Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
Decade-Long Vulnerability in Microsoft Secure Boot Uncovered
In July 2026, researchers discovered a critical vulnerability in Microsoft's Secure Boot, a feature designed to protect devices from firmware infections. This flaw, present for 13 of Secure Boot's 14-year existence, allowed attackers to bypass protections using outdated, signed firmware images known as shims. These shims, some dating back to 2013, remained signed by Microsoft despite known defects, enabling unauthorized code execution during system boot and facilitating persistent malware infections. This incident underscores the importance of rigorous certificate management and timely revocation processes. The prolonged exposure highlights potential oversight in Microsoft's security protocols, emphasizing the need for continuous monitoring and updating of security measures to prevent similar vulnerabilities. ([pcgamer.com](https://www.pcgamer.com/software/operating-systems/turns-out-microsofts-secure-boot-was-little-better-than-a-busted-lock-for-about-a-decade/?utm_source=openai))
1 month ago
Kill Chain
Anthropic's Claude Mythos Reveals Critical Flaws in Emerging Encryption Standards
In July 2026, Anthropic's AI model, Claude Mythos Preview, identified significant vulnerabilities in two cryptographic methods: HAWK, a digital signature scheme under NIST's post-quantum cryptography evaluation, and a simplified seven-round version of the Advanced Encryption Standard (AES). The AI discovered a mathematical shortcut in HAWK's lattice structure, reducing its effective key strength by half, and a novel attack method named 'Möbius Bridge' that accelerates theoretical attacks on seven-round AES by 200 to 800 times. While these findings do not impact current software, they highlight potential weaknesses in cryptographic systems under development. ([cyberscoop.com](https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/?utm_source=openai)) This incident underscores the growing role of AI in cryptanalysis, revealing vulnerabilities in encryption methods before their widespread adoption. It emphasizes the need for continuous evaluation of cryptographic standards to ensure resilience against emerging threats, especially as AI capabilities advance.
1 month ago
Kill Chain
Coordinated Cyberattack Disrupts Water Utilities in 30+ Minnesota Communities
In late July 2026, over 30 Minnesota communities experienced disruptions in their water and wastewater utilities due to a coordinated cyberattack targeting operational technology systems. Cities such as Braham and Plymouth reported incidents where water treatment plants and related infrastructure were temporarily taken offline. While the attacks did not compromise water quality, they highlighted vulnerabilities in critical infrastructure. This incident underscores the escalating threat posed by state-sponsored cyber actors targeting U.S. critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) had previously warned of Iranian-affiliated groups, like CyberAv3ngers, exploiting internet-connected operational technology devices, including programmable logic controllers. ([epa.gov](https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian?utm_source=openai))
1 month ago
Kill Chain
Fastjson CVE-2026-16723: Critical RCE Vulnerability Under Active Exploitation
In July 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-16723, was discovered in Alibaba's Fastjson library versions 1.2.68 through 1.2.83. This flaw allows unauthenticated attackers to execute arbitrary code in applications using the vulnerable library, particularly those deployed as Spring Boot executable fat-JARs. The vulnerability is exploitable under Fastjson's default configuration, without the need for enabling AutoType or the presence of specific gadget classes. Active exploitation has been observed, primarily targeting U.S.-based organizations across sectors such as Financial Services, Healthcare, Computing, and Retail. ([imperva.com](https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/?utm_source=openai)) The absence of a patch for Fastjson 1.x, which is no longer actively maintained, underscores the urgency for organizations to mitigate this risk. The exploitation of this vulnerability highlights the critical need for timely software updates and the adoption of secure coding practices to prevent similar attacks in the future.
1 month ago
Kill Chain
MCBS Data Breach 2025: A Wake-Up Call for Healthcare Cybersecurity
In September 2025, Medical Computer Business Services (MCBS), a healthcare billing firm based in Augusta, Georgia, experienced a significant data breach. Unauthorized access to their network occurred between September 22 and 26, 2025, leading to the exposure of sensitive information belonging to 1,261,464 individuals. The compromised data included names, addresses, Social Security numbers, dates of birth, health insurance details, and medical histories. The PEAR ransomware group claimed responsibility for the attack, alleging the exfiltration of 3.3 terabytes of data from MCBS systems. This incident underscores the escalating threat posed by ransomware groups targeting the healthcare sector. The breach highlights the critical need for robust cybersecurity measures to protect sensitive patient information and the importance of timely detection and response to such intrusions.
1 month ago
Kill Chain
Decades-Old BMC Vulnerability Exposes Over 24,000 Servers
In July 2026, researchers identified over 24,000 internet-exposed servers leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interfaces. This flaw, CVE-2013-4786, allows attackers to obtain password hashes via the IPMI 2.0 protocol's RAKP authentication, enabling offline password cracking. Exploiting this vulnerability grants attackers control over physical servers, allowing them to alter configurations, apply malicious firmware updates, and compromise systems at a level not monitored by standard security solutions. The United States accounted for 39% of the vulnerable servers, with many being Supermicro systems protected by default credentials susceptible to offline cracking. The resurgence of this decades-old vulnerability underscores the critical need for organizations to reassess and secure their remote management interfaces. As attackers increasingly target such weaknesses, it is imperative to implement robust security measures, including rotating default BMC passwords, isolating management networks, and disabling legacy IPMI authentication to mitigate potential breaches.
1 month ago
Kill Chain
Understanding the 'Certighost' Vulnerability in Microsoft AD CS
In July 2026, Microsoft addressed a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121 and nicknamed 'Certighost'. This flaw allowed low-privileged domain users to impersonate domain controllers, potentially leading to full Active Directory domain compromise. The vulnerability exploited a defective trust boundary within the certificate-based client authentication process, enabling attackers to manipulate certificate requests and gain elevated privileges. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates?utm_source=openai)) The release of a proof-of-concept exploit by security researchers has heightened the urgency for organizations to apply the patch. This incident underscores the importance of promptly addressing vulnerabilities in critical infrastructure components to prevent potential domain-wide security breaches. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/07/27/certighost-cve-2026-54121-poc-exploit-released/?utm_source=openai))
1 month ago
Kill Chain
Protecting Against Session Hijacking: Beyond Password Resets
In July 2026, cybersecurity experts highlighted a significant shift in attacker tactics from traditional password theft to session and token hijacking. This method allows adversaries to bypass multi-factor authentication (MFA) by exploiting authenticated sessions, enabling them to impersonate legitimate users and maintain persistent access within trusted environments. Techniques such as device-code phishing and stealing browser cookies have become prevalent, rendering conventional defenses like password resets and MFA prompts less effective. This evolution underscores the urgent need for organizations to move beyond securing initial logins and focus on protecting authenticated sessions throughout their lifecycle. Continuous monitoring of post-authentication behavior, implementing phishing-resistant authentication methods, and promptly revoking compromised tokens are critical measures to mitigate these advanced threats.
1 month ago
Kill Chain
Operation Cronos: A Landmark Takedown of LockBit Ransomware Group
In February 2024, an international law enforcement coalition led by the UK's National Crime Agency (NCA) and the FBI executed Operation Cronos, effectively dismantling the LockBit ransomware group. This operation involved seizing LockBit's infrastructure, including their dark web leak site and administrative panels, arresting key members in Poland and Ukraine, and freezing over 200 cryptocurrency accounts linked to the group. LockBit, active since 2019, was responsible for thousands of ransomware attacks worldwide, extorting over $120 million from victims across various sectors. The takedown significantly disrupted their operations and provided decryption keys to assist victims in data recovery. ([weforum.org](https://www.weforum.org/stories/2024/02/lockbit-ransomware-operation-cronos-cybercrime/?utm_source=openai)) The success of Operation Cronos underscores the effectiveness of coordinated international efforts in combating cybercrime. However, the rapid reemergence of LockBit highlights the resilience of such groups and the ongoing need for vigilance and adaptive cybersecurity strategies to address evolving threats. ([techcrunch.com](https://techcrunch.com/2024/02/26/lockbit-ransomware-takedown-now-what/?utm_source=openai))
1 month ago
Kill Chain
Arista VeloCloud Orchestrator Vulnerability (CVE-2026-16812) Exploited in the Wild
In July 2026, a critical command injection vulnerability (CVE-2026-16812) was discovered in on-premises versions of Arista VeloCloud Orchestrator (VCO). This flaw allows unauthenticated remote attackers to execute arbitrary commands on the VCO host, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. Arista has confirmed active exploitation of this vulnerability in the wild and has released patches to address the issue. Organizations using affected versions are urged to upgrade immediately to mitigate the risk. ([arista.com](https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144?utm_source=openai)) The exploitation of CVE-2026-16812 underscores the increasing targeting of network infrastructure components by threat actors. As SD-WAN solutions like VeloCloud become integral to enterprise networks, ensuring their security is paramount. This incident highlights the necessity for organizations to maintain up-to-date systems and implement robust monitoring to detect and respond to such vulnerabilities promptly.
1 month ago
Kill Chain
AI-Assisted Discovery of CVE-2026-53264: A Linux Kernel Privilege Escalation Vulnerability
In July 2026, STAR Labs disclosed a critical vulnerability in the Linux kernel, identified as CVE-2026-53264, which allows local users to escalate privileges to root. This use-after-free race condition exists in the network traffic-control subsystem and was exploited on CentOS Stream 9. Researcher Lee Jia Jie utilized artificial intelligence to expedite the discovery and development of the exploit. The flaw requires specific kernel configurations and unprivileged user namespaces to be exploitable. The incident underscores the growing role of AI in cybersecurity, both for defense and offense. It highlights the necessity for organizations to promptly apply patches and monitor for emerging threats, especially as exploit code becomes publicly available.
1 month ago
Kill Chain
Critical TeamCity Vulnerability (CVE-2026-63077) Exposes Servers to Unauthenticated Remote Code Execution
In July 2026, JetBrains identified a critical security vulnerability (CVE-2026-63077) in all versions of TeamCity On-Premises. This flaw allows unauthenticated attackers with HTTP(S) access to bypass authentication and execute arbitrary operating system commands with the privileges of the TeamCity server process. The vulnerability stems from insecure deserialization in the agent polling protocol, enabling remote code execution without credentials or user interaction. JetBrains released patches in versions 2025.11.7 and 2026.1.3 to address this issue. ([blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/?utm_source=openai)) The incident underscores the importance of promptly applying security updates to prevent potential exploitation. Organizations using TeamCity On-Premises should upgrade to the patched versions or apply the provided security patch plugin to mitigate the risk of unauthorized access and potential compromise of build environments. ([blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/?utm_source=openai))
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports