MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

State-linked attackers breach government networks via WordPress and switch vulnerabilities

Image via BleepingComputer
Image via BleepingComputer

A threat actor linked to the Red Heron group has been exploiting known flaws in ZyXEL switches and WordPress to infiltrate nearly 1,000 devices and exfiltrate over 18,500 database records, including credentials and personal data. The campaign, detected by GreyNoise, targeted government and law-enforcement entities across 29 countries, with one intrusion at a Western government organization involving extensive Windows reconnaissance and privilege escalation attempts. The attackers also breached a Russian state organization in occupied Ukraine, marking a red-on-red compromise.

Expanded Detail

The campaign, active since June 2026, blends opportunistic scanning with targeted intrusion. Attackers used public exploits for WordPress and ZyXEL flaws, but also chained multiple vulnerabilities across platforms like Ubiquiti and Proxmox. One notable breach involved a Western government network, where the intruder spent over half an hour probing security controls, attempting to bypass AMSI and escalate privileges before stealing database credentials. The stolen records included plaintext passwords and personal data tied to law-enforcement agencies. A separate intrusion hit a Russian state body in occupied Ukraine, illustrating the attacker’s broad geographic reach.

GreyNoise’s detection relied on its global sensor grid, which captured activity from a single source IP. The researchers noted that several exploited flaws are not yet listed in CISA’s Known Exploited Vulnerabilities catalog, leaving gaps in defensive prioritization. The attacker’s toolset included custom exploits and backdoors, with indicators of compromise shared for network defenders.

Context

This incident could strain trust in widely used infrastructure, as WordPress and ZyXEL devices underpin many small businesses and public agencies. Government and law-enforcement data exposure may enable further phishing, identity theft, or espionage. The “red-on-red” breach suggests state-aligned actors can target each other, potentially escalating geopolitical tensions. Organizations may need to accelerate patching and monitoring, but resource-constrained entities could struggle, widening security gaps.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
U.S. agencies face Thursday deadline to fix Zyxel switch bug under active attack · Cybersecurity
Global probe ties North Korean group to mass device compromise and crypto theft · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Chinese hackers exploit WordPress, Zyxel flaws to steal govt data.” Browse more stories.