Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Phoenix Attack Bypasses DDR5 Rowhammer Defenses in 2025
In September 2025, researchers from ETH Zurich and Google disclosed the 'Phoenix' attack—a novel Rowhammer-based hardware vulnerability that successfully bypasses the Target Row Refresh (TRR) defenses in popular DDR5 memory chips, specifically targeting modules from market leader SK Hynix. By exploiting specific shortcomings in TRR’s sampling intervals and synchronizing access over precise refresh cycles, the Phoenix attack can reliably induce bit flips in physical memory. In controlled tests, the attack enabled researchers to gain root-level privileges on commodity systems in under two minutes, expose sensitive cryptographic keys across virtual machines, and manipulate binaries such as sudo for rapid local privilege escalation. The vulnerability, now tracked as CVE-2025-6202, impacts DDR5 modules manufactured between January 2021 and December 2024, posing industry-wide risk since current mitigations are ineffective for existing hardware. This incident stands out as it revives concerns over hardware-level attacks that are resistant to conventional software security solutions. As threats like Phoenix emerge, it highlights the rapid evolution of side-channel and privilege-escalation techniques even in the face of new hardware protections, underlining the pressing need for industry collaboration and innovation on memory security standards.
8 months ago
Kill Chain
Malicious MCP Servers: How AI Supply Chain Integrations Were Weaponized in 2024
In early 2024, security researchers uncovered a novel supply chain attack exploiting the Model Context Protocol (MCP), an emerging integration layer for AI assistants. Attackers published seemingly legitimate MCP servers on public repositories such as PyPI, which, once installed by developers, silently harvested sensitive credentials, SSH keys, cloud configs, and API secrets. Data exfiltration was cleverly disguised as benign HTTP requests to plausible endpoints, while the malicious packages mimicked real productivity tools, evading both user scrutiny and common detection mechanisms. This attack leveraged implicit trust in third-party AI extensions, exposing a major blind spot for organizations integrating AI into development workflows. This breach reflects a growing trend where adversaries weaponize trusted AI integration points, mirroring techniques seen in Open Source and DevOps supply chain compromises. As enterprise AI adoption accelerates, similar threats targeting protocol-level integration, plugin ecosystems, and shadow AI deployments are expected to rise, intensifying regulatory and governance pressures around software supply chain security.
8 months ago
Kill Chain
Inside the 2025 Salesloft Drift SaaS Supply Chain Breach: Lessons in Token Management
In early 2025, a significant supply chain breach occurred when threat actor UNC6395 exploited a dormant OAuth token from a third-party Salesloft Drift integration within a Salesforce environment. Leveraging the compromised token—which bypassed MFA—the attacker launched automated connections from multiple unknown VPNs, enumerating CRM accounts and exfiltrating customer data, including embedded credentials. This enabled lateral movement, granting persistent, unauthorized access to hundreds of downstream client Salesforce instances and facilitating privilege escalation into additional systems via harvested secrets. The incident underscores an urgent trend of attackers exploiting inadequately governed third-party integrations, token sprawl, and absent monitoring. With growing SaaS adoption and rising API-driven architectures, identity-driven supply chain attacks have become top risks, accelerating regulatory scrutiny and industry demand for automated token hygiene, lifecycle management, and more rigorous third-party security postures.
8 months ago
Kill Chain
Gentlemen Ransomware Exploits Vulnerable Driver to Disable Enterprise Security (2024)
In early 2024, the Gentlemen ransomware group executed a sophisticated attack leveraging a vulnerable version of the ThrottleStop.sys driver to disable antivirus and endpoint detection and response (EDR) systems. By exploiting this signed but flawed driver, the attackers were able to gain kernel-level privileges, terminate security defenses, and deploy ransomware effectively across targeted organizations. The impact resulted in rapid file encryption, significant operational disruption, and increased ransom demands as incident response capabilities were bypassed. This incident highlights the growing trend of ransomware operators abusing trusted, vulnerable drivers to evade security controls. The ease with which attackers weaponize driver vulnerabilities underscores the urgent need for organizations to enhance driver and device control, patch management, and implement Zero Trust security strategies.
8 months ago
Kill Chain
SonicWall Firewalls Under Siege: Akira Ransomware Exploits CVE-2024-40766
Between July and August 2024, Akira ransomware affiliates targeted SonicWall firewall devices by exploiting CVE-2024-40766, a vulnerability in the SSL VPN protocol, combined with widespread configuration errors. Despite the availability of patches, attackers successfully accessed devices where remediation steps such as local password resets after firmware upgrades and proper multi-factor authentication (MFA) implementation were neglected. These campaigns leveraged misconfigured LDAP group permissions and compromised credentials to gain initial access, enabling Akira to steal sensitive data and encrypt systems across numerous organizations. The resulting attacks led to data theft, system downtime, and expensive ransom demands, with impacts observed globally, including within Australia. Akira’s ongoing surge illustrates the growing sophistication and persistence of ransomware groups in targeting both unpatched and improperly configured perimeter devices. This attack wave highlights the critical need for organizations to not only apply security patches promptly but to rigorously follow up with secure configuration and identity management measures to prevent operational and financial losses.
8 months ago
Kill Chain
AsyncRAT Attackers Exploit ConnectWise ScreenConnect—Credential & Crypto Theft on the Rise
In September 2025, cybersecurity researchers identified a sophisticated attack leveraging the ConnectWise ScreenConnect remote monitoring tool to deliver AsyncRAT, a potent remote access trojan. Threat actors exploited legitimate RMM infrastructure to establish unauthorized access, bypass defenses, and deploy a VBScript-based loader on victim systems. Once installed, AsyncRAT facilitated unauthorized credential harvesting and cryptocurrency theft from compromised hosts, exposing sensitive business and personal data. The campaign’s use of trusted IT management software as an initial entry vector complicated detection and posed significant risks to organizations relying on remote administration tools. This incident underscores an increasing security challenge: the abuse of legitimate remote management solutions by attackers to evade detection and propagate malware. As identity-driven and tool-based attacks surge, businesses must re-examine their controls, segmentation, and monitoring to counter exploitation of sanctioned IT utilities.
8 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More
On September 9, 2025, Microsoft released its September Patch Tuesday updates, addressing 177 vulnerabilities across its ecosystem, including 86 that impacted Microsoft products directly. Among these, 13 were rated as critical, and two had already been publicly disclosed. Notable vulnerabilities included improper URL security zone classification (CVE-2025-54107, CVE-2025-54917), which could allow attackers to bypass security features, and several remote code execution flaws affecting critical workloads. While none of these vulnerabilities were exploited before disclosure, their wide range—including issues in Azure, Office, and the Windows kernel—signals continued risk across cloud and on-premises environments. These vulnerabilities highlight evolving attacker techniques, such as zone misclassification and privilege escalation in cloud services, while underscoring the complexity of patch management in hybrid infrastructures. The scale of affected Microsoft and open-source components (like Azure Linux/Mariner) points to the growing regulatory and operational urgency for comprehensive and timely vulnerability management.
8 months ago
Kill Chain
Vyro AI 2024 GenAI Data Leak: Why Cyber Hygiene Can't Wait
In early 2024, Vyro AI experienced a significant data leak involving the unintentional exposure of proprietary and sensitive user data via a GenAI platform. The incident occurred when internal users, unaware of best security practices, shared confidential information with generative AI tools that did not have adequate encryption or access controls. This exposed private data to unauthorized individuals and third parties, highlighting deficiencies in the company’s data protection policies and cloud application oversight. This breach is emblematic of the growing risks associated with GenAI usage in enterprise environments, where shadow IT and user-driven data sharing can sidestep traditional security controls. As organizations adopt AI at scale, ensuring robust data governance and compliance is more critical than ever to avoid regulatory and reputational fallout.
8 months ago
Kill Chain
VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks
In September 2025, security researchers from ETH Zurich disclosed 'VMScape,' a sophisticated side-channel attack that breaks guest-host isolation in virtualized environments by exploiting incomplete speculative execution mitigations in modern AMD and Intel CPUs. The exploit enables a malicious guest VM to leak sensitive data, such as cryptographic keys, from the unmodified QEMU hypervisor memory, bypassing existing Spectre defenses without requiring host compromise. The attack impacts AMD Zen 1–5 and Intel Coffee Lake CPUs, allowing memory leaks at rates that threaten cloud multi-tenancy and data privacy. While VMScape requires deep technical expertise and sustained attack duration, its discovery highlights ongoing challenges in securing virtualization infrastructure against novel hardware-level threats. The incident underscores the need for prompt hardware and software mitigation deployment and a renewed focus on isolation techniques amid rising CPU vulnerability disclosures.
8 months ago
Kill Chain
Ascension Health 2024: Kerberoasting Ransomware Attack Exposes Microsoft Security Risks
In May 2024, Ascension Health experienced a major ransomware breach, impacting over 5.6 million patient records. Attackers exploited a contractor’s click on a malicious Bing search result in Microsoft Edge, leveraging a 'Kerberoasting' attack against Microsoft Active Directory. By abusing weak and legacy RC4-encrypted Kerberos service account credentials, attackers escalated privileges and moved laterally across sensitive healthcare infrastructure, ultimately exfiltrating patient data and disrupting operations. The incident highlighted significant shortcomings in Microsoft's default security settings and communication of critical risks to enterprise customers, even after prior warnings from security experts and U.S. government officials. The breach is emblematic of a rising trend in identity-based and ransomware attacks exploiting outdated cryptographic standards across critical infrastructure sectors, especially healthcare. Regulatory and public scrutiny on vendor responsibility, ransomware defense, and secure default configurations have intensified following this high-profile compromise.
8 months ago
Kill Chain
2025 Cursor AI Code Editor Vulnerability: Supply-Chain Risk via Malicious Repositories
In September 2025, a security flaw was disclosed affecting Cursor, an AI-powered code editor, that allowed silent code execution when users opened repositories embedded with malicious payloads. The vulnerability stemmed from a default-disabled security setting, letting attackers execute arbitrary code on victim machines under their own user privileges. Security researchers highlighted the risk of potential supply-chain attacks, as any developer opening a tampered repository could unwittingly trigger the exploit, potentially leading to credential theft, system compromise, or further lateral movement within organizational networks. The impact was amplified by Cursor's AI-driven capabilities and its popularity in modern development environments. This incident spotlights the growing risks at the intersection of AI-driven tools and software supply chains. With more organizations relying on smart code editors and automated workflows, attackers are increasing their focus on weaknesses in tool defaults and developer behaviors, driving regulatory concern and heightening the urgency for robust code execution safeguards.
8 months ago
Kill Chain
Cryptojacking Surge: TOR-Based Attack Exploits Docker API Misconfigurations in 2025
In July 2025, cybersecurity researchers identified a new wave of cryptojacking attacks leveraging the TOR network to hide command-and-control infrastructure. Attackers targeted internet-exposed and misconfigured Docker APIs, deploying malicious containers that mined cryptocurrency on compromised infrastructures. This campaign, tracked by Akamai and initially reported by Trend Micro in June 2025, showed sophisticated behaviors including blocking rival threat actors and securing persistence, which increased the impact on affected organizations by silently draining cloud computing resources and escalating operational costs. This incident highlights the growing convergence of container security risks and anonymizing networks like TOR, reflecting a broader trend of attackers shifting toward stealthy, infrastructure-focused exploits. With cloud-native workloads and container orchestration becoming standard, organizations face urgent regulatory and operational pressure to harden APIs and improve cloud security hygiene.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports