A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.
The campaign targeted security gaps in commonly deployed networking and content management infrastructure, gaining access to sensitive government data stored in backend databases.
ZyXEL GS1900 switches, used for network management across many organizations, contained exploitable flaws that allowed attackers to bypass authentication. WordPress installations with unpatched vulnerabilities provided additional entry points.
The threat actor systematically compromised devices across multiple targets, demonstrating persistent access to steal data at scale. The 18,500+ records extracted suggest sustained presence within affected networks.
Organizations running these products should immediately patch systems and audit access logs for suspicious activity. ZyXEL and WordPress maintainers have released security updates addressing the exploited vulnerabilities. Network administrators should prioritize updates for internet-facing devices and implement additional monitoring on switched infrastructure.
Government agencies affected are reviewing the scope of compromised data and notifying relevant stakeholders.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.
WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.
Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.
GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.