Trusence Technology, daily
Last updated 24 September 2026 Türkçe
← All stories
Security

Chinese-linked group hits WordPress, ZyXEL gear to steal government data

A Red Heron–linked actor used fresh WordPress and ZyXEL bugs to raid government and small-business systems worldwide for credentials and personal data.

Threat intel firm GreyNoise reports that a Chinese‑speaking threat actor linked to the Red Heron cluster is exploiting multiple internet‑facing products, including WordPress and ZyXEL GS1900 switches, to steal government and small‑business data. Using WordPress wp2shell bugs CVE‑2026‑63030 and CVE‑2026‑60137, the group breached at least 49 organizations across 29 countries and, in one Western government network, pivoted from the web server to an internal SQL server to exfiltrate at least 18,566 records with plaintext credentials and PII. The same actor compromised a Russian state entity in occupied Ukraine and has been scanning and attacking from a single IP since early June 2026, according to GreyNoise’s Global Observation Grid. From August 17, they also abused ZyXEL CVE‑2026‑7273 to pull configurations, network details and hashed root credentials from 996 switches in 48 countries, and probed other enterprise systems such as PAN‑OS GlobalProtect, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, and Proxmox VE. GreyNoise has published IoCs, and notes that some of the flaws used in this campaign are still missing from CISA’s Known Exploited Vulnerabilities catalog, underscoring the need to patch beyond KEV lists and harden exposed admin surfaces.

Why it matters

The campaign shows how quickly a capable actor can pivot from new web exploit code to deep access inside government networks. By chaining WordPress flaws into an internal SQL server, the group pulled more than 18,500 records with plaintext passwords and sensitive personal data tied to government and law-enforcement agencies, while also harvesting configs and root credential hashes from nearly a thousand ZyXEL switches in dozens of countries. That combination of account data and network intelligence raises the risk of follow-on intrusions against public bodies and small organizations alike.

Sources