Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
How Storm-3032 and Storm-3121 Are Exploiting BYOD Policies to Breach Corporate Microsoft 365
Since May 2026, Microsoft researchers have tracked threat actors Storm-3032 and Storm-3121 conducting sophisticated initial access campaigns targeting corporate executives through their personal devices. The attackers use voice calls and text messages impersonating IT helpdesks to trick employees into updating authentication credentials via phishing links. Once access is gained, the threat actors exploit Microsoft Graph API to enumerate corporate resources and exfiltrate sensitive data from SharePoint, OneDrive, and Exchange before potentially selling access to extortion groups like ShinyHunters. This campaign highlights the growing trend of attackers bypassing corporate security controls by targeting the weakest link - personal devices with minimal security protections. As organizations increasingly adopt BYOD policies and hybrid work models, identity-based attacks exploiting trusted communication channels represent a critical evolution in threat actor tactics.
1 week ago
Kill Chain
How Cisco FMC Vulnerabilities Enabled Qilin Ransomware Deployment
In September 2026, Cisco revealed that three distinct threat clusters exploited critical vulnerabilities CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) systems. The attacks involved state-sponsored groups and ransomware operators who leveraged these flaws to deploy web shells, steal credentials, conduct reconnaissance, and ultimately deploy Qilin ransomware. The exploitation allowed attackers to bypass authentication, gain root access, and perform living-off-the-land techniques using legitimate FMC tools to avoid detection while moving laterally through victim networks. This incident highlights the growing trend of threat actors targeting network security infrastructure as initial access vectors, demonstrating how critical security appliances themselves become single points of failure when unpatched vulnerabilities exist.
1 week ago
Kill Chain
CISA Adds Four Critical Infrastructure Vulnerabilities to KEV Catalog
In September 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities affect widely deployed enterprise infrastructure including Fortinet security appliances (CVE-2025-25249 heap-based buffer overflow), Citrix NetScaler (CVE-2026-19490 authentication bypass), Google Chromium V8 engine (CVE-2026-87491 out-of-bounds write), and Cisco Firewall Management Center (CVE-2026-20079 authentication bypass). These vulnerabilities pose significant risks as they target critical network security infrastructure and web browsers used across federal and private sector environments. This incident highlights the ongoing threat landscape where attackers systematically target network security appliances and widely-used software components to establish persistent access and bypass security controls, reflecting the continued evolution of threat actor tactics toward infrastructure-level compromises.
1 week ago
Kill Chain
Critical MikroTik RouterOS Vulnerabilities Added to CISA KEV Catalog: Immediate Action Required
CISA added two critical MikroTik RouterOS vulnerabilities (CVE-2026-67277 and CVE-2026-86060) to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026 following evidence of active exploitation. CVE-2026-67277 involves missing authentication for critical functions, while CVE-2026-86060 relates to improper neutralization of argument delimiters in commands. These vulnerabilities affect network infrastructure devices and allow attackers to gain total control of compromised systems, posing significant risks to federal and enterprise networks. This addition reinforces the critical importance of rapid vulnerability remediation as network infrastructure attacks continue to surge, with threat actors increasingly targeting edge devices and routers to establish persistent footholds for lateral movement and data exfiltration campaigns.
1 week ago
Kill Chain
Storm-3075 and AI-Themed Phishing: The New Frontier of Social Engineering
Throughout 2026, cybercriminals increasingly exploited AI brand trust through sophisticated phishing campaigns targeting popular platforms like ChatGPT, Microsoft Copilot, DeepSeek, and Claude. Microsoft Threat Intelligence documented massive campaigns including a ChatGPT-themed operation sending 100,000 phishing emails daily to harvest credit card data, Claude-themed credential theft using adversary-in-the-middle techniques, and malvertising campaigns distributing Vidar stealer through fake AI Windows plugins. Storm-3075, an initial access broker, commoditized AI-themed malvertising across criminal networks, demonstrating the rapid scaling of these attacks. This trend reflects the broader evolution of social engineering attacks exploiting emerging technology hype cycles, with AI brands carrying significant trust and curiosity that attackers leverage to bypass traditional security awareness. The campaigns represent a paradigm shift from isolated phishing attempts to multi-stage attack chains spanning email, web, identity, and endpoint domains.
1 week ago
Kill Chain
Conti Ransomware Developer Gets 4-Year Prison Sentence in Landmark Prosecution
Ukrainian national Oleksii Lytvynenko was sentenced to four years in prison for his role in the Conti ransomware group, which attacked over 1,000 organizations globally before disbanding in 2022. Lytvynenko joined the prolific cybercrime operation in September 2021, developing malware and holding data from 12 victims including eight U.S.-based organizations. The group extorted approximately $634,000 in Bitcoin from victims in Tennessee, including a government entity that resulted in compromised sheriff's department, emergency medical services, and police department systems. This sentencing represents continued law enforcement efforts to prosecute ransomware operators despite their overseas operations, as Conti members have since rebranded under multiple successor groups including Black Basta, Royal, and BlackSuit, maintaining the threat landscape's evolution and persistence of ransomware-as-a-service operations.
1 week ago
Kill Chain
Ransomware Gangs Target WatchGuard Firebox Vulnerability: 9,000 Devices Still at Risk
CISA confirmed that ransomware gangs are actively exploiting CVE-2025-14733, a critical remote code execution vulnerability in WatchGuard Firebox firewalls. The flaw, first disclosed in December 2025, stems from an out-of-bounds write vulnerability affecting firewalls with IKEv2 VPN configurations. Despite patches being available for nine months, nearly 9,000 vulnerable devices remain exposed online according to Shadowserver monitoring, down from an initial 115,000. The vulnerability allows unauthenticated attackers to execute malicious code remotely with low complexity, making it an attractive target for threat actors. This incident highlights the persistent challenge of network perimeter security in an era where traditional firewalls face sophisticated exploitation techniques. With WatchGuard serving over 250,000 organizations through 17,000 resellers globally, the widespread exposure of this vulnerability demonstrates how legacy security infrastructure becomes a liability when not properly maintained and patched.
1 week ago
Kill Chain
IDScan Breach Exposes 153 Million Driver's Licenses: A Wake-Up Call for Identity Verification Security
In September 2026, identity verification company IDScan confirmed a significant data breach affecting over 153 million driver's license scans and personal identification documents. Threat actors gained unauthorized access to IDScan's cloud platform, compromising customer data including full names, driver's license numbers, and scanned copies of government-issued IDs. The stolen data was subsequently advertised on a dark web platform called 'Nexus' before being taken offline following FBI investigation. IDScan provides identity verification services to car rental companies, financial institutions, cannabis dispensaries, and hospitality businesses across the US and Canada. This incident highlights the growing threat to identity verification infrastructure as cybercriminals increasingly target centralized repositories of sensitive personal data. The breach demonstrates how third-party service providers handling critical identity documents have become high-value targets, creating cascading privacy risks across multiple industries that rely on these verification services.
1 week ago
Kill Chain
Russian AI Agents Exploit PaperCut Flaws in Global Campaign Hitting 395 Organizations
In August 2026, a Russian-speaking threat actor orchestrated an unprecedented AI-powered exploitation campaign targeting PaperCut NG/MF servers worldwide. Using hundreds of AI agents powered by OpenAI's Codex and DeepSeek models, the attackers automated exploit development for CVE-2026-81578 and CVE-2026-82078, compromising 440 PaperCut instances across 395 organizations in 48 countries within days. The campaign demonstrated alarming speed, with attackers achieving remote code execution in under four hours and domain administrator privileges in just seven minutes at some targets, primarily affecting educational institutions. This incident marks a critical inflection point in cybersecurity, showcasing how AI can compress traditional attack timelines from weeks to minutes. As threat actors increasingly weaponize AI for automated vulnerability discovery and exploitation, organizations face an unprecedented challenge where human-speed incident response becomes obsolete against machine-speed attacks.
1 week ago
Kill Chain
Mantax Otax: The Android Threat That Encrypts, Steals, and Terrorizes Victims
Mantax Otax, a sophisticated Android malware strain discovered in September 2026, combines ransomware, spyware, and harassment capabilities to target Indonesian users through malicious APKs distributed outside Google Play. The malware uses accessibility services to gain extensive device control, encrypts files on older Android versions (9 and below) using victim-specific AES keys, and steals sensitive data including SMS messages, call logs, WhatsApp conversations, and real-time screen recordings. Beyond encryption and data theft, version 2 introduced psychological harassment features including jumpscare overlays, forced audio messages, and repeated dialog boxes to pressure victims into paying ransoms through Firebase-hosted chat negotiations. This incident highlights the growing trend of multi-vector mobile threats that combine financial extortion with psychological manipulation, demonstrating how threat actors are evolving beyond traditional ransomware to create more coercive attack campaigns targeting vulnerable mobile ecosystems in developing markets.
1 week ago
Kill Chain
ShieldCrash Exploit Exposes Critical Gaps in Windows Defender Security
In September 2026, the security researcher known as Nightmare-Eclipse released 'ShieldCrash,' a zero-day privilege escalation exploit targeting Microsoft's Windows Defender Malware Protection Engine. This exploit bypasses Microsoft's patch for the previous CVE-2026-69414 'ShieldBreak' vulnerability, demonstrating arbitrary file read capabilities under SYSTEM privileges across all supported Windows versions. The exploit is part of an ongoing vendetta by the researcher against Microsoft, who has been releasing monthly zero-day exploits since April 2026, often followed by patch bypasses that expose incomplete remediation efforts. This incident highlights the growing trend of adversarial security research where legitimate researchers turn hostile due to vendor disputes, creating sustained security risks for enterprise environments relying on Windows infrastructure and endpoint protection solutions.
1 week ago
Kill Chain
LiteLLM Default Key Crisis: How 10% of AI Gateways Exposed Critical Infrastructure
In February 2026, Wiz Research discovered that nearly 10% of internet-facing LiteLLM AI gateway servers accepted the default administrator key 'sk-1234' from the platform's setup documentation. This misconfiguration exposed API keys for multiple AI model providers, allowed access to cloud IAM credentials through metadata services, and granted attackers full administrative control over affected gateways. The vulnerability enabled LLMjacking attacks where threat actors could consume AI services at victims' expense, while also providing pathways to broader cloud infrastructure compromise. This incident highlights the growing security risks in AI infrastructure as organizations rapidly deploy AI gateways without proper hardening. With over 85,000 LiteLLM instances discovered by August 2026 and active exploitation of related vulnerabilities already documented, the misconfiguration represents a critical gap in AI security posture management across cloud environments.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports