Executive Summary
A Chinese-speaking threat actor linked to the Red Heron group conducted a sophisticated multi-vector campaign from June to August 2026, exploiting critical vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) and ZyXEL GS1900 switches (CVE-2026-7273) to breach government and business organizations across 48 countries. The attackers compromised 996 devices and exfiltrated over 18,500 sensitive records containing government personnel data, law enforcement information, and plaintext credentials through advanced reconnaissance and database infiltration techniques. This incident highlights the growing sophistication of state-sponsored threat actors who leverage publicly available exploits within days of their release to target critical infrastructure and government entities. The campaign's timing coincided with increased geopolitical tensions and demonstrates how adversaries rapidly weaponize disclosed vulnerabilities to achieve strategic intelligence objectives.
Why This Matters Now
This breach exemplifies the accelerated threat landscape where state-sponsored actors exploit vulnerabilities within days of public disclosure, targeting critical government infrastructure during heightened geopolitical tensions and demonstrating the urgent need for rapid patch management and zero-trust security architectures.
Attack Path Analysis
Chinese threat actors exploited WordPress wp2shell vulnerabilities and ZyXEL switch flaws to gain initial access, performed extensive reconnaissance and privilege escalation through AMSI bypass techniques, moved laterally to internal SQL servers via password spraying, maintained persistent command and control infrastructure, and exfiltrated over 18,566 records containing PII and credentials from government and law enforcement agencies across 49 organizations in 29 countries.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploited wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) in WordPress Core and ZyXEL GS1900 switch flaw (CVE-2026-7273) to gain initial access to government and business networks
Related CVEs
CVE-2022-0847
CVSS 7.8A flaw was found in the way the 'flags' member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel, allowing privilege escalation.
Affected Products:
Linux Linux Kernel – 5.8 - 5.16.10, 5.15.25, 5.10.102
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Password Spraying
Process Injection
Account Discovery
File and Directory Discovery
Exfiltration Over C2 Channel
Credentials In Files
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software security vulnerabilities are addressed
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.02(g)
DORA – Identification and protection
Control ID: Article 8
CISA ZTMM 2.0 – Access Management
Control ID: Identity.AM-5
NIS2 Directive – Cybersecurity risk management
Control ID: Article 21.2(a)
GDPR – Security of processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical exposure as Chinese hackers specifically targeted Western and Russian government organizations, stealing 18,566 records containing credentials and PII from law enforcement agencies.
Law Enforcement
High-priority target with confirmed data theft of accounts, plaintext passwords, and personally identifiable information through WordPress wp2shell exploits and SQL database breaches.
Information Technology/IT
Significant infrastructure risk from exploitation of WordPress, ZyXEL switches, Ubiquiti devices, and multiple CVEs requiring immediate patch management and zero trust implementation.
Computer Software/Engineering
Elevated threat from multi-technology attack chain targeting WordPress Core, Gitea, FlowiseAI, and other software platforms requiring enhanced egress security and anomaly detection.
Sources
- Chinese hackers exploit WordPress, Zyxel flaws to steal govt datahttps://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/Verified
- Open Season on Kapibala: Attacker Steals Government Records via WordPress Exploitationhttps://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitationVerified
- Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- CVE-2022-0847 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2022-0847Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this multi-stage attack by constraining lateral movement between compromised WordPress sites, SQL servers, and network infrastructure. The segmented architecture could limit attacker reachability across the 49 organizations spanning 29 countries.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise would likely still occur through vulnerable WordPress and ZyXEL systems, but attacker reach into cloud workloads and internal network segments could be constrained through identity-aware access controls and microsegmentation boundaries.
Control: Zero Trust Segmentation
Mitigation: Local privilege escalation could likely still succeed on compromised systems, but the scope of elevated access would be constrained to individual workload segments rather than providing broad network access across multiple systems and databases.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts to SQL servers would likely face significant constraints through east-west traffic enforcement, reducing the attacker's ability to reach backend databases even with extracted credentials from compromised WordPress systems.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications could likely be constrained across cloud environments through centralized visibility and policy enforcement, limiting the attacker's ability to maintain persistent access to distributed cloud workloads and infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration volumes would likely be constrained through egress policy enforcement, reducing the attacker's ability to extract large datasets containing PII and credentials from segmented database environments to external command and control infrastructure.
While some government data exposure would likely remain unavoidable after initial compromise, the blast radius across the 49 organizations could be significantly reduced through segmented access controls limiting cross-organizational data exposure.
Impact at a Glance
Affected Business Functions
- Government Data Management
- Law Enforcement Records
- Citizen Services
- National Security Operations
Estimated downtime: 7 days
Estimated loss: N/A
At least 18,566 records containing government accounts, plaintext passwords, and personally identifiable information (PII) connected to government and law-enforcement agencies. Configuration data from 996 ZyXEL network devices across 48 countries including hashed root credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between WordPress systems and critical database infrastructure
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration to external destinations
- • Enable Multicloud Visibility & Control to identify anomalous database access patterns and privilege escalation attempts
- • Activate Inline IPS (Suricata) to detect and block known exploit signatures for wp2shell and ZyXEL vulnerabilities
- • Establish Encrypted Traffic (HPE) controls to protect sensitive government data during transit and prevent credential exposure



