Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 29 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 337348 / 3054 reports
Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities
Impact· HIGH

Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities

In August 2026, Microsoft released patches for 398 security vulnerabilities across its Windows operating systems and supported software. Among these, CVE-2026-68820, a privilege escalation flaw in the afd.sys component, was actively exploited. This vulnerability allows attackers to elevate privileges by exploiting race conditions in the Windows socket driver. Additionally, two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the patch release, highlighting the critical need for timely updates. The increasing volume of vulnerabilities, attributed to AI-driven discovery methods, underscores the necessity for organizations to enhance their patch management processes. The active exploitation of CVE-2026-68820 emphasizes the urgency of applying these patches promptly to mitigate potential security breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity

In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. ([shellcodex.com](https://shellcodex.com/ransomware/group/gunra?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22572/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild
Impact· HIGH

Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild

In August 2026, Cisco disclosed a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw allows unauthenticated remote attackers to trigger a denial-of-service (DoS) condition by sending crafted HTTP requests to the Remote Access SSL VPN service on affected devices. Exploitation results in device reloads, causing service disruptions. The vulnerability affects devices with specific configurations, including IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access2. Cisco has released software updates to address this issue, as no workarounds are available. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches to network infrastructure devices. Delayed responses to such vulnerabilities can lead to significant operational disruptions and potential security breaches. This incident highlights the importance of maintaining up-to-date systems and monitoring for emerging threats to ensure network resilience.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass
Impact· HIGH

ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass

In August 2026, security researcher Chaotic Eclipse released a proof-of-concept (PoC) for a new Microsoft zero-day vulnerability named ShieldBreak. This vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656, also known as RoguePlanet. RoguePlanet is a race condition that, if exploited, allows an attacker to spawn a shell with SYSTEM-level privileges, enabling the execution of arbitrary code or unauthorized actions. Despite Microsoft's release of a patch in July 2026 to address RoguePlanet, the ShieldBreak PoC indicates that the patch is ineffective, as it can be fully bypassed, maintaining a 100% success rate in tests on Windows 11 25H2 and Windows Server 2025. The release of ShieldBreak underscores the persistent challenges in effectively patching critical vulnerabilities. It highlights the need for organizations to adopt comprehensive security measures beyond relying solely on vendor patches. This incident also emphasizes the importance of continuous monitoring and rapid response strategies to mitigate potential exploits that can arise even after patches are applied.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231
Impact· CRITICAL

Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231

In August 2026, SAP released patches to address a critical vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter. This flaw, rated 10.0 on the CVSS scale, allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation. Successful exploitation could lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the application. This incident underscores the ongoing risks associated with insufficient authorization checks and input validation in enterprise applications. Organizations must prioritize timely patch management and implement robust security measures to mitigate such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310
Impact· CRITICAL

Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310

In early August 2026, threat actors began exploiting CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, allowing unauthenticated remote code execution. Despite Broadcom's release of patches in late July, attackers leveraged this flaw to deploy persistent access mechanisms, notably using reverse_ssh to maintain control over compromised systems. The campaign affected 361 unique IP addresses across 47 countries, with significant concentrations in Germany, the U.S., Turkey, Iran, and France. This incident underscores the rapid weaponization of disclosed vulnerabilities by advanced persistent threat actors, emphasizing the necessity for organizations to promptly apply security patches and monitor for unauthorized outbound connections indicative of compromise.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Enterprise Defenses: Strong Perimeter, Weak Interior
Impact· MEDIUM

Enterprise Defenses: Strong Perimeter, Weak Interior

In the first half of 2026, Picus Labs conducted over 338 million attack simulations across client production environments, revealing a significant disparity in defense effectiveness. While perimeter defenses showed improvement, blocking approximately 69% of attacks, internal defenses were notably weaker, with a post-compromise prevention rate of only 37%. This indicates that once attackers breach the perimeter, they face minimal resistance, especially during reconnaissance and credential theft phases. This trend underscores the urgent need for organizations to bolster internal security measures. As attackers increasingly employ stealthy techniques to evade detection, focusing solely on perimeter defenses is insufficient. Enhancing internal monitoring and response capabilities is crucial to mitigate the risks associated with these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Three Known Exploited Vulnerabilities to Catalog

On August 11, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities are: CVE-2026-20349 affecting Cisco Secure Firewall ASA and FTD, CVE-2026-68820 in Microsoft Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 in Metabase. These vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies to federal agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and address these vulnerabilities promptly.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844
Impact· HIGH

Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844

In August 2026, a critical vulnerability (CVE-2026-18844) was identified in the Pulsetto Vagus Nerve Stimulator, a device widely used for non-invasive wellness applications. The flaw allows unauthenticated commands to be sent over its Bluetooth Low Energy (BLE) interface, enabling attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not responded to mitigation requests, leaving users exposed to potential exploitation. This incident underscores the growing security risks associated with IoT medical devices, emphasizing the need for robust security measures and prompt vendor responses to vulnerabilities to protect patient safety and device integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical API Flaw in Leading AI Models Exposes Sensitive Data
Impact· MEDIUM

Critical API Flaw in Leading AI Models Exposes Sensitive Data

In August 2026, researchers identified a vulnerability in the API implementations of OpenAI, Anthropic, and Google, allowing weaker AI models to decode encrypted reasoning traces from stronger models. This flaw enabled the extraction of sensitive information, including API keys and passwords, from session logs. The issue stemmed from the portability of encrypted reasoning objects across sessions and models, which could be exploited to reveal hidden content. The affected companies have since implemented mitigations to address this vulnerability. This incident underscores the critical importance of securing AI model APIs and the potential risks associated with encrypted reasoning objects. It highlights the need for developers to sanitize shared traces and avoid exposing raw API transcripts, even when visible text appears safe.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed
Impact· CRITICAL

Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed

In August 2026, a critical unauthenticated SQL injection vulnerability (CVE-2026-72898) was discovered in Metabase's password reset functionality. This flaw allows remote attackers to execute arbitrary SQL commands against the Metabase application database without authentication, potentially leading to full administrative access and data exfiltration. Metabase has confirmed active exploitation of this vulnerability in the wild, emphasizing the urgency for immediate remediation. The rapid exploitation of CVE-2026-72898 underscores a growing trend of attackers swiftly leveraging newly disclosed vulnerabilities. Organizations must prioritize timely patching and adopt proactive security measures to mitigate risks associated with such critical flaws.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Context Bombing: Turning Prompt Injections into Defensive Weapons
Impact· LOW

Context Bombing: Turning Prompt Injections into Defensive Weapons

In July 2026, cybersecurity researchers at Tracebit introduced a defensive technique called 'context bombing' to counteract AI-driven cyberattacks. This method involves embedding specific prompt injections within sensitive data stored on platforms like Amazon Web Services (AWS). When AI hacking agents encounter these prompts, they are directed to perform actions that violate their built-in safety protocols, leading to their immediate shutdown. This proactive approach effectively neutralizes potential threats before they can cause harm. ([arstechnica.com](https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too/?utm_source=openai)) The significance of this development lies in its innovative use of offensive tactics for defense. By leveraging prompt injections—a tool traditionally used by attackers—defenders can now preemptively disrupt AI-driven attacks. This strategy highlights a shift towards more adaptive and proactive cybersecurity measures in response to the evolving landscape of AI threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports