GreyNoise has attributed a sustained campaign to a Chinese-speaking actor it links to the Red Heron cluster, exploiting the wp2shell WordPress Core vulnerabilities CVE-2026-63030 and CVE-2026-60137 against at least 49 organisations in 29 countries, and the Zyxel GS1900 switch flaw CVE-2026-7273 against 996 devices in 48 countries since 17 August. The WordPress intrusions yielded at least 18,566 records — accounts, plaintext passwords and personally identifiable information tied to government and law-enforcement agencies — after the actor located credentials for a backend SQL database and used them in a password-spraying attack against an internal SQL server. In one Western government intrusion the operator spent 36 minutes running 17 scripts to bypass AMSI, escalate privileges through token impersonation and create a local administrator account. On the switch side, the exploitable payload was a PyArmor-obfuscated Python script that used TFTP to retrieve a collector covering device configurations, network information and hashed root-level credentials. The same actor also breached a Russian state organisation in occupied Ukraine — a red-on-red compromise — and this is the campaign behind yesterday's KEV addition for CVE-2026-7273, now with the exploitation figures attached.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-23 |
| Source | GreyNoise |
| Reliability | Tier 2 |
| CVEs | CVE-2026-60137, CVE-2026-63030, CVE-2026-7273 |