Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks
In September 2025, Supermicro disclosed critical firmware vulnerabilities (CVE-2025-7937 and CVE-2025-6198) affecting its server Baseboard Management Controller (BMC). Security researchers at Binarly demonstrated that attackers could leverage these flaws to bypass firmware signature verification and the BMC root of trust, allowing deployment of persistent, malicious firmware on widely used Supermicro servers. Exploits could grant adversaries complete, long-term control over both the BMC and host OS, enabling stealthy persistence and reliable evasion of security controls, while systems appeared to be running valid, signed code. Supermicro confirmed the vulnerabilities, releasing firmware patches, but proof-of-concept exploits are already public. This incident underscores the evolving challenge of hardware-level attacks, as advanced threat actors increasingly target supply chain and firmware layers to establish persistent, hard-to-detect footholds. Recent regulatory pressure and rising incidents of firmware-based threats highlight the urgency for security teams to elevate visibility and controls across hardware trust boundaries.
8 months ago
Kill Chain
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.
8 months ago
Kill Chain
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.
8 months ago
Kill Chain
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.
8 months ago
Kill Chain
Critical Wondershare RepairIt Vulnerabilities in 2025 Expose User Data and AI Models
In September 2025, security researchers from Trend Micro uncovered two critical vulnerabilities in Wondershare RepairIt, a leading file repair software. Identified as CVE-2025-10643 (authentication bypass, CVSS 9.1) and a second AI model tampering flaw, these vulnerabilities allowed unauthorized attackers to access sensitive user information and potentially manipulate embedded AI models. Exploitation could be achieved over unencrypted traffic routes, making lateral movement and data exfiltration easier for adversaries. The flaws highlighted the growing risks associated with AI-driven software and the increased attack surface presented by supply chain exposures. This incident underscores the urgency of securing both traditional application logic and the growing use of embedded AI models. Adversaries are increasingly targeting AI supply chains and exploiting weak east-west segmentation controls, a pattern observed in several recent breaches. Regulatory scrutiny and customer expectations around data protection continue to mount.
8 months ago
Kill Chain
Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)
In June 2024, a malicious npm JavaScript package was discovered masquerading as a utility library while covertly deploying a credential-stealing malware. Attackers cleverly embedded the malicious payload using steganography by hiding harmful code within QR code images bundled in the package. Once installed by developers, the malware extracted sensitive credentials and communicated with attacker-controlled infrastructure, posing a significant risk to any organization that unknowingly integrated the tainted dependency in its software supply chain. This incident underscores the mounting threat posed by highly obfuscated, supply chain attacks leveraging trusted open-source platforms. The attack highlights the emergence of sophisticated malware delivery via unconventional vectors such as steganographic encoding within common file formats. With broad software ecosystem dependencies and rapid code adoption, organizations face increasing urgency to vet third-party packages and enforce robust supply chain security controls.
8 months ago
Kill Chain
Scattered Spider’s $115M Ransomware Blitz: How Hybrid Attacks Changed Compliance Expectations in 2025
In 2025, U.K. and U.S. law enforcement charged members of the cybercrime group Scattered Spider, including Thalha Jubair and Owen Flowers, with a $115 million ransomware and extortion campaign targeting sectors such as retail, transportation, hospitality, and healthcare. The group, also known as 0ktapus and UNC3944, leveraged advanced social engineering, SIM-swapping, phishing, and remote access tactics to breach hundreds of organizations—including notorious attacks on MGM Resorts, Caesars Entertainment, Transport for London, and major U.K. retailers. Law enforcement tracked cryptocurrency ransoms to the group, seizing millions in illicit funds and identifying extensive operational overlap with LAPSUS$ and other threat collectives. This incident highlights the escalating threat posed by young, identity-driven ransomware affiliates employing blended TTPs, exploiting cloud and hybrid infrastructures, and leveraging insider access. Their success in spanning critical infrastructure and commercial targets underscores the urgent need for multilayered defenses, compliance vigilance, and aggressive regulatory and incident response readiness.
8 months ago
Kill Chain
Cloud Misconfiguration: How Exposed Docker Daemons Fueled a 2024 DDoS Botnet
In early 2024, cybersecurity researchers uncovered a widespread campaign exploiting misconfigured Docker daemons in cloud environments. Attackers leveraged openly accessible Docker APIs to deploy malicious containers and enlist compromised servers into a large-scale DDoS (Distributed Denial of Service) botnet. Using legitimate, cloud-native tools made detection and remediation more challenging for security teams. The incident resulted in increased infrastructure costs, service disruptions, and heightened risk of lateral movement and data exfiltration within affected organizations. This attack is illustrative of a growing trend where adversaries abuse cloud-native technologies and misconfigurations to orchestrate large-scale, persistent threat activity. As organizations accelerate cloud adoption, gaps in cloud security posture and lack of network segmentation are creating new attack surfaces, stressing the need for enhanced visibility, zero trust controls, and real-time anomaly detection.
8 months ago
Kill Chain
GitHub’s NPM Supply Chain Attack Shows Urgent Need for Token Security in 2024
In early 2024, GitHub took action to secure the NPM supply chain following a surge of sophisticated attacks exploiting weak authentication protocols and overly permissive access tokens. Adversaries—most notably those deploying the Shai-Hulud malware—compromised developer or maintainer accounts, then published malicious NPM packages, creating a vector for large-scale supply chain infection. The breaches risked both open-source and enterprise users, potentially allowing attackers access to downstream projects, credential leakage, and further lateral movement in corporate ecosystems. This incident is a critical reminder that software supply chains are increasingly targeted by cybercriminals using stolen credentials and token abuse. It highlights how even trusted platforms can expose organizations to risk when security controls such as MFA and token lifecycles are insufficiently enforced.
8 months ago
Kill Chain
UNC6148 Installs OVERSTEP Backdoor in SonicWall SMA Devices: 2024 APT Breach Analysis
In early 2024, a sophisticated threat actor group identified as UNC6148 targeted SonicWall Secure Mobile Access (SMA) appliances with a newly discovered backdoor malware named 'OVERSTEP'. By exploiting unpatched vulnerabilities, attackers gained unauthorized access, deployed persistent hidden software, exfiltrated credentials, and established remote control over affected devices. The compromise allowed lateral movement within victim networks, providing attackers with ongoing access to sensitive data and resources while evading detection for extended periods. Organizations using SonicWall SMA were particularly at risk of operational disruptions, data breaches, and unauthorized exposure of business-critical systems. This incident exemplifies the growing trend of supply-chain and edge-device attacks by advanced persistent threats (APTs). The deployment of stealthy backdoors like OVERSTEP signals increased sophistication and automation among threat actors, further pressuring organizations to improve detection, patch management, and east-west segmentation strategies.
8 months ago
Kill Chain
GitHub npm 2025: Major Supply Chain Attacks Drive Aggressive Security Overhaul
In August and September 2025, GitHub's npm ecosystem suffered a series of coordinated supply chain attacks involving high-impact campaigns such as "s1ngularity," "GhostAction," and worm-style "Shai-Hulud." Threat actors infiltrated GitHub repositories and npm packages via credential compromise and weaknesses in access controls, ultimately compromising thousands of developer accounts and private repositories. These attacks resulted in theft of sensitive code and data, disruption across open-source ecosystems, and considerable remediation costs for affected organizations. In response, GitHub has announced the rapid rollout of mandatory two-factor authentication, granular access tokens, and removal of insecure authentication methods for npm publishing, aiming to prevent recurrence and empower developers to proactively enhance their security posture. This wave of supply chain attacks underscores the growing risk of software dependency manipulation at scale. The incident highlights the urgency of hardening access controls, enforcing stronger authentication, and shifting developer communities toward zero trust principles to counteract increasingly sophisticated threats facing software ecosystems.
8 months ago
Kill Chain
UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025
In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations. The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports