GreyNoise ties Red Heron-linked group to WordPress, ZyXEL exploits hitting 996 devices
GreyNoise's Global Observation Grid detected a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress's wp2shell vulnerabilities to compromise 996 devices and steal over 18,500 records. The group, linked to the Red Heron actor previously tied to a Gitea flaw, breached at least 49 organizations across 29 countries since early June 2026, including an unnamed Western government agency.
GoKawiil's interpretation of the reporting above, not reported fact.
The intrusion at the government target shows a methodical attack chain—reconnaissance, AMSI bypass, privilege escalation, and password spraying—that led to theft of tens of thousands of database records, suggesting a well-resourced and patient operator. GreyNoise's findings indicate attackers are moving quickly to weaponize newly disclosed exploits like wp2shell, which could signal a broader pattern of rapid exploitation against government and small-business networks running outdated WordPress or networking gear.
- A Chinese-speaking actor linked to Red Heron exploited ZyXEL and WordPress flaws to hit 996 devices and steal 18,566+ records.
- At least 49 organizations in 29 countries were targeted, including an unnamed Western government body.
- GreyNoise says attackers used custom wp2shell exploits, AMSI bypass techniques, and password spraying to reach an internal SQL server.
Firewalla Gold Plus Network Firewall — With threat actors actively exploiting router and WordPress vulnerabilities to breach networks, having a dedicated firewall like Firewalla Gold Plus gives you real-time intrusion detection and blocking at the network edge. It helps flag suspicious outbound connections and known malicious IPs, which is exactly the kind of activity described in this attack campaign. A strong perimeter defense is a smart complement to keeping your WordPress and IoT devices patched.
See Firewalla Gold Plus Network Firewall on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-22
Published there as: “Chinese hackers exploit WordPress, Zyxel flaws to steal govt data”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.