Xygeni GitHub Action Compromised Via Tag Poison

2026-03-11T20:51:40Z356c30c14cc7ae2dc17207ca7192c14217fc1fa6c46c0124ae6a5d6ad464e751
C2CVE-2026-21385active-exploitationai-securityandroidciscocloud-securitycommand-injectionedr-bypassfirewall-vulnerabilitiesgithub-actiongoogle-geminimalvertisingmicrosoft-patch-tuesdaynation-state-activityopenclawphishingsupply-chaintag-poisoningvmwarevulnerability-managementzero-day

What happened

Multiple active threats and high-impact vulnerabilities reported: a supply-chain compromise of Xygeni's GitHub Action via tag poisoning allowed attackers to run a C2 implant for up to a week; a Qualcomm zero-day (CVE-2026-21385) is being exploited in targeted Android attacks; VMware Aria Operations has a command-injection flaw under active exploitation risking cloud environments; Cisco disclosed dozens of firewall vulnerabilities including multiple critical issues; Microsoft released patches for 83 CVEs. Additional notable trends include AI-related attack vectors (OpenClaw, Google Gemini panel

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
356c30c14cc7ae2dc17207ca7192c14217fc1fa6c46c0124ae6a5d6ad464e751
Enrichment time
2026-03-11T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Xygeni GitHub Action Compromised Via Tag Poison · Baitaphish