INC Ransomware Group Holds Healthcare Hostage in Oceania

2026-03-12T02:51:47Z365329e510e6e032fb953d084e3cd3ca2d7c583af4d173940e46e63cb065806f
C2CVE-2026-21385Oceaniaai-enabled-attackschina-aptcisco-firewallcommand-injectioncredential-phishingedr-bypassgithub-actionsgoogle-geminihealthcaremalvertisingmisconfigurationnation-statenorth-koreaopenclawpro-iranian-actorsqualcommransomwarerussia-aptsalesforcesupply-chaintag-poisoningvmware

What happened

This DarkReading feed highlights a surge in active, high-impact cyber activity: INC ransomware is disrupting healthcare across Oceania; a GitHub Action (xygeni/xygeni-action) was compromised via tag-poisoning enabling a week-long C2 implant; China- and Russia-linked APTs are refocusing operations regionally and deploying new sophisticated toolkits; multiple critical product flaws are being actively exploited or patched (notably Qualcomm Android zero-day CVE-2026-21385 and an exploited command-injection bug in VMware Aria Operations). Cisco released dozens of firewall fixes including critical 9

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
365329e510e6e032fb953d084e3cd3ca2d7c583af4d173940e46e63cb065806f
Enrichment time
2026-03-12T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · INC Ransomware Group Holds Healthcare Hostage in Oceania · Baitaphish