Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 31 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 361372 / 3054 reports
Critical Metabase SQL Injection Zero-Day Vulnerability Discovered
Impact· CRITICAL

Critical Metabase SQL Injection Zero-Day Vulnerability Discovered

In August 2026, Metabase disclosed a critical SQL injection vulnerability affecting versions 1.58 and above of its Cloud platform. This flaw allowed remote attackers to inject SQL statements into the application database, granting them administrator access. Exploiting this access, attackers could alter configurations, steal stored credentials, and access connected databases. Metabase promptly blocked the exploited endpoints and released patches to address the vulnerability. Self-hosted instances with exposed /api/session/reset_password endpoints remained at risk until updated. This incident underscores the persistent threat posed by SQL injection vulnerabilities, which continue to be prevalent despite longstanding awareness. Organizations are reminded of the importance of implementing prepared statements and other secure coding practices to mitigate such risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Gunra Ransomware Exploits Fortinet and Schneider Electric Vulnerabilities
Impact· HIGH

Gunra Ransomware Exploits Fortinet and Schneider Electric Vulnerabilities

In August 2026, cybersecurity agencies from South Korea and the U.S. issued warnings about Gunra ransomware attacks targeting critical infrastructure sectors worldwide. The attackers exploited vulnerabilities in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to gain initial access. Employing a double extortion model, they encrypted data and exfiltrated sensitive information, threatening to publish it unless a ransom was paid within five to seven days. Since its emergence in April 2025, Gunra has listed 51 victims, primarily in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group utilizes phishing campaigns and advanced encryption methods like Salsa20 and ChaCha20 to execute their attacks. This incident underscores the evolving tactics of ransomware groups, highlighting the critical need for organizations to promptly patch known vulnerabilities and implement robust security measures to protect against such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exploiting Windows 11 Plug and Play: A Path to SYSTEM-Level Access
Impact· HIGH

Exploiting Windows 11 Plug and Play: A Path to SYSTEM-Level Access

In August 2026, security researchers Alejandro Hernando and Borja Martinez unveiled a method to exploit Windows Plug and Play (PnP) auto-installation processes, enabling unprivileged users to achieve SYSTEM-level code execution on fully updated Windows 11 systems. By emulating specific USB devices, they triggered the installation of signed vendor software containing vulnerabilities, which they chained to escalate privileges. Notably, this attack vector can be executed both physically and remotely via Remote Desktop Protocol (RDP) when USB redirection is enabled. This discovery underscores the critical need for organizations to scrutinize device installation processes and enforce strict policies on USB device usage and redirection settings. The ability to escalate privileges through such mechanisms highlights potential gaps in endpoint security, emphasizing the importance of comprehensive monitoring and control over peripheral device interactions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OpenAI's GPT-5.6-Cyber: A Leap Forward in AI-Driven Cybersecurity
Impact· HIGH

OpenAI's GPT-5.6-Cyber: A Leap Forward in AI-Driven Cybersecurity

In August 2026, OpenAI introduced GPT-5.6-Cyber, a specialized AI model designed to enhance cybersecurity tasks such as vulnerability research, penetration testing, and incident response. Built upon GPT-5.6 Sol, this model reduces refusals for high-risk, dual-use cyber tasks, achieving a 95% completion rate for complex cybersecurity requests. Notably, GPT-5.6-Cyber identified CVE-2026-15903, a critical out-of-bounds read and write vulnerability in the V8 JavaScript engine, which could allow remote code execution via crafted HTML pages. This vulnerability was promptly patched by Google in mid-July 2026. The release of GPT-5.6-Cyber underscores the growing integration of AI in cybersecurity, providing defenders with advanced tools to proactively identify and mitigate vulnerabilities. This development highlights the importance of balancing AI capabilities with safety measures to prevent potential misuse, as AI models become increasingly adept at both offensive and defensive cyber operations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Python Privilege Escalation Vulnerability (CVE-2026-12003) Discovered
Impact· MEDIUM

