Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor linked to Red Heron exploited WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to breach organizations, including government targets, and steal database records containing passwords and PII. The campaign also exploited ZyXEL GS1900 Smart Managed Switches flaw CVE-2026-7273 and targeted PAN-OS GlobalProtect, FlowiseAI CVE-2026-56271, Ubiquiti UniFi OS CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, Linux CVE-2022-0847, Gitea CVE-2026-60004, Nuclio CVE-2026-79756, SENAITE LIMS CVE-2026-54569, and Proxmox VE CVE-2023-54391. Organizations should review GreyNoise IoCs and patch exposed systems, as the activity resulted in stolen credentials, device configurations, and sensitive records.