Xygeni GitHub Action Compromised Via Tag Poison
2026-03-11T20:51:40Z•356c30c14cc7ae2dc17207ca7192c14217fc1fa6c46c0124ae6a5d6ad464e751
C2CVE-2026-21385active-exploitationai-securityandroidciscocloud-securitycommand-injectionedr-bypassfirewall-vulnerabilitiesgithub-actiongoogle-geminimalvertisingmicrosoft-patch-tuesdaynation-state-activityopenclawphishingsupply-chaintag-poisoningvmwarevulnerability-managementzero-day
What happened
Multiple active threats and high-impact vulnerabilities reported: a supply-chain compromise of Xygeni's GitHub Action via tag poisoning allowed attackers to run a C2 implant for up to a week; a Qualcomm zero-day (CVE-2026-21385) is being exploited in targeted Android attacks; VMware Aria Operations has a command-injection flaw under active exploitation risking cloud environments; Cisco disclosed dozens of firewall vulnerabilities including multiple critical issues; Microsoft released patches for 83 CVEs. Additional notable trends include AI-related attack vectors (OpenClaw, Google Gemini panel
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 356c30c14cc7ae2dc17207ca7192c14217fc1fa6c46c0124ae6a5d6ad464e751
- Enrichment time
- 2026-03-11T20:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.