GreyNoise's Global Observation Grid detected a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress's wp2shell vulnerabilities to compromise 996 devices and steal over 18,500 records. The group, linked to the Red Heron actor previously tied to a Gitea flaw, breached at least 49 organizations across 29 countries since early June 2026, including an unnamed Western government agency.
bleepingcomputer.com
· 2026-09-22
GreyNoise reports that a suspected Russian-speaking threat actor deployed hundreds of AI agents, trained in a lab, to hunt down internet-exposed PaperCut NG and MF servers and exploit two known vulnerabilities. The campaign hit at least 440 instances across 395 organizations in 48 countries, with attackers pivoting from initial compromise toward Windows Active Directory environments.
darkreading.com
· 2026-09-11
GreyNoise reports that a likely Russian-speaking threat actor deployed hundreds of AI agents using OpenAI's Codex and DeepSeek models to build and launch exploits against two PaperCut NG/MF vulnerabilities. The campaign, which began August 31, compromised at least 440 servers across 395 organizations in 48 countries, mostly in education, with credentials stolen from 280 victims and admin access gained at 12 organizations.
bleepingcomputer.com
· 2026-09-10