Chinese Hackers Exploit Unpatched WordPress & Zyxel Flaws to Exfiltrate Government Data
A Chinese-linked threat actor exploited known vulnerabilities in WordPress and Zyxel network switches to compromise nearly 1,000 devices across 29 countries, stealing over 18,500 records including plaintext passwords and personally identifiable information. The root cause lies in unpatched, internet-facing systems that remained vulnerable long enough for a coordinated campaign to extract sensitive government data at scale. Storing credentials in plaintext compounded the damage significantly, turning a patching failure into a full data breach. This incident underscores that public-sector organizations are high-value targets and that delayed patching of widely-used platforms creates systemic, cross-border risk.
Tactical Insight
Immediate actions
- Apply all available patches for WordPress core, plugins, and Zyxel firmware immediately, prioritizing internet-facing assets.
- Audit all stored credentials and eliminate plaintext password storage by enforcing hashed credential standards.
- Conduct an emergency scan of internet-exposed assets using a vulnerability scanner (e.g., Tenable, Qualys) to identify any currently exploitable systems.
Long-term improvements
- Implement a formal patch management policy with SLA-based timelines (e.g., critical patches applied within 24–72 hours of release).
- Maintain a continuously updated asset inventory of all internet-facing devices, including network appliances and CMS platforms.
- Enforce network segmentation to isolate government data stores from internet-facing web and network infrastructure.
Detection measures
- Deploy intrusion detection and log aggregation tools to alert on anomalous outbound data transfers or lateral movement from edge devices.
- Subscribe to threat intelligence feeds (e.g., GreyNoise, CISA KEV catalog) to receive early warning of actively exploited vulnerabilities.
- Conduct regular penetration testing and red team exercises targeting public-facing systems to identify exploitable weaknesses before threat actors do.