Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise tracks 'Red Heron' actor exploiting multiple vulnerabilities including novel ZyXEL CVE-2026-7273 and stealing 18,000+ government records.
GreyNoise identified a suspected Chinese-speaking threat actor ('Red Heron') conducting widespread exploitation across multiple technologies since June 2026. The actor exploited Ubiquiti, WordPress, ZyXEL, Gitea, and other products, stealing over 18,000 sensitive records from a western government. A novel zero-day exploitation of CVE-2026-7273 in ZyXEL GS1900 switches affected 996 devices globally. GreyNoise observed patterns suggesting the actor used LLMs to generate custom attack tools.
80