Industry Category

Health Care / Life Sciences

Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.

3054 threat reports
Page 9 of 255

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Health Care / Life Sciences Threat Reports

Showing 97108 / 3054 reports
Cisco Secure FMC Under Attack: CVE-2026-20079 Exploitation Confirmed
Impact· CRITICAL

Cisco Secure FMC Under Attack: CVE-2026-20079 Exploitation Confirmed

In August 2026, Cisco confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software. The flaw, scoring 10.0 on CVSS, allows unauthenticated remote attackers to execute commands with root privileges by sending crafted HTTP requests to vulnerable devices. Evidence suggests exploitation began as early as July 2026, with attackers potentially chaining this vulnerability with CVE-2026-20316, a static credential flaw, to achieve comprehensive system compromise. CISA added the vulnerability to its KEV catalog, mandating federal agencies secure systems by September 12, 2026. This incident highlights the continued targeting of network infrastructure management platforms, which provide attackers with centralized control over security policies and network configurations. The maximum severity rating and active exploitation demonstrate the critical importance of securing management interfaces in an era of increasing nation-state and cybercriminal focus on infrastructure vulnerabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AdaptHealth Breach Exposes 4.1M Patients in ShinyHunters Attack
Impact· HIGH

AdaptHealth Breach Exposes 4.1M Patients in ShinyHunters Attack

In July 2026, healthcare provider AdaptHealth disclosed a major data breach affecting 4.1 million patients after the ShinyHunters ransomware group successfully executed a social engineering attack against a third-party contractor. The attack, which occurred on June 5, 2026, compromised privileged credentials and enabled access to cloud-based patient management systems, document storage platforms, and electronic health records. The breach exposed full names, contact information, demographic data, health insurance details, and protected health information across AdaptHealth's network of 680 locations serving all 50 U.S. states. This incident exemplifies the escalating threat landscape targeting healthcare organizations through sophisticated social engineering tactics and third-party supply chain vulnerabilities. The breach highlights the increasing trend of ransomware groups specifically targeting healthcare data for maximum impact and regulatory pressure, making it a critical reference point for current cybersecurity strategies in the healthcare sector.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Powered Cyber Attacks: How UAT-10147 Weaponized Machine Learning in August 2026
Impact· CRITICAL

AI-Powered Cyber Attacks: How UAT-10147 Weaponized Machine Learning in August 2026

In August 2026, Recorded Future's Insikt Group identified 73 high-impact vulnerabilities actively exploited in the wild, marking a significant shift in threat actor operations with the emergence of AI-assisted exploitation campaigns. The Chinese-speaking threat group UAT-10147 demonstrated a novel approach by combining traditional vulnerability exploitation with agentic artificial intelligence tools like DeepAudit and PentestGPT for post-compromise operations. The group systematically targeted internet-facing servers through vulnerabilities in Zimbra, AjaxPro, Nacos, and Telerik platforms before deploying AI agents for automated privilege escalation and lateral movement across compromised networks. This incident represents a critical evolution in cyber warfare, as threat actors increasingly integrate AI capabilities into their attack workflows to scale operations and enhance target selection. The convergence of AI-powered offensive tools with traditional exploitation techniques signals a new era of automated cyber threats that can operate with unprecedented speed and precision, fundamentally changing the threat landscape for enterprise security teams.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft's Record 974 Patches Signal New Era of AI-Driven Vulnerability Management
Impact· CRITICAL

Microsoft's Record 974 Patches Signal New Era of AI-Driven Vulnerability Management

In September 2026, Microsoft released its largest security update in company history, patching 974 vulnerabilities across Windows operating systems and other software products. The unprecedented patch bundle included two actively exploited zero-day flaws (CVE-2026-81963 and CVE-2026-85880) allowing privilege escalation, plus 113 critical vulnerabilities that could enable complete system compromise. Notable critical flaws included CVE-2026-69730, a DNS weakness affecting Windows Server 2012+ and Windows 10, and CVE-2026-69829, a Windows Shell remote code execution vulnerability with a 9.8 CVSS score requiring no user interaction. This massive patch release reflects the growing impact of AI-assisted vulnerability discovery, which is dramatically accelerating the identification of security flaws across the software industry. While AI tools are creating larger volumes of vulnerabilities to address, security experts emphasize that organizations must focus on risk-based prioritization rather than attempting to patch every identified flaw simultaneously.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's Record-Breaking 974 CVE Patch Tuesday: Zero-Days and Wormable Threats Demand Immediate Action
Impact· CRITICAL

Microsoft's Record-Breaking 974 CVE Patch Tuesday: Zero-Days and Wormable Threats Demand Immediate Action

Microsoft's September 2026 Patch Tuesday set a new record with 974 CVEs, marking the fourth consecutive month of substantially larger security updates driven by AI-assisted vulnerability discovery. Two zero-day vulnerabilities (CVE-2026-85880 and CVE-2026-81963) are under active exploitation, targeting Windows Advanced Local Procedure Call and Windows Update Stack respectively. The release includes 13 critical flaws, 20 wormable CVEs creating network contagion risks, and a cluster of near-maximum severity remote code execution bugs affecting Windows Shell, NFS services, and Microsoft Word. With 438 elevation of privilege vulnerabilities and 260 remote code execution flaws, attackers gained unprecedented attack surface across Windows, Office, SQL Server, and Azure environments. This massive vulnerability disclosure represents the new normal as AI transforms cybersecurity landscapes, creating larger attack surfaces while simultaneously enabling faster discovery of long-standing security gaps before malicious actors can exploit them.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Attackers Use Multi-Hop Google Redirects to Bypass Email Security
Impact· MEDIUM

How Attackers Use Multi-Hop Google Redirects to Bypass Email Security

In September 2026, cybersecurity researchers at KnowBe4 identified a sophisticated phishing campaign exploiting multiple Google services to evade detection systems. Threat actors chained together Google Meet, DoubleClick, Google Custom Search, and other Google infrastructure to create multi-hop redirect sequences that appear legitimate to security gateways. The campaign dynamically constructs credential harvesting pages based on victim email addresses and deploys ScreenConnect remote access tools through fake identity verification prompts. Victims' stolen credentials are delivered to operators via Telegram channels within seconds, along with IP addresses, geolocation data, and organizational details. This incident highlights the evolving sophistication of phishing attacks that abuse trusted infrastructure to bypass traditional security controls. As threat actors increasingly leverage legitimate cloud services for malicious purposes, organizations face growing challenges in detecting attacks that appear benign at every inspection point until the final malicious payload is delivered.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Workflow Identity Hijacking: The New AI Attack Vector Bypassing Enterprise Security
Impact· HIGH

Workflow Identity Hijacking: The New AI Attack Vector Bypassing Enterprise Security

Security researchers at Noma Labs have identified a new AI attack vector called 'workflow identity hijacking' that exploits authorization design flaws in enterprise AI pipelines. The attack allows threat actors to bypass standard security controls by sending seemingly benign requests through unauthenticated entry points like support emails or web forms. The AI workflow processes these requests using high-privilege service accounts, enabling unauthorized data access and exfiltration without traditional prompt injection techniques. This represents a fundamental shift from model manipulation to identity delegation vulnerabilities in AI systems. This attack vector is particularly relevant now as organizations rapidly deploy AI automation without proper identity scoping and least privilege principles, creating widespread exposure to data breaches through seemingly legitimate AI interactions.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft's Record 974-Vulnerability Patch Release Signals AI-Driven Security Era
Impact· CRITICAL

Microsoft's Record 974-Vulnerability Patch Release Signals AI-Driven Security Era

In September 2026, Microsoft released a record-breaking security update addressing 974 vulnerabilities across its software portfolio, including two actively exploited zero-day flaws (CVE-2026-85880 and CVE-2026-81963). Both zero-days are privilege escalation vulnerabilities affecting Windows Advanced Local Procedure Call and Windows Update Stack respectively, allowing attackers to gain SYSTEM-level privileges. The massive patch release included 723 Windows vulnerabilities, 111 Office flaws, and over 110 critical severity issues, bringing Microsoft's 2026 total to over 2,600 patches - more than double the previous annual record. This unprecedented vulnerability disclosure reflects the acceleration of AI-assisted security research and automated vulnerability discovery tools. The scale demonstrates how artificial intelligence is revolutionizing both offensive security research and defensive patching cycles, fundamentally changing the threat landscape and forcing organizations to adapt their vulnerability management strategies for an era of exponential security disclosure growth.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical SAP Kernel Vulnerability Exposes Enterprise Systems to Complete Compromise
Impact· CRITICAL

Critical SAP Kernel Vulnerability Exposes Enterprise Systems to Complete Compromise

SAP released critical security updates in September 2026 addressing multiple vulnerabilities, including CVE-2026-44756, a maximum-severity CVSS 10.0 flaw in SAP Extended Passport Processing. Discovered by Onapsis and codenamed OVERPASS, this memory corruption vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands with SAP administrative privileges. The flaw affects SAP kernel code across multiple protocols including web, GUI, and RFC layers, making it reachable through internet-facing components without requiring credentials. Successful exploitation enables complete compromise of SAP business data, lateral movement to connected systems, and manipulation of critical application configurations. This incident highlights the growing threat landscape targeting enterprise resource planning systems as organizations increasingly digitize their core business processes. With SAP systems managing critical financial and operational data for thousands of enterprises globally, kernel-level vulnerabilities represent existential risks that bypass traditional authentication controls and demand immediate remediation efforts.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ShieldCrash Exposes Critical Gap in Microsoft Defender Patch Strategy
Impact· HIGH

ShieldCrash Exposes Critical Gap in Microsoft Defender Patch Strategy

In September 2026, security researcher Chaotic Eclipse demonstrated a critical patch bypass vulnerability dubbed 'ShieldCrash' affecting Microsoft Defender's Malware Protection Engine. This zero-day exploit bypasses the incomplete fix for CVE-2026-69414 (ShieldBreak), allowing arbitrary file read operations with SYSTEM privileges on all supported Windows versions. Despite Microsoft's August 2026 patch addressing the original ShieldBreak vulnerability, the researcher revealed that specific attack vectors remained unpatched, enabling continued exploitation of the same underlying security flaw through alternative code paths. This incident highlights the growing trend of researchers discovering incomplete security patches in enterprise endpoint protection platforms, with similar vulnerabilities recently disclosed in CrowdStrike Falcon, Kaspersky, and Avast products, demonstrating systemic challenges in comprehensive vulnerability remediation across the cybersecurity industry.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
F5 BIG-IP Under Attack: Memory-Resident Web Shell Evades Traditional Detection
Impact· CRITICAL

F5 BIG-IP Under Attack: Memory-Resident Web Shell Evades Traditional Detection

A sophisticated malware campaign targeting F5 BIG-IP Access Policy Manager appliances exploits CVE-2025-53521 to inject PHP web shells directly into memory rather than storing them on disk. The malware, tracked as c05d5254 and PoisonedRefresh, hooks Apache functions to modify three specific PHP scripts in memory when loaded, enabling command execution through normal web requests while evading traditional file-based detection. The attack chain begins with exploitation of the critical remote code execution vulnerability (CVSS 9.8) and establishes persistence through infected system binaries and installation media. This incident highlights the evolution of fileless malware techniques and the growing sophistication of infrastructure-focused attacks. As organizations increasingly rely on application delivery controllers and load balancers for critical services, attackers are developing advanced evasion techniques that challenge traditional security monitoring approaches, making network-level visibility and behavioral analysis essential for detection.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chrome V8 Zero-Day Exploited in Wild: Critical Browser Security Implications for Enterprise
Impact· CRITICAL

Chrome V8 Zero-Day Exploited in Wild: Critical Browser Security Implications for Enterprise

In September 2026, Google patched CVE-2026-87491, an actively exploited zero-day vulnerability in Chrome's V8 JavaScript engine that allowed remote code execution within the browser sandbox. The out-of-bounds write flaw enabled attackers to execute arbitrary code through crafted HTML pages, representing the seventh Chrome zero-day exploited in the wild during 2026. Google acknowledged active exploitation but withheld details about the attack methods and threat actors to protect users during the patch deployment phase. This incident highlights the persistent targeting of browser engines by sophisticated threat actors who continue developing novel exploitation techniques against widely-used platforms. The frequency of Chrome zero-days in 2026 demonstrates an escalation in browser-based attacks as threat actors adapt to improved endpoint security measures.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports