✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Pharmaceuticals
Breach intelligence, attack campaigns, and threat reports targeting the Pharmaceuticals sector.
Explore Other Sectors
Pharmaceuticals Threat Reports
Microsoft Dismantles RedVDS: Takedown of a Major Cybercrime Infrastructure in 2026
In January 2026, Microsoft, in collaboration with Europol and German authorities, disrupted RedVDS, a global cybercrime-as-a-service platform responsible for at least $40 million in fraud losses since March 2025. RedVDS provided criminals with affordable, disposable virtual Windows servers and administrator-level access, enabling mass phishing, business email compromise (BEC) scams, credential theft, and sophisticated social engineering—including attacks leveraging AI technologies. The takedown involved legal action, seizure of RedVDS infrastructure, and removal of its marketplace and customer portal, significantly impacting cybercriminal campaigns that leveraged these services to attack organizations and individuals worldwide. This incident underscores the increasing threat posed by cybercrime-as-a-service models, which drastically lower barriers for criminals to launch high-volume, geographically-targeted attacks leveraging cloud infrastructure. The rise of AI-generated phishing, deepfakes, and anonymized payment methods heightens risk, challenging both organizational defenses and global law enforcement.
6 months ago
Kill Chain
AVEVA 2026: Critical ICS Vulnerabilities Put Manufacturing at Risk
In January 2026, AVEVA disclosed seven critical vulnerabilities in its Process Optimization suite, widely used by critical manufacturing and infrastructure sectors worldwide. The flaws, reported by Veracode’s Christopher Wu, include unauthenticated remote code execution, SQL injection, privilege escalation, code injection, and cleartext transmission of sensitive data. Attackers exploiting these vulnerabilities could fully compromise servers, escalate user privileges, access sensitive process data, and potentially undermine operational continuity or safety. Affected versions include all AVEVA Process Optimization releases up to and including 2024.1. These vulnerabilities highlight increasing targeting of industrial control and process optimization platforms, exposing gaps in legacy ICS security. With global critical infrastructure at risk and exploitation methods aligned with broader trends in supply chain and lateral movement attacks, this incident underscores urgent needs for robust security controls, ongoing software updates, and regulatory compliance in the ICS/OT domain.
6 months ago
Kill Chain
Former Insiders Launch ALPHV/BlackCat Ransomware Attacks in 2023
In 2023, two former cybersecurity professionals, Ryan Clifford Goldberg and Kevin Tyler Martin, exploited their trusted positions at incident response firms Sygnia and DigitalMint to perpetrate a series of targeted ransomware attacks. Acting in collusion with a third party and leveraging the ALPHV (BlackCat) ransomware variant, they compromised the networks of organizations across several critical sectors, including healthcare, engineering, and manufacturing. The group successfully extorted nearly $1.3 million from a Florida-based medical company and caused total damages exceeding $9.5 million across multiple states, before being apprehended and pleading guilty in federal court within months of indictment. This breach stands out for the attackers’ abuse of insider knowledge and privileged access, highlighting a new threat vector where trusted security personnel become adversaries. The case draws industry-wide attention to potential insider threats, the rising sophistication of ransomware groups, and the urgent need for enhanced monitoring and zero trust practices.
6 months ago
Kill Chain
Inotiv 2025 Ransomware Breach: Pharma Data at Risk
In August 2025, Inotiv, a leading American pharmaceutical firm, suffered a significant ransomware attack resulting in the theft of sensitive personal data belonging to thousands of individuals. Threat actors infiltrated the company’s network, deployed ransomware, and exfiltrated confidential information before encrypting internal systems. The breach led to data exposure and operational disruption, prompting Inotiv to notify impacted parties and regulatory authorities. Forensic investigation indicated unauthorized access over an extended period prior to the ransomware detonation, increasing the scope of compromised information. This incident highlights the escalating risks faced by the pharmaceutical industry, where highly regulated data attracts sophisticated ransomware groups. The resurgence of data-exfiltration ransomware tactics underlines the urgent need for advanced segmentation, egress controls, and integrated detection to defend against evolving threats and meet compliance expectations.
6 months ago
Kill Chain
Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security
In December 2025, Mirion Medical disclosed multiple high-severity vulnerabilities affecting its EC2 Software NMIS BioDose product, versions prior to 23.0. These flaws—incorrect permission assignments, use of hard-coded credentials, and client-side authentication weaknesses—could be exploited by attackers to gain unauthorized access, elevate privileges, manipulate executables, steal sensitive medical data, or execute arbitrary code. Impacting the healthcare and public health sectors globally, these vulnerabilities pose critical operational and patient-data risks, especially in environments with networked installations and exposed Microsoft SQL Server databases. No active exploitation has yet been reported, but CISA urges urgent mitigation measures due to the vulnerabilities’ remote exploitability and low attack complexity. This incident highlights intensifying regulatory scrutiny on medical device security as threat actors increasingly target healthcare systems for sensitive patient data and intellectual property. The vulnerabilities in Mirion’s product underscore persistent gaps in authentication and privilege controls—a growing concern amid adoption of connected medical technologies and regulatory frameworks such as HIPAA and NIST.
6 months ago
Kill Chain
Festo ICS Hidden Function Flaw Raises Global Manufacturing Security Stakes
In November 2025, Festo SE & Co. KG disclosed a critical security vulnerability (CVE-2023-3634) in its MSE6-C2M/D2M/E2M industrial control modules. The flaw, caused by hidden functionality accessible to remote, low-privileged authenticated users, could enable attackers to trigger undocumented test modes leading to a complete loss of confidentiality, integrity, and availability across affected devices. Operations worldwide in the critical manufacturing sector were potentially exposed due to this vulnerability, rated CVSS 8.8, though no evidence of active exploitation was reported. The issue prompted coordinated advisories from CERT@VDE and CISA, highlighting the systemic risk to industrial automation environments. This incident highlights ongoing threats to operational technology (OT) and industrial control systems, as the trend of exploiting hidden or undocumented features grows. With manufacturing and critical infrastructure increasingly interconnected, such vulnerabilities pose a greater risk of targeted disruptions and underscore the urgent need for proactive cybersecurity and compliance safeguards in OT environments.
6 months ago
Kill Chain
Rogue Incident Responders Deploy ALPHV/BlackCat Ransomware Against US Companies
In 2023, three US-based cybersecurity professionals, including an incident response manager from Sygnia and a ransomware negotiator from DigitalMint, were indicted after orchestrating a wave of ransomware attacks using the ALPHV/BlackCat strain. Beginning in May 2023, the group compromised five US organizations spanning healthcare, pharmaceuticals, engineering, and tech, deploying ransomware to encrypt critical data and extort payments. Only a Florida medical company paid, sending nearly $1.3 million in ransom; the other four victims did not make payments. The attacks were uncovered through joint law enforcement efforts, leading to arrests and criminal charges for the conspirators. This case is significant as it highlights the ongoing risk of insider threats even among trusted cybersecurity professionals. The exploitation of privileged insider knowledge paired with advanced ransomware-as-a-service tooling demonstrates how internal actors can subvert security postures, fueling industry concerns about vigilance, vetting, and zero trust principles within security teams.
6 months ago
Kill Chain
Oxford Nanopore 2025: MinKNOW Vulnerabilities Expose Medical Devices to Remote Exploitation
In October 2025, Oxford Nanopore Technologies disclosed three critical vulnerabilities in its MinKNOW DNA/RNA sequencing devices, impacting versions prior to 24.11. These flaws, which included missing authentication for critical functions, insufficiently protected credentials, and improper checks for exceptional conditions, allowed unauthorized users—both local and remote—to access, manipulate, or halt sequencing operations. Attackers could exploit default remote access settings and insecure credential storage to exfiltrate or alter sensitive data and cause denial of service in key sequencing workflows. The vulnerabilities were responsibly reported by academic researchers, prompting urgent advisories by CISA and the vendor. This incident underscores increasing risk to healthcare and life sciences infrastructure, with medical device supply chains emerging as a prime target for cyberattackers. As regulatory focus on medical device cybersecurity intensifies globally, organizations must swiftly address legacy systems and implement controls that secure both east-west and egress traffic, limit access, and ensure encrypted credential storage.
6 months ago
Kill Chain
Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations
In September 2025, a critical vulnerability (CVE-2025-5086, CVSS 9.0) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management software was found to be actively exploited in the wild. Threat actors leveraged this flaw to gain unauthorized access, bypassing authentication and executing arbitrary code on exposed systems. The breach impacted several manufacturing sector organizations globally, leading to disruptions in operational technology, potential data compromise, and urgent incident response actions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog and issuing public guidance for immediate patching and mitigation. This incident is significant as adversaries continue to target vulnerable OT/IoT platforms central to manufacturing operations. The increased frequency of high-severity vulnerabilities in critical infrastructure software, combined with rapid weaponization by threat actors, is driving regulatory scrutiny and highlighting the urgent need for robust vulnerability management and zero trust controls across industrial environments.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports