State-linked attackers breach government networks via WordPress and switch vulnerabilities

A threat actor linked to the Red Heron group has been exploiting known flaws in ZyXEL switches and WordPress to infiltrate nearly 1,000 devices and exfiltrate over 18,500 database records, including credentials and personal data. The campaign, detected by GreyNoise, targeted government and law-enforcement entities across 29 countries, with one intrusion at a Western government organization involving extensive Windows reconnaissance and privilege escalation attempts. The attackers also breached a Russian state organization in occupied Ukraine, marking a red-on-red compromise.
The campaign, active since June 2026, blends opportunistic scanning with targeted intrusion. Attackers used public exploits for WordPress and ZyXEL flaws, but also chained multiple vulnerabilities across platforms like Ubiquiti and Proxmox. One notable breach involved a Western government network, where the intruder spent over half an hour probing security controls, attempting to bypass AMSI and escalate privileges before stealing database credentials. The stolen records included plaintext passwords and personal data tied to law-enforcement agencies. A separate intrusion hit a Russian state body in occupied Ukraine, illustrating the attacker’s broad geographic reach.
GreyNoise’s detection relied on its global sensor grid, which captured activity from a single source IP. The researchers noted that several exploited flaws are not yet listed in CISA’s Known Exploited Vulnerabilities catalog, leaving gaps in defensive prioritization. The attacker’s toolset included custom exploits and backdoors, with indicators of compromise shared for network defenders.
This incident could strain trust in widely used infrastructure, as WordPress and ZyXEL devices underpin many small businesses and public agencies. Government and law-enforcement data exposure may enable further phishing, identity theft, or espionage. The “red-on-red” breach suggests state-aligned actors can target each other, potentially escalating geopolitical tensions. Organizations may need to accelerate patching and monitoring, but resource-constrained entities could struggle, widening security gaps.