Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
In July 2026, Microsoft disclosed CVE-2026-58644, a critical deserialization vulnerability in SharePoint Server, allowing unauthenticated remote code execution. This flaw affects SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Exploitation requires an attacker to send a specially crafted network request, leading to potential full server compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by July 19, 2026. The inclusion of CVE-2026-58644 in CISA's catalog underscores the urgency of addressing this vulnerability, as it has been actively exploited in the wild. Organizations using affected SharePoint versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.
2 months ago
Kill Chain
CISA Adds Three Exploited Vulnerabilities to KEV Catalog
On July 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and remediation efforts. With the increasing frequency of such exploits, it is imperative for entities to adopt risk-based vulnerability management practices to safeguard their systems against potential breaches.
2 months ago
Kill Chain
ACR Stealer 2026: Unveiling the ClickFix Intrusion Chains
Between late April and mid-June 2026, Microsoft Defender Experts observed a surge in ACR Stealer activity targeting enterprise environments. Attackers employed 'ClickFix' social engineering tactics to deceive users into executing malicious commands, leading to the theft of browser credentials, authentication tokens, and sensitive documents. The campaigns utilized two primary intrusion chains: one leveraging WebDAV for payload delivery with Python-based loaders and blockchain-backed command-and-control mechanisms, and another employing MSHTA-initiated PowerShell scripts with steganographic techniques for in-memory payload execution. These sophisticated methods enabled attackers to evade detection and maintain persistence within compromised systems. The significance of this incident lies in the advanced techniques used to bypass traditional security measures, highlighting the evolving nature of cyber threats. Organizations must remain vigilant against such deceptive tactics and enhance their security protocols to detect and mitigate similar attacks effectively.
2 months ago
Kill Chain
AI-Driven Cyberattacks: Key Insights from Unit 42's 2026 Report
In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. The 2026 Global Incident Response Report highlights that adversaries are leveraging AI to accelerate attack timelines, with data exfiltration occurring up to four times faster than in previous years. Identity weaknesses were exploited in nearly 90% of investigations, and 87% of intrusions involved multiple attack surfaces, including endpoints, networks, cloud services, SaaS platforms, and identity systems. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai)) This trend underscores the urgent need for organizations to enhance their cybersecurity posture by addressing identity vulnerabilities, improving visibility across attack surfaces, and implementing AI-driven defense mechanisms to counteract the speed and complexity of modern cyber threats.
2 months ago
Kill Chain
Indictment of Russian Nationals for Bulletproof Hosting Services Facilitating Cyberattacks
In July 2026, U.S. federal prosecutors unsealed an indictment against three Russian nationals—Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova, and Kirill Andreevich Zatolokin—accusing them of operating bulletproof hosting services through their companies, Media Land and ML.Cloud. These services allegedly facilitated cyberattacks on critical infrastructure across 21 U.S. states and several countries, resulting in over $62 million in damages. The indictment details how the accused provided infrastructure and technical support to cybercriminals, enabling malware distribution, ransomware attacks, and other illicit activities. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai)) This case underscores the persistent threat posed by bulletproof hosting providers, which offer cybercriminals resilient infrastructure to conduct attacks with impunity. The indictment highlights the necessity for international cooperation in dismantling such networks and protecting critical infrastructure from cyber threats. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai))
2 months ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
Between August 31 and September 3, 2024, the cybercriminal group Scattered Spider executed a sophisticated cyberattack on Transport for London (TfL). Utilizing social engineering techniques, they infiltrated TfL's network, leading to significant disruptions in technical services, including the Oyster payment system and third-party APIs. The attack necessitated a mass password reset for all 28,000 TfL employees and resulted in financial losses estimated at £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups employing advanced social engineering tactics to target critical infrastructure. Organizations must enhance their cybersecurity measures, particularly in employee training and network security protocols, to mitigate such risks.
2 months ago
Kill Chain
Spirals Ransomware Attack on South Asian IT Firm in June 2026
In June 2026, an IT services firm in South Asia fell victim to a rapid and sophisticated ransomware attack orchestrated by a previously unknown group deploying the 'Spirals' ransomware. The attackers gained initial access through a publicly exposed Internet Information Services (IIS) server, where they uploaded an ASP.NET web shell. Within a three-hour window, they established persistent access, disabled security software, extracted credentials, and moved laterally across the network. Less than 24 hours after the initial breach, the Spirals ransomware was deployed, encrypting files and exfiltrating sensitive data. The attackers threatened to publish the stolen data within six days unless a ransom was paid. This incident underscores the evolving threat landscape, where cybercriminals are executing attacks with unprecedented speed and efficiency. Organizations must reassess their security postures, particularly concerning publicly accessible services and rapid response capabilities, to mitigate such swift and damaging intrusions.
2 months ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
In August 2024, Transport for London (TfL) suffered a significant cyberattack orchestrated by the Scattered Spider hacking group. The breach disrupted internal systems and online services, including Dial-a-Ride, concessionary travel cards, digital payments, and contactless ticketing. Approximately 148 systems were rendered inoperable, and all 27,000 TfL employees were required to reset their passwords in person. The attack resulted in £29 million in losses and recovery costs, with potential economic damages estimated at up to £56 billion had the transport network been fully compromised. This incident underscores the escalating threat posed by cybercriminal groups like Scattered Spider, known for their sophisticated social engineering tactics and targeting of critical infrastructure. The successful prosecution of the perpetrators highlights the importance of early cooperation between organizations and law enforcement in mitigating cyber threats and bringing offenders to justice.
2 months ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
2 months ago
Kill Chain
Critical Vulnerability in Claude Chrome Extension Exposes User Data
In July 2026, a critical vulnerability was discovered in Anthropic's Claude for Chrome browser extension. This flaw allowed malicious extensions to simulate user interactions, triggering predefined AI actions without user consent. Exploiting this, attackers could access connected services such as Gmail, Google Docs, Google Calendar, and Salesforce, leading to unauthorized data access and potential data exfiltration. The vulnerability stemmed from the extension's failure to verify the origin of click events, accepting synthetic events generated by other extensions as legitimate user actions. This incident underscores the growing risks associated with browser extensions and their integration with AI-powered services. As organizations increasingly adopt such tools to enhance productivity, ensuring robust security measures and thorough validation of user interactions becomes imperative to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
Outdated UEFI Bootloaders Pose Security Risks
In July 2026, researchers identified 11 outdated UEFI shim bootloaders, all signed by Microsoft, that remained trusted components within the Secure Boot framework. These bootloaders, versions 0.9 and earlier, lacked modern security protections and could be exploited by attackers to bypass Secure Boot, allowing the execution of malicious code during the boot process and establishing persistent access below the operating system level. Microsoft addressed the issue by revoking these vulnerable bootloaders in June 2026 through Secure Boot revocation updates. However, systems that have not applied these updates remain susceptible to boot-level attacks, as the revoked shims continue to be trusted on unpatched machines. This incident underscores the critical importance of timely firmware updates and the need for organizations to maintain vigilance over the security of their boot processes to prevent potential exploits.
2 months ago
Kill Chain
Identity Attacks Surpass Exploits as Leading Ransomware Cause in 2026
In 2026, identity-based attacks emerged as the leading cause of ransomware incidents, surpassing traditional vulnerability exploits. According to Sophos' State of Ransomware 2026 report, malicious emails (26%) and phishing (24%) accounted for half of all ransomware attack vectors, while exploited vulnerabilities declined to 18%. Notably, 67% of victims identified the ransomware attack as their most significant identity-related breach of the year. Despite the deployment of multifactor authentication (MFA) in 97% of credential-based attacks, these measures failed to prevent compromises, highlighting gaps in implementation and the evolving sophistication of attackers. This shift underscores the critical need for organizations to enhance their identity security frameworks. The prevalence of identity-driven attacks necessitates a reevaluation of current security protocols, emphasizing advanced email filtering, comprehensive MFA deployment, and regular phishing awareness training to mitigate the rising threat landscape.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports