Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
TP-Link Routers Hit by 2025 Zero-Day: What You Need to Know About the CWMP Exploit
In September 2025, TP-Link confirmed a critical zero-day vulnerability impacting multiple router models, including Archer AX10 and AX1500. Discovered by independent researcher Mehrun (ByteRay), the stack-based buffer overflow exists within the routers' CWMP (CPE WAN Management Protocol) implementation, specifically in handling SOAP messages due to improper validation in 'strncpy' calls. Attackers can exploit this flaw to achieve remote code execution by redirecting devices to malicious CWMP servers or leveraging unchanged default credentials, leading to device compromise. Once compromised, adversaries can reroute DNS queries, intercept traffic, and inject malicious payloads, raising severe risks for users and organizations relying on affected devices. The continued exploitation of similar router vulnerabilities by groups like Quad7 botnet highlights a shift in attacker TTPs towards leveraging consumer and SOHO networking devices as entry points and persistence mechanisms. The prevalence of these attacks underscores the urgent need for robust patch management and secure configuration in edge infrastructure.
8 months ago
Kill Chain
Q2 2025 Global Ransomware Surge: Qilin, Nefilim, Black Kingdom, and the Modern Threat Landscape
In Q2 2025, the global ransomware threat landscape saw a significant surge with the discovery of 1,702 new ransomware variants and nearly 86,000 users targeted. High-profile law enforcement actions included indictments and extraditions involving Black Kingdom, Nefilim, Ryuk, DoppelPaymer, and RobbinHood operators. Major campaigns leveraged vulnerabilities in SAP NetWeaver, Fortinet devices, and Microsoft Windows (CLFS driver), with actors like Qilin and DragonForce demonstrating adeptness in exploiting zero-days and supply chain weaknesses. Double extortion and rapid lateral movement were widely observed, affecting critical sectors worldwide, including healthcare, government, and managed service providers. This incident underscores the advancement of ransomware attack tactics, the spread of sophisticated variants, and the persistence of threat actors despite law enforcement measures. The continued exploitation of newly discovered vulnerabilities and focus on high-revenue targets highlight the urgent need for enhanced prevention, detection, and incident response across organizations of all sizes.
8 months ago
Kill Chain
How Attackers Are Sidestepping macOS Built-in Security in 2024
In 2024, researchers and incident responders observed a sophisticated wave of cyberattacks targeting macOS systems, where adversaries adapted to built-in security protections such as Keychain, Gatekeeper, TCC, and System Integrity Protection. Threat actors leveraged utilities like Chainbreaker to extract password data, employed social engineering to bypass File Quarantine and Gatekeeper, and manipulated permission prompts through clickjacking techniques. By exploiting command-line utilities, attackers disabled or evaded standard protections, leading to potential exposure of sensitive credentials and increased risk of full system compromise. The macOS attack landscape continues to evolve, with adversaries innovating to evade resilient, native defenses. Rising adoption of macOS in enterprise environments and the seamless integration with personal devices make these evasion TTPs especially critical for security teams and compliance requirements focused on regulated and sensitive data.
8 months ago
Kill Chain
2025 Spotlight: ESET Uncovers First AI-Powered PromptLock Ransomware
In September 2025, ESET Research identified PromptLock, the first documented case of AI-powered ransomware. While not deployed in active attacks, PromptLock is a sophisticated proof-of-concept that leverages OpenAI’s gpt-oss-20b model via the Ollama API to create malicious Lua scripts in real-time. Written in Golang for both Windows and Linux, PromptLock automates enumeration, exfiltration, and encryption of target system files, with variants found on VirusTotal. Its design demonstrates the feasibility of AI-augmented malware, where dynamic scripting enables rapid adaptation to environments and highly automated attack flows. PromptLock’s discovery highlights the emergence of AI-driven tactics that could accelerate ransomware development and proliferation. As AI tools become more accessible, the risk of advanced, autonomous threats challenging enterprise security controls grows sharply, signaling a pivotal shift in the threat landscape.
8 months ago
Kill Chain
Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks
In early 2024, a significant security incident was discovered involving the inadvertent exposure of Azure Active Directory credentials via a misconfigured JSON configuration file. The public accessibility of this file enabled malicious actors to directly authenticate against Microsoft’s OAuth 2.0 endpoints, bypassing traditional security controls and potentially infiltrating cloud environments. Attackers leveraged this cloud misconfiguration to escalate cloud access, risking business-critical Azure resources, data loss, and lateral movement inside affected organizations. Detection came after researchers observed unusual authentication patterns linked to public file sharing, prompting rapid investigation and remediation efforts. The incident underscores how easily overlooked misconfigurations can undermine enterprise cloud security and compliance obligations. The breach highlights ongoing challenges as organizations migrate sensitive workflows to the cloud. Public file exposure, credential leakage, and abuse of identity platforms like Azure Active Directory remain top attack vectors. This incident amplifies recent regulatory scrutiny, reinforces the need for cloud visibility and zero trust practices, and signals rising attacker sophistication in exploiting misconfigured storage and identity controls.
8 months ago
Kill Chain
Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection
In 2024, a sophisticated phishing-as-a-service (PhaaS) operation leveraged Google and Cloudflare infrastructure to host undetectable phishing sites for over three years. By employing advanced cloaking techniques and encrypted traffic, threat actors were able to evade detection by security platforms and browsers, targeting users globally and harvesting credentials at scale. The persistent campaign highlights the effectiveness of public cloud abuse for malicious operations and the operational difficulties organizations face in detecting and mitigating such well-cloaked threats. This incident underscores a growing trend: cybercriminals turning to public cloud providers for reliable infrastructure and exploiting their reputation to bypass security controls. It also signals the adaptability of phishing campaigns and the need for enhanced monitoring and zero trust strategies in response to evolving attacker TTPs.
8 months ago
Kill Chain
FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)
Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls. This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.
8 months ago
Kill Chain
Amazon Disrupts APT29 Credential Theft Leveraging Cloudflare and Device Code Abuse
In early 2024, Amazon identified and disrupted a credential theft campaign orchestrated by the Russian-linked threat actor APT29 (also known as Cozy Bear or Midnight Blizzard). Attackers redirected targeted users to fraudulent Cloudflare verification pages and abused Microsoft's device code authentication flow to harvest credentials. This sophisticated phishing operation targeted employees with access to sensitive resources and leveraged social engineering along with technical exploits to bypass multi-factor authentication controls. Amazon’s security team coordinated rapid takedown efforts, mitigating potential compromise before widespread damage or data loss could occur. This incident exemplifies the increasing sophistication of nation-state actors, particularly in leveraging supply chain services and authentication protocols. The widespread adoption of identity and device-based authentication has introduced new attack surfaces, highlighting the urgent need for adaptive security measures and ongoing user vigilance in credential management.
8 months ago
Kill Chain
How a Zero-Click Exploit Unleashed AI Agent Mayhem Across Enterprises
In July 2025, researchers disclosed a critical vulnerability affecting generative AI agents deployed widely across enterprises. This exploit, requiring no user interaction (zero-click), enabled remote attackers to commandeer AI agents and gain broad, unauthorized access to sensitive business data and interdependent cloud applications. By leveraging the AI agents’ elevated privileges and extensive network reach, attackers could move laterally across organizational boundaries, exposing data in transit, triggering egress to attacker-controlled infrastructure, and bypassing traditional segmentation and policy enforcement. The incident resulted in heightened risk for data exfiltration, business interruption, and regulatory scrutiny as organizations scrambled to assess and mitigate exposure. This breach highlights the growing risks of autonomous AI behavior and the challenges of applying conventional network and application security frameworks to evolving AI-driven architectures. The attack underscores the urgent need for robust segmentation, encrypted traffic, and continuous threat monitoring in AI/ML environments, as both threat actors and defenders rapidly adapt to the rise of agentic AI.
8 months ago
Kill Chain
Nearly 2,000 MCP Servers Left Exposed by Authentication Misconfiguration in 2024
In early 2024, security researchers discovered that nearly 2,000 MCP (Management Control Plane) servers worldwide were left completely unsecured due to disabled or unconfigured authentication settings. This cloud misconfiguration meant that anyone with internet access could gain full administrative control, potentially allowing unauthorized parties to manipulate workloads, exfiltrate sensitive data, or deploy malicious software at will. The lack of basic security controls exposed organizations leveraging agentic AI services to severe operational risks, compliance violations, and potential breaches of critical business infrastructure. This incident underscores a troubling pattern of cloud misconfiguration, particularly as organizations rapidly adopt AI and cloud-native platforms. As threat actors increasingly target exposed management interfaces and identity systems, the urgent need for robust authentication and continuous configuration monitoring has never been greater.
8 months ago
Kill Chain
Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024
In early 2024, an independent security researcher uncovered a privilege escalation vulnerability in Amazon Elastic Container Service (ECS) that allowed attackers to abuse an undocumented protocol to gain IAM permissions well beyond their original access. By exploiting a misconfiguration in ECS’s internal handling of credentials, a malicious user could escalate from container-level privileges to full IAM role hijacking, enabling lateral movement across cloud environments and access to sensitive AWS resources. Amazon responded quickly and patched the issue after disclosure, but the flaw potentially exposed numerous customer environments to risk. This incident underscores the growing risk of cloud misconfigurations and privileged identity attacks, as well as the need for real-time monitoring of cloud service behaviors. Security teams should recognize the increasing creativity of threat actors targeting identity and access weaknesses within major cloud providers.
8 months ago
Kill Chain
Cloud Misconfig Leaves 2,000 MCP Servers Wide Open to Attack
In June 2024, security researchers uncovered that nearly 2,000 MCP (Managed Cloud Platform) servers were left exposed to the public internet without any authentication required. Attackers could readily gain unfettered administrative access, enabling full server control, lateral movement within environments, and potential exfiltration or disruption of sensitive workloads. The breach was a direct result of critical cloud misconfigurations, specifically the omission of basic authentication on systems underpinning key business and AI operations. While no single threat actor has been publicly attributed, the sheer scale exposes businesses globally to automated attacks, data theft, and business disruption. This incident highlights the persistent danger of insecure cloud defaults, particularly as organizations accelerate adoption of agentic AI and cloud-native architectures. With threat actors increasingly scanning for misconfigured cloud assets and attacker dwell time decreasing, timely secure configuration and visibility are more essential than ever.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports