Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
SolarWinds Hit by Yet Another Web Help Desk RCE Patch Bypass in 2025
In September 2025, SolarWinds disclosed a critical security vulnerability (CVE-2025-26399) in its Web Help Desk (WHD) software, affecting version 12.8.7 and prior. This flaw—stemming from unsafe deserialization in the AjaxProxy component—permits unauthenticated attackers to achieve remote code execution (RCE) on affected servers. The issue represents a patch bypass for earlier vulnerabilities (CVE-2024-28986, CVE-2024-28988), demonstrating persistent weaknesses in the remediation process. While there are no documented exploitations as of publication, previous flaws in this component were added to CISA’s Known Exploited Vulnerabilities catalog, underscoring risk to organizations reliant on WHD for ticketing and IT asset management. This incident underscores the enduring challenge of patch bypasses, where subsequent hotfixes fail to fully resolve underlying flaws, leading to repeated exposures. Weaknesses in serialization logic and high-value IT management software are a favored target for attackers seeking lateral movement, privilege escalation, or supply chain compromise.
8 months ago
Kill Chain
State-Sponsored Command Injection Breach Targets Libraesva ESG in 2025
In September 2025, Libraesva, a widely used email security gateway provider, identified and patched a medium-severity vulnerability, CVE-2025-59689, actively exploited by a state-sponsored threat actor. The flaw involved improper sanitization in the handling of compressed email attachments, allowing attackers to execute arbitrary shell commands from non-privileged user accounts. The exploit targeted a specific appliance, highlighting both the technical skill and tactical precision of the attacker. Libraesva’s emergency fix was deployed within 17 hours to cloud and on-premise environments, and an automated scan for indicators of compromise was also released. Organizations running unsupported product versions must upgrade manually to remain protected. This incident exemplifies the growing sophistication and focus of state-linked adversaries exploiting command injection flaws in trusted security layers like email gateways. As supply-chain and infrastructure-focused attacks increase across sectors, organizations face mounting regulatory and operational pressure to maintain up-to-date security and swift response mechanisms.
8 months ago
Kill Chain
ShadowV2 Botnet Weaponizes AWS Docker Misconfigurations for DDoS-for-Hire Attacks
In September 2025, researchers uncovered that the ShadowV2 botnet exploited misconfigured Docker containers deployed on Amazon Web Services (AWS) instances. Attackers leveraged these open containers to install Go-based malware, transforming vulnerable cloud servers into nodes for distributed denial-of-service (DDoS) attacks available for hire. The botnet operators were able to saturate targets’ networks and disrupt organizational operations using cloud-scale resources, highlighting a sophisticated abuse of both infrastructure-as-a-service offerings and container orchestration weaknesses. The campaign predominantly impacted organizations with unmanaged or lax security practices around containerized workloads and cloud network borders. This attack underscores the growing trend of threat actors targeting cloud misconfigurations and using them as platforms for broader cybercriminal infrastructure. The incident reflects both the increasing commoditization of DDoS-as-a-service and the urgency of securing cloud-native deployments against well-known attack patterns.
8 months ago
Kill Chain
GitHub Mandates 2FA and Short-Lived Tokens After npm Supply Chain Attack
In September 2025, GitHub responded to a series of sophisticated supply chain attacks targeting the npm package ecosystem, most notably the Shai-Hulud compromise. Adversaries exploited weak authentication mechanisms and abused publishing tokens to inject self-replicating malware into widely used npm libraries. These malicious packages were automatically distributed downstream to thousands of unsuspecting development workflows, putting the integrity of software supply chains at risk. The attacks prompted GitHub to mandate two-factor authentication (2FA) for all npm publishers and to introduce short-lived authentication tokens to substantially reduce exposure to token theft. This incident underscores the growing trend of attackers targeting developer ecosystems as entry points for widespread compromise. The enhanced security controls by GitHub reflect a broader industry movement to harden software supply chains amid intensifying regulatory scrutiny and increasingly sophisticated attack methods.
8 months ago
Kill Chain
SolarWinds 2025 RCE Flaw: What CVE-2025-26399 Means for Enterprise Security
In September 2025, SolarWinds disclosed a critical vulnerability (CVE-2025-26399, CVSS 9.8) in its Web Help Desk software, allowing remote code execution via deserialization of untrusted data. Attackers could exploit this flaw to execute arbitrary commands on affected systems, potentially leading to full compromise of customer environments. SolarWinds released urgent hotfixes to address the flaw after it was identified during routine security testing, emphasizing the risk to organizations running unpatched instances exposed to the internet. This incident underscores the persistent threat posed by software supply chain vulnerabilities and insecure coding practices in widely used IT management platforms. With high-profile supply chain attacks on the rise, rapid vulnerability disclosure and patching are now critical to minimizing both direct exploitation and regulatory exposure.
8 months ago
Kill Chain
Supermicro BMC Supply-Chain Bugs Reveal Firmware Trust Weaknesses in 2025
In September 2025, researchers unveiled two medium-severity vulnerabilities affecting Supermicro's Baseboard Management Controller (BMC) firmware. Attackers could leverage improper cryptographic signature validation to bypass root-of-trust controls, allowing the deployment of malicious firmware images through supply-chain vectors. The flaws enable an adversary to compromise hardware integrity, potentially resulting in persistent access, data exfiltration, and disruption within enterprise server environments. Supermicro promptly released firmware updates and provided mitigation guidance as exploitation risks became public. This incident reflects an unsettling rise in supply-chain attacks targeting device firmware and hardware trust anchors. It underscores both the growing sophistication of attacker techniques and the criticality of maintaining robust verification, anomaly detection, and real-time firmware integrity validation for modern IT infrastructure.
8 months ago
Kill Chain
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.
8 months ago
Kill Chain
Microsoft Entra ID Flaw Exposed: How One Vulnerability Enabled Global Admin Impersonation
In September 2025, Microsoft disclosed a severe security flaw (CVE-2025-55241) affecting its Entra ID (formerly Azure Active Directory) service. The vulnerability, which received a maximum CVSS score of 10.0, allowed threat actors to bypass token validation and impersonate any user—including Global Administrators—across any tenant. Successful exploitation could grant attackers unrestricted access to sensitive data and resources within affected organizations, making this a high-impact privilege escalation incident. Microsoft responded swiftly, issuing a critical patch to contain the risk and urging immediate customer action. This incident highlights the ongoing trend of identity-based attacks against cloud platforms, emphasizing the necessity of robust access controls and vigilant monitoring. The discovery reinforces the risks of SaaS/IDaaS privilege escalation, as attackers increasingly target provider-side weaknesses to achieve large-scale compromise.
8 months ago
Kill Chain
Multi-Vector Cyberattack 2025: AI, Chrome 0-Day, DDR5 and npm Supply Chain Breach
In September 2025, a multifaceted wave of cyber threats was observed, including a Chrome zero-day exploit, AI-generated hacking toolkits, active exposure of DDR5 memory vulnerability (Rowhammer-based bit-flip attacks), and a virulent npm worm targeting the software supply chain. Attackers leveraged 0-day browser exploits to execute malicious code, engineered advanced AI tools for automation, and deployed the npm worm to laterally move via package dependencies. The surge in attack sophistication resulted in unauthorized access, rapid lateral movement, and significant operational disruption for developers and enterprises globally. This incident underscores an urgent pivot in attacker tactics—combining classic and novel vulnerabilities across infrastructure, code, and memory. The simultaneous exploitation of multiple vectors signals a broader trend of adaptive threat landscapes, increasing regulatory scrutiny, and the need for rapid detection, cross-layer visibility, and agile patching cycles.
8 months ago
Kill Chain
Critical Microsoft Entra ID Flaw Put Every Cloud Tenant at Risk in 2024
In early 2024, cybersecurity researchers uncovered a critical authentication flaw affecting Microsoft Entra ID (formerly Azure Active Directory), potentially enabling attackers to hijack any company's Entra ID tenant worldwide. By exploiting legacy identity features in combination with certain misconfigurations, attackers could bypass authentication controls and gain unauthorized administrative access, allowing full control over organizational resources in the affected tenants. Prompt discovery and responsible disclosure to Microsoft helped prevent active exploitation, though the underlying issue raised significant concern across the enterprise cloud ecosystem. This incident underscores the urgent need for organizations to continuously review legacy configurations, monitor identity security posture, and respond proactively to new classes of authentication bypass risks. With identity-based attacks rising across sectors, cloud environments are particularly vulnerable, highlighting zero trust best practices and ongoing vigilance as regulatory and threat environments evolve.
8 months ago
Kill Chain
2025 Picus Blue Report: Why Ransomware Still Evades Defenses
In early 2025, the Picus Blue Report identified a concerning trend in global ransomware attacks: despite widespread awareness of ransomware tactics, organizations failed to prevent over a third of attack attempts, with prevention rates plummeting to 62%. Far more alarming, only 3% of simulated data exfiltration attempts were effectively blocked, exposing substantial gaps in data security frameworks. Attackers leveraged a blend of known and emerging ransomware variants to infiltrate networks, bypassing traditional and next-gen defenses by exploiting east-west traffic and insufficient segmentation. This led to successful encryption and large-scale data theft, disrupting business continuity for multiple sectors globally. This incident underscores a broader industry challenge: as ransomware evolves, so do the techniques for bypassing established defenses. The drastic fall in exfiltration prevention highlights an urgent need for modernized controls, especially with the regulatory and reputational stakes of breaches rising sharply in 2025.
8 months ago
Kill Chain
Fortra GoAnywhere MFT 2024: License Servlet Zero-Day Exposes File Transfer Infrastructure
In June 2024, Fortra disclosed a critical vulnerability (CVE-2024-XXXX) in its GoAnywhere Managed File Transfer (MFT) product’s License Servlet, enabling unauthenticated attackers to execute system commands remotely via command injection. Researchers discovered that by submitting crafted requests to the vulnerable servlet, attackers could gain full control of affected servers. No authentication was required, significantly increasing the risk of exploitation. Fortra released immediate security updates and guidance after reports of active exploitation attempts surfaced. Impacted organizations primarily included enterprises leveraging GoAnywhere MFT for secure file transfers, resulting in heightened risk of data exfiltration and business disruption. This incident underscores the ongoing importance of timely patch management, especially for widely used secure transfer solutions. The vulnerability’s ease of exploitation and criticality reflects trends of attackers targeting third-party file transfer products—often for extortion or ransomware campaigns—prompting renewed regulatory and industry scrutiny.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports