SAML Action enabled. The second vulnerability, CVE-2026-19489, enables denial-of-service attacks when SIP ALG is enabled on large-scale NAT configurations. With over 24,000 NetScaler instances exposed online and Citrix's history of 22 exploited vulnerabilities in five years, immediate patching is critical. This incident highlights the continuing trend of authentication bypass vulnerabilities targeting enterprise network infrastructure, particularly VPN and remote access solutions that became critical during hybrid work adoption and remain prime targets for initial access in modern cyber campaigns.
1 month ago
Kill Chain
How AI-Powered Phishing Attacks Are Outsmarting Traditional Email Security
AI-powered phishing attacks have fundamentally transformed email threats, achieving a 54% click-through rate according to Harvard Business Review research. Attackers leverage large language models to conduct reconnaissance via LinkedIn and public sources, generating highly personalized spear phishing campaigns that bypass traditional email filters through polymorphic techniques. These attacks evade signature-based detection by continuously changing content, formatting, and delivery methods while using trusted cloud services and QR codes. The average cost of phishing-related data breaches has reached $4.8 million, with post-compromise activity escalating rapidly through session hijacking and lateral movement. This trend represents a critical shift from prevention-focused email security to comprehensive behavioral monitoring and response. As AI democratizes sophisticated phishing techniques, managed service providers must adopt detection strategies that monitor identity, endpoint, and user behavior patterns rather than relying solely on email gateway filtering.
1 month ago
Kill Chain
N-able Passportal Vulnerability Exposes MSP Supply Chain Risks
In July 2026, security researcher James Arnott discovered a critical vulnerability in N-able's Passportal password manager that allowed any malicious website to steal complete vault access tokens and master keys. The flaw affected approximately 2,500 managed service providers (MSPs) and 165,000 small and medium-sized businesses using the cloud-based credential management system. Attackers could compromise all stored passwords, time-based one-time passwords (TOTPs), and maintain persistent access for up to 100 days through stolen refresh tokens. N-able patched the vulnerability within 24 hours, but the underlying cloud-based architecture continues to expose users to supply chain risks. This incident highlights the growing risks of cloud-based password managers in an era where supply chain attacks targeting MSPs have become increasingly sophisticated, making credential security architecture choices more critical than ever for organizations managing downstream client access.
1 month ago
Kill Chain
Unveiling 'CoSnitch': The AI Vulnerability in Microsoft Copilot
In December 2025, Varonis Threat Labs identified a vulnerability in Microsoft Copilot Personal, termed 'CoSnitch,' which allowed attackers to manipulate the AI into revealing its own architectural details. By crafting specific prompts, researchers induced Copilot to disclose information that facilitated memory poisoning, automatic prompt execution via specially crafted URLs, and data exfiltration. Microsoft addressed this issue by releasing patches on August 18, 2026, and confirmed that enterprise customers were unaffected. This incident underscores the evolving threat landscape where AI systems can be exploited to divulge sensitive information. It highlights the necessity for continuous security assessments and the implementation of robust guardrails to prevent similar vulnerabilities in AI-driven platforms.
1 month ago
Kill Chain
Critical GitLab Vulnerability CVE-2026-19478: Immediate Action Required
In August 2026, GitLab disclosed a critical vulnerability (CVE-2026-19478) in its Community and Enterprise Editions, affecting versions from 18.2 up to 19.2.3. This code injection flaw within the GraphQL API allows unauthenticated attackers to remotely modify or delete public projects and user data. The vulnerability has been assigned a CVSS score of 9.4 due to its high impact on data integrity and availability. Organizations using self-managed GitLab instances are urged to upgrade to the patched versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4 immediately to mitigate this risk. The disclosure of CVE-2026-19478 underscores the critical importance of securing APIs against unauthorized access and code injection attacks. As threat actors increasingly exploit such vulnerabilities, organizations must prioritize timely patching and implement robust monitoring of API activities to detect and prevent unauthorized operations.
1 month ago
Kill Chain
Critical Vulnerabilities in macOS, SharePoint, vCenter, and IKE Under Active Exploitation
In August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These vulnerabilities include CVE-2026-65400 affecting Apple macOS, CVE-2026-55040 in Microsoft SharePoint, CVE-2026-59310 in VMware vCenter, and CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions. Exploitation of these flaws has led to unauthorized access, deployment of cryptocurrency miners, backdoors, and ransomware attacks across multiple countries. The active exploitation of these vulnerabilities underscores the persistent threat posed by sophisticated cyber actors targeting widely used enterprise systems. Organizations are urged to prioritize patching and implement robust security measures to mitigate potential risks associated with these exploits.
1 month ago
Kill Chain
Microsoft Uncovers Extensive MacSync Stealer Infrastructure
In August 2026, Microsoft Defender Experts identified over 30 web domains associated with MacSync Stealer, a macOS-targeted information-stealing malware. The investigation revealed that the malware utilized social engineering tactics, such as ClickFix, to trick users into executing malicious commands in the Terminal. Once executed, MacSync Stealer collected sensitive data, including macOS Keychain contents, browser credentials, SSH keys, and AWS credentials, which were then exfiltrated to attacker-controlled servers. The malware employed various evasion techniques, including in-memory execution and the use of native macOS utilities, to minimize detection. This incident underscores the evolving sophistication of macOS-targeted malware and the increasing use of social engineering techniques to bypass traditional security measures. Organizations must remain vigilant and educate users about the risks of executing unverified commands, especially as threat actors continue to adapt their methods to exploit human factors.
1 month ago
Kill Chain
Arup's $25 Million Deepfake Scam: A Wake-Up Call for Cybersecurity
In January 2024, a finance employee at Arup's Hong Kong office received an email, purportedly from the company's UK-based CFO, requesting a confidential transaction. To verify, the employee joined a video conference with individuals appearing as the CFO and other senior colleagues. Convinced by the authenticity of the participants, the employee executed 15 wire transfers totaling approximately $25.6 million to designated bank accounts. Subsequent investigations revealed that the video call participants were AI-generated deepfakes, and the entire scenario was orchestrated by cybercriminals. This incident underscores the evolving sophistication of cyber threats, where attackers leverage advanced AI technologies to create highly convincing social engineering schemes. Organizations must recognize that traditional verification methods, such as visual and auditory confirmation, can be compromised. Implementing multi-factor authentication, establishing robust verification protocols, and educating employees about emerging threats are crucial steps in mitigating such risks.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports