Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-linked actor exploited WordPress and Zyxel flaws, stealing government records from dozens of organizations.
GreyNoise says a Chinese-speaking actor linked to Red Heron exploited WordPress core wp2shell flaws CVE-2026-63030 and CVE-2026-60137, breaching at least 49 organizations in 29 countries. One Western government intrusion produced at least 18,566 SQL records with accounts, plaintext passwords, and law-enforcement PII after AMSI bypass, token theft, local-admin creation, and password spraying. On August 17 the actor used CVE-2026-7273 to compromise 996 Zyxel GS1900 switches in 48 countries and also targeted UniFi OS, PAN-OS GlobalProtect, FlowiseAI, Gitea, Nuclio, Proxmox VE, SENAITE LIMS, and Dirty Pipe. CISA has the three UniFi bugs on the KEV list; GreyNoise published backdoor and C2 indicators.