Life Mirrors Art: Ransomware Hits Hospitals on TV & IRL

2026-03-04T20:37:02Z316f37b46b9fe6125a6bf9f4e74ec53041794fd82f3faf05e1ee9af5c33a67e4
CVE-2026-20127CVE-2026-2329AI threatsClaude CodeFortiGateGrandstreamLazarus GroupMFA bypassMedusa ransomwareOT/ICSReact2Shellhealthcarephishingransomwaresupply-chainthreat-intelligencezero-day

What happened

DarkReading news roundup covering a wide range of active threats and security trends: ransomware hitting healthcare (real-world incident mirrored on TV); a long-running, high-severity Cisco SD‑WAN zero‑day (CVE-2026-20127) actively exploited for ~3 years; a critical unauthenticated Grandstream VoIP vulnerability (CVE-2026-2329) enabling root access; mass FortiGate compromises by an AI‑enabled attacker; supply‑chain infections (malicious npm package Cline/OpenClaw, Android Keenadu payload); North Korean–linked poisoned Next.js repos and Lazarus using Medusa ransomware and multiple malware tools

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
316f37b46b9fe6125a6bf9f4e74ec53041794fd82f3faf05e1ee9af5c33a67e4
Enrichment time
2026-03-04T20:37:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.