Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 27 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 313324 / 3054 reports
Suspected China-Nexus APT Exploits VMware vCenter Vulnerability CVE-2026-59310
Impact· CRITICAL

Suspected China-Nexus APT Exploits VMware vCenter Vulnerability CVE-2026-59310

In August 2026, a suspected China-nexus Advanced Persistent Threat (APT) group exploited CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, to execute arbitrary code remotely. This exploitation led to the deployment of a backdoor and a reverse SSH binary, culminating in the installation of Babuk-derived ransomware. The ransomware deployment appeared to serve as a diversion, complicating forensic analysis and potentially masking the primary objectives of the intrusion. This incident underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure through known vulnerabilities. It highlights the necessity for organizations to promptly apply security patches and maintain vigilant monitoring to detect and mitigate such sophisticated attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Urgent: macOS Screen Sharing Vulnerability (CVE-2026-65400) Exploited in the Wild
Impact· CRITICAL

Urgent: macOS Screen Sharing Vulnerability (CVE-2026-65400) Exploited in the Wild

In August 2026, a critical vulnerability (CVE-2026-65400) was discovered in macOS's Screen Sharing feature, allowing remote attackers to bypass authentication and gain root access to systems exposed via port 5900. Exploiting this flaw, attackers installed Monero cryptocurrency miners on compromised machines. Apple released out-of-band patches on August 6, 2026, for macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address this issue. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners?utm_source=openai)) This incident underscores the importance of promptly applying security updates and reassessing the exposure of remote access services. The active exploitation of this vulnerability highlights the ongoing risks associated with unpatched systems and the necessity for robust security practices.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Securing MCP Servers: Protecting Enterprise Secrets from Emerging Threats
Impact· CRITICAL

Securing MCP Servers: Protecting Enterprise Secrets from Emerging Threats

In August 2026, a critical vulnerability was identified in Model Context Protocol (MCP) servers, which are integral in connecting AI agents to enterprise systems. These servers were found to store sensitive credentials, such as API keys and tokens, in plaintext configuration files. Additionally, the decentralized nature of MCP server deployments led to credential sprawl, with secrets scattered across multiple ungoverned servers. This lack of centralized management and oversight resulted in static, long-lived credentials that were rarely rotated, increasing the risk of unauthorized access. Furthermore, MCP servers were susceptible to prompt injection attacks, where malicious instructions embedded in documents or web pages could manipulate AI agents into executing unintended actions, potentially leading to data breaches or system compromises. The significance of this vulnerability is underscored by the widespread adoption of MCP servers in enterprise environments, facilitating AI agents' access to critical tools and data. The exposure of sensitive credentials and the potential for prompt injection attacks highlight the urgent need for organizations to reassess their security protocols surrounding MCP server deployments. Implementing centralized secret management, enforcing least privilege access, and establishing robust monitoring mechanisms are essential steps to mitigate these risks and protect enterprise assets.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Flags Critical Vulnerability in Ray AI Compute Engine
Impact· CRITICAL

CISA Flags Critical Vulnerability in Ray AI Compute Engine

On August 17, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-62593 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation of this critical vulnerability in the Ray AI compute engine. This flaw allows remote code execution via DNS rebinding attacks, particularly affecting developers using Ray versions prior to 2.52.0 in conjunction with Firefox and Safari browsers. The vulnerability arises from inadequate defenses against browser-based attacks, relying on the User-Agent header, which can be manipulated. Exploitation can occur when a developer visits a malicious website or encounters a harmful advertisement, potentially leading to unauthorized code execution on the developer's system. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-62593&utm_source=openai)) The inclusion of CVE-2025-62593 in the KEV Catalog underscores the persistent threat posed by code injection vulnerabilities and the importance of timely patching. Organizations utilizing Ray should immediately upgrade to version 2.52.0 or later to mitigate this risk. This incident highlights the evolving tactics of cyber adversaries and the necessity for continuous vigilance and proactive security measures in software development environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AmnesiaStealer: A New Threat to macOS Users
Impact· HIGH

AmnesiaStealer: A New Threat to macOS Users

In August 2026, a new macOS-targeted malware named AmnesiaStealer was identified, exploiting ClickFix social engineering tactics to infiltrate systems. The malware deceives users into executing malicious commands, leading to the installation of a payload that captures sensitive data, including browser profiles, passwords, cryptocurrency wallets, and keychain information. Notably, AmnesiaStealer employs a 'stream_module' to duplicate victims' browser sessions in a headless mode, granting attackers real-time control over authenticated sessions without alerting the user. This method allows for seamless data exfiltration and potential misuse of personal and financial information. The emergence of AmnesiaStealer underscores a growing trend in sophisticated social engineering attacks targeting macOS users. The malware's ability to hijack browser sessions and operate undetected highlights the need for heightened vigilance and robust security measures. Organizations and individuals must stay informed about such evolving threats and implement proactive defenses to mitigate potential risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Evooo1Bot: The Latest Linux Botnet Threatening IoT Security in 2026
Impact· CRITICAL

Evooo1Bot: The Latest Linux Botnet Threatening IoT Security in 2026

In August 2026, security researchers identified a new Mirai-based modular Linux botnet named Evooo1Bot, which has been actively targeting internet-facing gateway devices from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. By exploiting known vulnerabilities, Evooo1Bot compromises these devices, transforming them into SOCKS5 traffic relay nodes. Beyond proxying capabilities, the malware exhibits functionalities including credential theft, SSH brute-forcing, and the execution of distributed denial-of-service (DDoS) attacks. Notably, Evooo1Bot employs encrypted command-and-control communications over port 443 and implements various persistence mechanisms to maintain control over infected systems. The emergence of Evooo1Bot underscores a concerning trend in the evolution of botnet malware, where attackers are increasingly leveraging compromised IoT devices to facilitate anonymized malicious activities. This development highlights the critical need for organizations and individuals to proactively secure their networked devices by regularly updating firmware, changing default credentials, and disabling unnecessary remote access features to mitigate the risk of exploitation by such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
macOS Screen Sharing Flaw Exploited to Deploy Monero Miner
Impact· CRITICAL

macOS Screen Sharing Flaw Exploited to Deploy Monero Miner

In August 2026, a critical vulnerability (CVE-2026-65400) in macOS's Screen Sharing feature was exploited by attackers to deploy Monero cryptocurrency miners on compromised systems. The flaw allowed unauthenticated remote access via TCP port 5900, enabling attackers to gain root privileges, access files, and modify security settings. The Netherlands' National Cyber Security Centre (NCSC) reported active exploitation of this vulnerability, particularly on systems with port 5900 exposed to the internet. Apple addressed the issue on August 6, 2026, with updates to macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, enhancing state management to enforce proper credential validation. Users unable to update immediately were advised to disable Screen Sharing to mitigate risk. This incident underscores the persistent threat posed by unauthorized cryptocurrency mining and highlights the importance of timely software updates. The exploitation of such vulnerabilities can lead to significant system performance degradation and potential exposure to further malicious activities. Organizations are reminded to regularly review and secure remote access configurations to prevent unauthorized access.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Vercel Breach 2026: Lessons in OAuth Security and Third-Party Risk Management
Impact· HIGH

Vercel Breach 2026: Lessons in OAuth Security and Third-Party Risk Management

In April 2026, Vercel, a prominent cloud platform, experienced a significant security breach initiated through a compromised OAuth token from a third-party AI tool, Context.ai. An attacker exploited this token to access a Vercel employee's Google Workspace account, subsequently infiltrating internal systems and exfiltrating sensitive customer data, including unencrypted credentials and API keys. The breach was publicly disclosed on April 20, 2026, with attackers demanding $2 million for the stolen data. This incident underscores the escalating risks associated with third-party integrations and the critical need for stringent access controls and continuous monitoring of OAuth permissions. The Vercel breach highlights the growing trend of supply chain attacks leveraging OAuth vulnerabilities, emphasizing the necessity for organizations to reassess and fortify their security postures against such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Gunra Ransomware's 2026 Assault on Global Critical Infrastructure
Impact· CRITICAL

Gunra Ransomware's 2026 Assault on Global Critical Infrastructure

In August 2026, the Gunra ransomware group intensified its attacks on global critical infrastructure sectors, including healthcare, finance, and government. Utilizing malware derived from leaked Conti source code, Gunra employs a double-extortion strategy—encrypting data and threatening to publish stolen information unless a ransom is paid. The group gains initial access by exploiting known vulnerabilities in internet-facing devices, particularly firewalls and VPNs, and uses tools like Impacket for lateral movement. Their operations have expanded through a Ransomware-as-a-Service (RaaS) model, recruiting affiliates to scale attacks. ([itpro.com](https://www.itpro.com/security/ransomware/warning-issued-over-gunra-ransomware-gang-as-attacks-ramp-up-globally?utm_source=openai)) This escalation underscores the evolving threat landscape where ransomware groups are increasingly targeting critical infrastructure with sophisticated tactics. Organizations must prioritize patching known vulnerabilities, implementing robust network segmentation, and maintaining offline backups to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Flaw in Flow Neuroscience FL-100: CVE-2026-18164
Impact· HIGH

Critical Security Flaw in Flow Neuroscience FL-100: CVE-2026-18164

In August 2026, a critical vulnerability (CVE-2026-18164) was identified in Flow Neuroscience's FL-100 device, a transcranial direct current stimulation headset used for treating major depressive disorder. The flaw involved hard-coded credentials that allowed attackers within Bluetooth range to bypass authentication and manipulate brain stimulation parameters, potentially overriding safety limits. This vulnerability affected all FL-100 devices manufactured before July 2026. Flow Neuroscience promptly released firmware updates to address the issue, urging users to update their devices via the Flow app. This incident underscores the persistent risks associated with hard-coded credentials in medical devices, a known issue in industrial control systems. The exploitation of such vulnerabilities can lead to unauthorized control over critical device functions, posing significant safety hazards. The healthcare sector must prioritize robust security measures to prevent similar threats, especially as medical devices increasingly incorporate wireless technologies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Command Injection Vulnerability in Johnson Controls Metasys (CVE-2025-26385)
Impact· HIGH

Critical Command Injection Vulnerability in Johnson Controls Metasys (CVE-2025-26385)

In January 2026, a critical command injection vulnerability (CVE-2025-26385) was identified in Johnson Controls' Metasys building automation system. This flaw allowed unauthenticated remote attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability impacted multiple Metasys components, including the Application and Data Server (ADS), Extended Application and Data Server (ADX), and various tools integrated with SQL Express, across versions 12.0 through 14.1. Johnson Controls promptly released patches and provided mitigation strategies to address the issue. This incident underscores the importance of securing building automation systems, especially as they become increasingly interconnected. Organizations are urged to apply the latest patches, follow vendor-recommended hardening guidelines, and implement network segmentation to protect critical infrastructure from similar vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical DoS Vulnerability in Siemens Desigo Controllers (CVE-2026-59693)
Impact· HIGH

Critical DoS Vulnerability in Siemens Desigo Controllers (CVE-2026-59693)

In August 2026, Siemens identified a denial-of-service (DoS) vulnerability in its Desigo DXR and PXC controllers, designated as CVE-2026-59693. This flaw allows attackers to send malformed BACnet packets, causing the devices to become unresponsive to BACnet queries. Recovery necessitates a device reset or reboot to restore normal functionality. Siemens has released updated firmware versions to address this issue and recommends that users update their devices promptly. This incident underscores the critical importance of securing building automation systems against network-based attacks. As these systems are integral to various critical infrastructure sectors, including commercial facilities, energy, healthcare, and transportation, ensuring their resilience against such vulnerabilities is paramount to maintaining operational continuity and safety.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports