:

CHINESE HACKERS EXPLOIT WORDPRESS, ZYXEL FLAWS

SECURITY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.

The campaign targeted security gaps in commonly deployed networking and content management infrastructure, gaining access to sensitive government data stored in backend databases. ZyXEL GS1900 switches, used for network management across many organizations, contained exploitable flaws that allowed attackers to bypass authentication. WordPress installations with unpatched vulnerabilities provided additional entry points. The threat actor systematically compromised devices across multiple targets, demonstrating persistent access to steal data at scale. The 18,500+ records extracted suggest sustained presence within affected networks. Organizations running these products should immediately patch systems and audit access logs for suspicious activity. ZyXEL and WordPress maintainers have released security updates addressing the exploited vulnerabilities. Network administrators should prioritize updates for internet-facing devices and implement additional monitoring on switched infrastructure. Government agencies affected are reviewing the scope of compromised data and notifying relevant stakeholders.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.

JUST NOWSecurity Desk

WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.

2H AGOIndustry Desk

Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.

2H AGOIndustry Desk

GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.