INC Ransomware Group Holds Healthcare Hostage in Oceania
2026-03-12T02:51:47Z•365329e510e6e032fb953d084e3cd3ca2d7c583af4d173940e46e63cb065806f
C2CVE-2026-21385Oceaniaai-enabled-attackschina-aptcisco-firewallcommand-injectioncredential-phishingedr-bypassgithub-actionsgoogle-geminihealthcaremalvertisingmisconfigurationnation-statenorth-koreaopenclawpro-iranian-actorsqualcommransomwarerussia-aptsalesforcesupply-chaintag-poisoningvmware
What happened
This DarkReading feed highlights a surge in active, high-impact cyber activity: INC ransomware is disrupting healthcare across Oceania; a GitHub Action (xygeni/xygeni-action) was compromised via tag-poisoning enabling a week-long C2 implant; China- and Russia-linked APTs are refocusing operations regionally and deploying new sophisticated toolkits; multiple critical product flaws are being actively exploited or patched (notably Qualcomm Android zero-day CVE-2026-21385 and an exploited command-injection bug in VMware Aria Operations). Cisco released dozens of firewall fixes including critical 9
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 365329e510e6e032fb953d084e3cd3ca2d7c583af4d173940e46e63cb065806f
- Enrichment time
- 2026-03-12T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.