Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
APT Campaign Exploits Cisco ASA Zero-Days: Persistent Threats to Government Devices in 2025
In September 2025, U.S. federal agencies were ordered by CISA to urgently patch Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices after two critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) were exploited by the APT group UAT4356 (STORM-1849). Attackers achieved unauthenticated remote code execution and persistent control by manipulating device ROMMON, deploying malware such as LINE VIPER and the RayInitiator bootkit to facilitate malware implants, command execution, and possible data exfiltration. The campaign, linked to the larger ArcaneDoor operation, threatened essential government and global infrastructure by allowing full device compromise, evasion of detection, and resistance to conventional remediation steps. This incident highlights an escalating trend in sophisticated, state-linked attacks targeting edge infrastructure, often leveraging supply-chain weaknesses and persistent malware able to survive reboots and firmware updates. It also underscores renewed regulatory pressure for timely vulnerability mitigation and increased focus on Zero Trust architectures for critical sectors.
8 months ago
Kill Chain
Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data
In February 2024, the unofficial 'postmark-mcp' npm package—a clone of the genuine Postmark MCP email handler—was discovered to have maliciously exfiltrated users' email data. With a single line of code added in its latest update, the package silently sent every processed email to an external domain controlled by the attacker. This supply chain compromise exploited developer trust in open-source libraries, resulting in unintentional leakage of confidential user communications and putting affected organizations and their customers at risk of data exposure or further attacks. This incident underscores the growing frequency and sophistication of supply chain attacks targeting software ecosystems like npm. Organizations face heightened regulatory and reputational risks as attackers leverage trusted distribution platforms to propagate malicious code, making robust dependency monitoring and vendor validation more critical than ever.
8 months ago
Kill Chain
Cisco 2025: Critical SNMP Vulnerability Actively Exploited in IOS and IOS XE
In September 2025, Cisco disclosed that an actively exploited vulnerability (CVE-2025-20352, CVSS 7.7) in its IOS and IOS XE software allows remote attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition via specially crafted SNMP packets. The flaw, which came to light after attacker activity was observed leveraging previously compromised administrative credentials, impacts a broad range of Cisco networking equipment. The immediate impact includes risks of device takeover, network disruption, and possible lateral movement within victims’ environments. This incident underscores the criticality of securing network infrastructure against both external and internal threats, as attackers continue to exploit overlooked or unpatched vulnerabilities at the core of modern networks. The active exploitation highlights an urgent need for organizations to review segmentation, monitoring, and patch management practices in light of evolving attack techniques.
8 months ago
Kill Chain
Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach
In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch. This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.
8 months ago
Kill Chain
Cisco ASA Zero-Day (CVE-2025-20333) Breach: Inside the CISA Emergency Response
In September 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20333, CVSS 9.9) affecting its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) Software. Attackers actively exploited improper input validation in the VPN web server, enabling them to bypass authentication and potentially gain unauthorized access to sensitive environments. Cisco urged immediate patching as exploitation was observed targeting both perimeter and internal firewalls, demonstrating advanced lateral movement strategies. This exploitation prompted an emergency mitigation directive from CISA to reduce risk across U.S. federal agencies and private enterprises. This incident underscores the ongoing evolution of threat actors leveraging zero-days to target critical infrastructure firewalls, coinciding with a nationwide spike in sophisticated, identity-driven attacks. Organizations are under increasing regulatory scrutiny to patch rapidly and advance segmentation, threat monitoring, and east-west traffic controls.
8 months ago
Kill Chain
Scattered Spider Ransomware: Teen Member Arrested, Group Claims Shutdown in 2024
In June 2024, law enforcement arrested a teenage member of the notorious Scattered Spider ransomware group, a cybercriminal collective linked to disruptive attacks against major organizations including MGM Resorts and Caesars Entertainment. The arrest followed claims by the group that it was shutting down operations amid heightened law enforcement scrutiny and infighting among its members. Scattered Spider became infamous for leveraging social engineering and identity-based attacks to gain initial entry, then rapidly moving laterally to deliver ransomware and conduct data theft. This latest development underscores the increasingly aggressive response from law enforcement to high-impact ransomware threats. The recent action highlights the continued evolution and volatility of ransomware groups, many of which are now using sophisticated identity compromise and cloud-based attack chains. Organizations should remain vigilant as law enforcement disruptions may cause threat actors to splinter, rebrand, or accelerate new attack campaigns using similar techniques.
8 months ago
Kill Chain
Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security
Between 2017 and 2025, waves of exploit attempts have targeted Hikvision IP cameras using vulnerabilities such as CVE-2017-7921. Attackers abused easily guessable or default credentials passed via HTTP GET parameters, leveraging weak authentication mechanisms to access sensitive camera endpoints, user configurations, and device data. The entry vector relied on IoT device misconfigurations and insecure design, while brute-force attempts and credential stuffing remain prevalent. This activity has potential to expose live feeds, user data, and create a foothold into internal networks, with implications for privacy, compliance, and physical security. This breach is notable today as attempts to exploit Hikvision and similar IoT cameras continue at scale, highlighting persistent IoT security challenges due to poor credential hygiene, slow patch adoption, and device interface limitations. The incident demonstrates ongoing risk as attackers increasingly automate targeting of legacy and unpatched embedded devices across global networks.
8 months ago
Kill Chain
Cisco SNMP Zero-Day: Active Exploits Target IOS XE Network Devices in 2025
In September 2025, Cisco disclosed a critical vulnerability (CVE-2025-20352) affecting its IOS and IOS XE operating systems, actively exploited via the SNMP subsystem. The flaw stems from a stack-based buffer overflow that allows authenticated remote attackers to trigger denial-of-service or potentially achieve root-level remote code execution. Attackers utilized crafted SNMP packets over both IPv4 and IPv6 to compromise devices with SNMP enabled, including popular models like the Meraki MS390 and Catalyst 9300. Cisco confirmed attacks in the wild following credential compromise, urging immediate patching, as no reliable workarounds exist. This incident highlights the ongoing risks associated with ubiquitous network protocols like SNMP and the necessity of rapid response to zero-day exploits within core infrastructure. The rise of attacks targeting network management systems signals both increased attacker sophistication and heightened regulatory scrutiny.
8 months ago
Kill Chain
PyPI Phishing Attack Exposes Open-Source Supply Chain in 2025
In September 2025, the Python Package Index (PyPI) suffered a targeted supply-chain phishing campaign, where threat actors impersonated PyPI via convincing emails and domain lookalikes (such as pypi-mirror.org). Attackers sent phishing emails to PyPI maintainers, warning of account suspension and requesting email verification. Unsuspecting victims who followed malicious links and entered credentials risked account compromise, enabling attackers to breach legitimate developer accounts. The likely aim was to either infect existing packages with malware or introduce new malicious packages into trusted software repositories, potentially impacting the broader Python ecosystem. This incident underscores the growing sophistication of software supply-chain threats, especially as open-source repositories face sustained phishing campaigns and credential harvesting tactics. As phishing campaigns increasingly target developers and critical infrastructure, strong phishing-resistant authentication and vigilant domain monitoring are now essential industry-wide defenses.
8 months ago
Kill Chain
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.
8 months ago
Kill Chain
Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed
In September 2025, a critical, still-unpatched vulnerability (CVE-2025-10184) was publicly disclosed in OnePlus smartphones running OxygenOS 12 through 15. Discovered by Rapid7, the flaw enables any installed app—without explicit permissions or user input—to access and exfiltrate SMS content and metadata on affected devices. This exposure was caused by insecurely exported content providers in the custom Android Telephony package, allowing SQL injection-style inference attacks. Despite multiple disclosure attempts, OnePlus did not respond for over four months; the details, including a proof of concept, were disclosed publicly to accelerate a fix. The case underscores rising risks from insecure mobile customizations and vendor slow response, especially as attackers increasingly exploit flaws in widely deployed consumer devices. With the proliferation of mobile-centric attacks and regulatory scrutiny on data privacy, this breach highlights the urgent need for robust patch management and proactive mobile security.
8 months ago
Kill Chain
Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge
In September 2025, Cisco disclosed a high-severity zero-day vulnerability (CVE-2025-20352) affecting IOS and IOS XE network infrastructure devices. The flaw, a stack-based buffer overflow in the SNMP subsystem, allowed remote, authenticated attackers with low privileges to cause denial-of-service and, in some cases, permitted high-privileged attackers to fully compromise devices. Exploitation was detected after local administrator credentials were stolen, enabling threat actors to send malicious SNMP packets over IPv4/IPv6, impacting unpatched devices globally. Immediate patching was recommended as no workarounds existed except tightly restricting SNMP access. This incident underscores the criticality of timely patching and robust identity and network access controls, as attackers increasingly target network infrastructure via both credential compromise and protocol-level vulnerabilities. Industry-wide, it marks an escalating trend of high-impact, infrastructure-level exploits requiring urgent coordinated response.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports