[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4sYJs47dqJi6jhA8M6hM1bQZ4SkCAI-2xqZvQkHL4JU":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"32230832-18d8-4a86-b887-5697c7929918","Chinese hackers exploit WordPress, Zyxel flaws to steal govt data","chinese-hackers-exploit-wordpress-zyxel-flaws-to-steal-govt-data-178864","A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]","A Chinese-speaking threat actor, potentially linked to the Red Heron group, has been actively exploiting vulnerabilities in WordPress and Zyxel switches to steal sensitive government data. The campaign, detected by GreyNoise, has compromised nearly 1,000 devices and over 18,500 records, including plaintext passwords and PII, from organizations across 29 countries.","Chinese hackers exploit WordPress and Zyxel flaws to steal government data.","Chinese hackers exploit WordPress, Zyxel flaws to steal govt data By Bill Toulas September 22, 2026 04:35 PM 0 A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. The adversary targeted multiple technologies, including PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, Ubiquity, with exploits for known security issues. Scans and attacks attributed to the adversary originate from the same IP address and have been recorded since early June 2026, and have been attributed to a threat actor related to the Red Heron group, linked to exploiting a critical flaw in the Gitea self-hosted Git service. The activity was detected by threat intelligence company GreyNoise through its Global Observation Grid (GOG) network of sensors. According to the researchers, the threat actor leveraged the wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) in the WordPress Core component to breach at least 49 organizations in 29 countries. Public exploits for wp2shell became available in mid-July, and active exploitation was observed a few days later. The campaign GreyNoise observed started around the same time, targeting high-value entities. While many targets were in the small business and government sectors, one intrusion at an unnamed Western government organization stands out. The attacker used a custom wp2shell exploit and performed extensive Windows and security reconnaissance, checking Microsoft Defender, AMSI, available services, listening ports, local accounts, application restrictions, and database configuration. Over 36 minutes, the threat actor tried 17 scripts to bypass AMSI, escalate privileges through token impersonation or theft, create a local administrator, and extract registry data, GreyNoise says. After locating credentials for a backend SQL database, the attackers used them in a password-spraying attack that gave them access to an internal SQL server, from which they stole at least 18,566 records. According to the researchers, the data contained accounts, plaintext passwords, and personally identifiable information (PII) connected to government and law-enforcement agencies. wp2shell attack timelineSource: GreyNoise The same attacker breached a Russian state organization in occupied Ukraine, which the researchers described as a “red-on-red” compromise. Exploiting multiple flaws On August 17, the threat actor started to exploit a high-severity flaw (CVE-2026-7273) in ZyXEL GS1900 Smart Managed Switches and compromised 996 devives in 48 countries to extract device configurations, network information, and hashed root-level credentials. Timeline of exploitation activitySource: GreyNoise Additionally, the hackers attempted to chain the Ubiquiti UniFi OS vulnerabilities tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to obtain root-level remote code execution. CISA has flagged the three Ubiquiti flaws as actively exploited since late June 2026. GreyNoise also confirmed targeting of PAN-OS GlobalProtect, FlowiseAI (CVE-2026-56271), the Linux kernel’s Dirty Pipe flaw (CVE-2022-0847), Gitea (CVE-2026-60004), Nuclio (CVE-2026-79756), SENAITE LIMS (CVE-2026-54569) and Proxmox VE (CVE-2023-54391). The researchers highlight that not all security issues leveraged in attacks linked to this threat cluster have been added to CISA's catalog of Known Exploited Vulnerabilities (KEV). GreyNoise has provided a set of indicators of compromise (IoCs) connected to the observed activity, which include hashes for backdoors and command-and-control (C2) infrastructure. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: CISA orders feds to patch Zyxel flaw exploited for data theftHackers target WordPress sites via third-party WooCommerce pluginJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsCritical Elementor Pro flaw exploited to take over WordPress sitesRecently patched PaperCut zero-days used in data theft attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchinese-hackers-exploit-multiple-technologies-to-steal-govt-data\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2025\u002F03\u002F05\u002Fchinese-hacker-flag.jpg","2026-09-22T20:35:24+00:00","2026-09-22T22:00:22.668881+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Red Heron","threat_actor",{"name":22,"type":23},"WordPress","product",{"name":25,"type":23},"ZyXEL GS1900 Smart Managed Switches",{"name":27,"type":23},"PAN-OS Global Protect",{"name":29,"type":23},"FlowiseAI",{"name":31,"type":23},"Nuclio","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":32,"icon":34,"name":35,"slug":36},null,"Nation-state","nation-state",[38,40,45,50],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60,62,65,68,70,72,75,78,81,84,87],{"type":57,"value":58,"context":59},"cve","CVE-2026-63030","WordPress Core vulnerability exploited",{"type":57,"value":61,"context":59},"CVE-2026-60137",{"type":57,"value":63,"context":64},"CVE-2026-7273","ZyXEL GS1900 Smart Managed Switch vulnerability exploited",{"type":57,"value":66,"context":67},"CVE-2026-34908","Ubiquiti UniFi OS vulnerability exploited",{"type":57,"value":69,"context":67},"CVE-2026-34909",{"type":57,"value":71,"context":67},"CVE-2026-34910",{"type":57,"value":73,"context":74},"CVE-2022-0847","Linux kernel Dirty Pipe vulnerability exploited",{"type":57,"value":76,"context":77},"CVE-2026-60004","Gitea vulnerability exploited",{"type":57,"value":79,"context":80},"CVE-2026-79756","Nuclio vulnerability exploited",{"type":57,"value":82,"context":83},"CVE-2026-56271","FlowiseAI vulnerability exploited",{"type":57,"value":85,"context":86},"CVE-2026-54569","SENAITE LIMS vulnerability exploited",{"type":57,"value":88,"context":89},"CVE-2023-54391","Proxmox VE vulnerability exploited"]