Skip to content
Tech News
← Back to articles

GreyNoise ties Red Heron-linked group to WordPress, ZyXEL exploits hitting 996 devices

read original get Firewalla Gold Plus Network Firewall → more articles
GoKawiil Brief

GreyNoise's Global Observation Grid detected a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress's wp2shell vulnerabilities to compromise 996 devices and steal over 18,500 records. The group, linked to the Red Heron actor previously tied to a Gitea flaw, breached at least 49 organizations across 29 countries since early June 2026, including an unnamed Western government agency.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The intrusion at the government target shows a methodical attack chain—reconnaissance, AMSI bypass, privilege escalation, and password spraying—that led to theft of tens of thousands of database records, suggesting a well-resourced and patient operator. GreyNoise's findings indicate attackers are moving quickly to weaponize newly disclosed exploits like wp2shell, which could signal a broader pattern of rapid exploitation against government and small-business networks running outdated WordPress or networking gear.

Key Takeaways
Worth a Look

Firewalla Gold Plus Network Firewall — With threat actors actively exploiting router and WordPress vulnerabilities to breach networks, having a dedicated firewall like Firewalla Gold Plus gives you real-time intrusion detection and blocking at the network edge. It helps flag suspicious outbound connections and known malicious IPs, which is exactly the kind of activity described in this attack campaign. A strong perimeter defense is a smart complement to keeping your WordPress and IoT devices patched.

See Firewalla Gold Plus Network Firewall on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-22

Published there as: “Chinese hackers exploit WordPress, Zyxel flaws to steal govt data”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.