Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 36 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 421432 / 3054 reports
Pass-ta-key Attacks: A New Threat to Passwordless Authentication
Impact· HIGH

Pass-ta-key Attacks: A New Threat to Passwordless Authentication

In August 2026, security researchers from Palo Alto Networks' Unit 42 identified three novel attacks, collectively termed "Pass-ta-key," targeting Google Password Manager's passkey synchronization on Windows devices equipped with Trusted Platform Modules (TPMs). These attacks enable malware on already-compromised systems to impersonate trusted devices, register malicious user-verification keys, and extract master keys used to encrypt all synced passkeys. Notably, the "Golden Pass-ta-key" technique allows attackers to access the security domain secret, potentially compromising all passkeys stored in the victim's Google Password Manager. This incident underscores the evolving threats to passwordless authentication systems and highlights the necessity for robust validation mechanisms and secure handling of cryptographic materials. Organizations must reassess their reliance on passkey synchronization and implement additional safeguards to mitigate such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phishing Service Exploits RingCentral to Compromise Microsoft 365 Accounts
Impact· HIGH

Phishing Service Exploits RingCentral to Compromise Microsoft 365 Accounts

In August 2026, the 'Greatness' phishing-as-a-service platform expanded its operations to include adversary-in-the-middle attacks and device-code phishing, specifically targeting Microsoft 365 accounts. Cybercriminals leveraged this platform to impersonate RingCentral, a widely-used communications service, by sending fraudulent emails that appeared to originate from service@ringcentral.com. These emails, often containing fake voicemail and performance-review notifications, successfully bypassed email security filters due to RingCentral's whitelisted status. Upon clicking embedded links, victims were redirected to phishing sites designed to capture authentication tokens, enabling attackers to access and exfiltrate data from Outlook, Teams, SharePoint, and OneDrive, with unauthorized access persisting for over two weeks in some instances. This incident underscores a significant evolution in phishing tactics, highlighting the increasing sophistication of phishing-as-a-service platforms and their ability to exploit trusted services to bypass security measures. The use of adversary-in-the-middle techniques to capture multi-factor authentication tokens represents a notable advancement in cybercriminal methodologies, emphasizing the need for organizations to continually adapt their security protocols to counteract these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cybercriminals Exploit Cloud Platforms for Phishing in 2026
Impact· MEDIUM

Cybercriminals Exploit Cloud Platforms for Phishing in 2026

In 2026, threat actors increasingly exploited legitimate cloud services to host phishing sites, leveraging platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This approach allowed attackers to bypass traditional security measures, as phishing pages hosted on reputable domains appeared trustworthy to victims. The use of these platforms enabled the rapid deployment of multi-stage adversary-in-the-middle (AitM) attacks, effectively capturing multi-factor authentication (MFA) sessions and compromising user accounts. This trend underscores a significant shift in cybercriminal tactics, highlighting the need for enhanced detection mechanisms that go beyond domain reputation. The widespread abuse of trusted cloud services for phishing campaigns necessitates a reevaluation of current security strategies to effectively counteract these sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Greatness PhaaS Adds Device Code Phishing to Bypass MFA
Impact· HIGH

Greatness PhaaS Adds Device Code Phishing to Bypass MFA

In August 2026, the 'Greatness' phishing-as-a-service (PhaaS) platform introduced device code phishing capabilities, enabling attackers to bypass multi-factor authentication (MFA) and gain unauthorized access to Microsoft 365 accounts. This method exploits the OAuth 2.0 Device Authorization Grant, tricking users into authenticating a malicious device by entering a provided code on a legitimate Microsoft page. Once the code is entered, attackers obtain access and refresh tokens, allowing persistent access to services like Outlook, Teams, and OneDrive without needing user credentials. This development signifies a significant evolution in phishing tactics, as it leverages legitimate authentication flows to circumvent traditional security measures. The commoditization of such advanced techniques through PhaaS platforms like 'Greatness' lowers the barrier for cybercriminals, increasing the prevalence and sophistication of phishing attacks targeting organizations and individuals alike.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Unveiling the Smoke#Screen RMM Takeover: A New Threat Actor Playbook
Impact· CRITICAL

Unveiling the Smoke#Screen RMM Takeover: A New Threat Actor Playbook

In August 2026, the Smoke#Screen campaign emerged, leveraging the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool to gain persistent remote access to compromised networks. Attackers employed diverse social engineering lures, including fake Zoom and Adobe updates, business document requests, and system maintenance tools, to trick victims into executing malicious files. This resulted in the silent installation of ScreenConnect agents that connected to attacker-controlled relay servers, providing unauthorized access to both Windows and macOS systems. The campaign's sophistication was evident in its use of rotating payloads and varied lures, making detection challenging. This incident underscores a growing trend where threat actors exploit legitimate RMM tools to bypass security controls and maintain persistence. The evolving tactics highlight the need for organizations to enhance their defenses against such sophisticated social engineering attacks and to monitor for unauthorized installations of RMM software.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Impact· HIGH

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

In August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity vulnerability in N-able N-central, identified as CVE-2026-18577, to its Known Exploited Vulnerabilities catalog. This flaw, resulting from incomplete patching of a previous issue, allows authentication bypass and account takeover, enabling remote attackers to gain administrative access to N-central servers. Exploitation of this vulnerability has been observed, with attackers leveraging the built-in Take Control feature to pivot into managed endpoints and establish persistence mechanisms. Indicators of compromise include the presence of a 'svchost.exe' file in user documents folders and a registered service named 'Cloudflared,' a legitimate tunneling utility often misused for covert connections. Additionally, inbound connections from specific IP addresses associated with VPN services have been noted. N-able has acknowledged that a limited number of customers were affected and has released a patch in version 2026.3 HF1 to address the issue. This incident underscores the persistent targeting of remote monitoring and management (RMM) platforms by threat actors to facilitate unauthorized access and maintain footholds within organizational networks. The exploitation of CVE-2026-18577 highlights the critical need for organizations to promptly apply security patches and monitor for signs of compromise to mitigate potential threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical cPanel Vulnerability CVE-2026-58048: Immediate Action Required
Impact· CRITICAL

Critical cPanel Vulnerability CVE-2026-58048: Immediate Action Required

In August 2026, cPanel addressed a critical vulnerability (CVE-2026-58048) that allowed authenticated users to execute SQL commands with root privileges, potentially leading to full server compromise. This flaw affected all supported versions of cPanel & WHM, as well as WP Squared. Exploitation required a valid cPanel account with access to MySQL/MariaDB features. The issue stemmed from improper handling during the database renaming process, enabling users to bypass standard privilege restrictions. cPanel released patches to mitigate this vulnerability and provided guidance for administrators unable to update immediately. This incident underscores the importance of timely patch management and the potential risks associated with privilege escalation vulnerabilities in widely used web hosting management software. Organizations should prioritize updating their systems and reviewing access controls to prevent unauthorized administrative actions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds CVE-2026-18577 to Known Exploited Vulnerabilities Catalog
Impact· CRITICAL

CISA Adds CVE-2026-18577 to Known Exploited Vulnerabilities Catalog

On August 3, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability allows attackers to gain unauthorized access to systems by exploiting an alternate path or channel, posing significant risks to federal enterprises. CISA's inclusion of this CVE underscores the critical nature of the flaw and the necessity for immediate remediation to prevent potential breaches. The addition of CVE-2026-18577 to the KEV Catalog highlights a growing trend of authentication bypass vulnerabilities being actively exploited. Organizations are urged to prioritize patching and implementing robust access controls to mitigate the risks associated with such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Botnet Exploits Command Injection Vulnerabilities in Diagnostic Tools
Impact· HIGH

Botnet Exploits Command Injection Vulnerabilities in Diagnostic Tools

In August 2026, cybersecurity researchers identified a botnet actively scanning for vulnerabilities in diagnostic tools across various web interfaces. The botnet targeted specific URLs associated with diagnostic functions, such as "/apply.cgi" and "/cgi-bin/diagnostic.cgi," exploiting known command injection vulnerabilities like CVE-2024-12856 and CVE-2013-7179. These vulnerabilities allowed attackers to execute arbitrary commands on affected systems, potentially leading to unauthorized access and data exfiltration. The exploitation of diagnostic tools underscores the critical need for secure coding practices and regular vulnerability assessments to prevent such attacks. This incident highlights a growing trend where botnets leverage command injection flaws in diagnostic utilities to compromise systems. Organizations must prioritize the security of diagnostic interfaces, ensuring they are not exposed to unauthorized access and are regularly updated to mitigate known vulnerabilities. Implementing robust input validation and employing secure coding practices are essential steps in defending against such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Keyv npm Worm Supply Chain Attack: A 2026 Case Study
Impact· HIGH

Keyv npm Worm Supply Chain Attack: A 2026 Case Study

In August 2026, a credential-stealing worm was discovered in the npm package 'keyv@6.0.0', rapidly spreading to hundreds of packages across multiple organizations. The malware utilized a 'preinstall' script to execute within developer and continuous integration environments, harvesting sensitive credentials such as repository access tokens, cloud service keys, and private keys. This allowed the attacker to further propagate the infection by publishing compromised versions of additional packages. The Keyv repository also contained malicious hooks in Claude Code and Visual Studio Code configurations, enabling payload execution when users trusted the workspace or permitted project configurations. This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The self-propagating nature of the worm highlights the critical need for robust security measures in package management and development environments. Organizations must implement stringent controls over dependency management, regularly audit third-party packages, and ensure that development tools are configured to prevent unauthorized script execution during package installation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SMOKE#SCREEN Campaign: Exploiting Trusted Platforms for Persistent Remote Access
Impact· CRITICAL

SMOKE#SCREEN Campaign: Exploiting Trusted Platforms for Persistent Remote Access

In August 2026, cybersecurity researchers identified an active campaign, dubbed SMOKE#SCREEN, leveraging social engineering tactics themed around Adobe and Zoom software updates to deploy Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect. The attackers utilized VBScript droppers, batch file loaders, and .NET executables, directing victims to a WsgiDAV-based staging server. Successful breaches resulted in persistent remote access to compromised systems via ScreenConnect agents connecting to attacker-controlled relay servers. The campaign's initial access vector was spear-phishing emails containing obfuscated VBScript droppers that performed environment checks before executing malicious payloads. Notably, the attackers employed trusted hosting services like Dropbox and Cloudflare to evade detection, highlighting the increasing abuse of legitimate RMM tools to bypass security controls and blend into enterprise environments. This incident underscores a growing trend where threat actors exploit legitimate RMM tools to establish persistent access within enterprise networks. The use of trusted platforms for payload delivery complicates detection and mitigation efforts, emphasizing the need for organizations to enhance monitoring of RMM tool usage and implement stringent controls over software update processes to prevent similar attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NOVA's AI-Driven Vulnerability Discovery: A Cybersecurity Game-Changer
Impact· MEDIUM

NOVA's AI-Driven Vulnerability Discovery: A Cybersecurity Game-Changer

In August 2026, Palo Alto Networks' Unit 42 unveiled the Network and Open-Source Vulnerability Analyzer (NOVA), an autonomous system leveraging frontier AI models to discover vulnerabilities in open-source software. Over two months, NOVA analyzed 3,915 projects, uncovering 14,090 vulnerabilities, 99.4% previously unreported, with 40% classified as high or critical severity. This rapid discovery underscores the transformative impact of AI on cybersecurity, significantly reducing the time between vulnerability identification and potential exploitation. The accelerated pace of vulnerability discovery necessitates immediate adaptation in cybersecurity strategies. Organizations must implement advanced virtual patching, enhance software supply chain security, and adopt zero-trust architectures to mitigate risks in this evolving threat landscape.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports