Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
Summary
A Chinese-speaking threat actor is exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive government data. The campaign has impacted 996 devices and over 18,500 records stored in backend databases.
IFF Assessment
FOE
This article details an ongoing cyberattack by a threat actor that is compromising government data, posing a direct threat to defenders.
Defender Context
This incident highlights the persistent threat posed by nation-state actors leveraging known vulnerabilities in widely used infrastructure. Defenders should prioritize patching and monitoring for exploitation of Zyxel switches and WordPress, especially in environments handling sensitive government data.