Critical Python Privilege Escalation Vulnerability (CVE-2026-12003) Discovered

In June 2026, a critical vulnerability (CVE-2026-12003) was identified in Python versions 3.11.0a3 through 3.15.0b2, affecting Windows installations. This flaw allowed low-privilege users to execute arbitrary code with elevated privileges by exploiting improper handling of the VPATH variable, leading to unauthorized access to alternative library folders. The vulnerability was introduced in December 2021 and publicly disclosed on June 16, 2026. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-12003?utm_source=openai)) This incident underscores the importance of securing software installation paths and the need for organizations to promptly apply security patches to prevent privilege escalation attacks. The Python Software Foundation has released updates to address this issue, and users are advised to upgrade to the latest versions to mitigate potential risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gunra Ransomware Group: A Growing Global Threat
Impact· HIGH

Gunra Ransomware Group: A Growing Global Threat

In August 2026, U.S. and South Korean cyber agencies issued a joint advisory regarding the Gunra ransomware group, a ransomware-as-a-service (RaaS) operation that has been active since April 2025. Gunra employs double-extortion tactics, encrypting victims' data and threatening to publish it unless a ransom is paid. The group has targeted a wide range of sectors, including academia, financial services, government facilities, healthcare, manufacturing, and utilities, across multiple continents. Notably, Gunra has been recruiting ethical hackers and penetration testers as initial access brokers, offering them a share of the ransom profits in exchange for access to enterprise networks. This advisory underscores the evolving nature of ransomware threats, highlighting the increasing sophistication of RaaS operations and their global reach. Organizations are urged to bolster their cybersecurity defenses, particularly by addressing known vulnerabilities in internet-facing devices and implementing robust access controls to mitigate the risk of such attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall SMA1000 Vulnerabilities Exploited by Ransomware Gangs
Impact· CRITICAL

SonicWall SMA1000 Vulnerabilities Exploited by Ransomware Gangs

In July 2026, SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances: CVE-2026-15409, a server-side request forgery flaw, and CVE-2026-15410, a code injection vulnerability. These flaws allowed unauthenticated attackers to execute arbitrary commands, leading to unauthorized access and potential data breaches. ([sonicwall.com](https://www.sonicwall.com/support/notices/%E8%A3%BD%E5%93%81%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E9%87%8D%E8%A6%81%E3%81%AA%E3%81%8A%E7%9F%A5%E3%82%89%E3%81%9B-sma-1000%E3%82%B7%E3%83%AA%E3%83%BC%E3%82%BA%E3%81%AB%E8%A4%87%E6%95%B0%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7/kA1VN000001nv6D0AQ?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups have actively exploited these vulnerabilities, emphasizing the urgency for organizations to apply the available patches promptly. The exploitation of these vulnerabilities underscores a growing trend of attackers targeting remote access solutions to infiltrate corporate networks. Organizations must prioritize securing their remote access infrastructure to prevent such breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
StormEncryptor Ransomware: Exploiting N-central Vulnerability CVE-2026-18577
Impact· HIGH

StormEncryptor Ransomware: Exploiting N-central Vulnerability CVE-2026-18577

In August 2026, the financially motivated threat actor Storm-1175, previously associated with Medusa ransomware, began deploying a new ransomware strain named StormEncryptor. The attacks were likely initiated by exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management tool. Once inside the network, the attackers utilized tools like AnyDesk and SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz to extract credentials. StormEncryptor, written in C++, appends the ".encrypted" extension to files and drops a ransom note titled '!!!README_FIRST!!!.txt' in each directory, demanding contact within three days to prevent data leakage. This incident underscores the evolving tactics of ransomware groups, highlighting the rapid transition from initial access to data exfiltration and encryption. The exploitation of vulnerabilities in widely used management tools like N-central emphasizes the critical need for organizations to promptly apply security patches and monitor for signs of compromise to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Check Point VPN Vulnerability Exploited by Qilin Ransomware Group
Impact· CRITICAL

Critical Check Point VPN Vulnerability Exploited by Qilin Ransomware Group

In May 2026, a critical authentication bypass vulnerability, CVE-2026-50751, was discovered in Check Point's Remote Access VPN and Mobile Access products utilizing the deprecated IKEv1 protocol. This flaw allowed unauthenticated remote attackers to establish VPN connections without valid credentials, effectively granting unauthorized access to internal networks. The Qilin ransomware group exploited this vulnerability, initiating attacks as early as May 7, 2026, targeting several organizations globally. Check Point became aware of these exploits by June 4, 2026, and promptly released patches and mitigation measures to address the issue. The exploitation of CVE-2026-50751 underscores the persistent threat posed by ransomware groups like Qilin, who rapidly adapt to exploit known vulnerabilities. This incident highlights the critical importance of timely vulnerability management and the need for organizations to deprecate outdated protocols to prevent unauthorized access and potential data breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Storm-1175's New StormEncryptor Ransomware Exploits N-central Vulnerability
Impact· HIGH

Storm-1175's New StormEncryptor Ransomware Exploits N-central Vulnerability

In August 2026, Microsoft disclosed that Storm-1175, a financially motivated threat actor linked to China, deployed a new ransomware strain named StormEncryptor. This malware, written in C++, appends the ".encrypted" extension to files and drops a ransom note titled "!!!README_FIRST!!!.txt" in each directory. The group likely exploited CVE-2026-18577, a critical authentication bypass vulnerability in N-able's N-central platform, to gain initial access. This flaw allows unauthenticated attackers to obtain full control over managed endpoints. Storm-1175's rapid exploitation of such vulnerabilities underscores the urgency for organizations to apply patches promptly and monitor their environments for signs of compromise. The emergence of StormEncryptor signifies a shift in Storm-1175's tactics, moving from the previously used Medusa ransomware to a new, custom-developed strain. This evolution highlights the group's adaptability and the increasing sophistication of ransomware campaigns targeting critical infrastructure sectors globally.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Metabase Vulnerability Exposes Sensitive Data
Impact· CRITICAL

Critical Metabase Vulnerability Exposes Sensitive Data

In February 2026, a critical vulnerability was discovered in Metabase, an open-source business intelligence tool. This flaw allowed authenticated users, including those with embedding permissions, to craft specially formatted notification templates to extract sensitive information, such as database connection details and credentials, and send them via outbound email. Metabase promptly addressed the issue by releasing security advisories and urging all self-hosted users to upgrade to the latest versions to mitigate potential exploitation. ([metabase.com](https://www.metabase.com/blog/security-vulnerability?utm_source=openai)) This incident underscores the importance of timely software updates and vigilant monitoring of open-source tools. As organizations increasingly rely on such platforms, ensuring their security becomes paramount to prevent unauthorized data access and potential breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Operation Lunar Peek: A Deep Dive into the Exploitation of PAN-OS Vulnerabilities
Impact· CRITICAL

Operation Lunar Peek: A Deep Dive into the Exploitation of PAN-OS Vulnerabilities

In November 2024, Palo Alto Networks disclosed two critical vulnerabilities in its PAN-OS software: CVE-2024-0012, an authentication bypass flaw, and CVE-2024-9474, a privilege escalation issue. Exploited together in a campaign dubbed 'Operation Lunar Peek,' these vulnerabilities allowed unauthenticated attackers to gain root access to firewall management interfaces. Approximately 2,000 devices were compromised, primarily in the United States and India, leading to unauthorized administrative actions and potential configuration tampering. This incident underscores the escalating sophistication of cyber threats, where attackers rapidly exploit vulnerabilities before patches are widely applied. It highlights the necessity for organizations to adopt proactive vulnerability management strategies, including timely patching and restricting access to critical management interfaces, to mitigate the risk of similar exploits.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports