Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, government] · confidence: high · severity: medium · affected_sectors: [government] · au_impact: true

GreyNoise has attributed a sustained campaign to a Chinese-speaking actor it links to the Red Heron cluster, exploiting the wp2shell WordPress Core vulnerabilities CVE-2026-63030 and CVE-2026-60137 against at least 49 organisations in 29 countries, and the Zyxel GS1900 switch flaw CVE-2026-7273 against 996 devices in 48 countries since 17 August. The WordPress intrusions yielded at least 18,566 records — accounts, plaintext passwords and personally identifiable information tied to government and law-enforcement agencies — after the actor located credentials for a backend SQL database and used them in a password-spraying attack against an internal SQL server. In one Western government intrusion the operator spent 36 minutes running 17 scripts to bypass AMSI, escalate privileges through token impersonation and create a local administrator account. On the switch side, the exploitable payload was a PyArmor-obfuscated Python script that used TFTP to retrieve a collector covering device configurations, network information and hashed root-level credentials. The same actor also breached a Russian state organisation in occupied Ukraine — a red-on-red compromise — and this is the campaign behind yesterday's KEV addition for CVE-2026-7273, now with the exploitation figures attached.

Attribute Detail
Sector Government
Date 2026-09-23
Source GreyNoise
Reliability Tier 2
CVEs CVE-2026-60137, CVE-2026-63030, CVE-2026-7273