2832 stories
·
0 followers

Hackers Breach Government WordPress Site and Steal 18,566 Records With Plaintext Passwords

1 Share

The breach was part of a wider campaign targeting vulnerable WordPress installations worldwide. The activity from May 7, 2026 onward to a single malicious cyber actor believed to be a Chinese-speaking operator, possibly active in the UTC+8 time zone.

The actor is suspected to be the same group, or linked to, the “Red Heron” campaign previously reported by Acronis.

GreyNoise said the threat actor began exploiting WordPress sites around July 20 using the wp2shell exploit chain, involving CVE-2026-63030 and CVE-2026-60137.

The campaign successfully compromised at least 49 organizations across 29 countries, mainly affecting government and small-business targets.

WordPress Breach Exposes Passwords

The government intrusion began on July 22, when the attacker used the WordPress exploit chain to deploy a custom web shell on the targeted server. Within minutes, the actor extracted the WordPress user table, stealing 13 administrator accounts.

The attackers then accessed the WordPress administration panel and created a new account designed to appear legitimate. They altered its registration date to make it blend in with the victim’s existing account history.

After gaining access, the threat actor uploaded a custom information-gathering plugin and used the web shell to inspect the Windows-based server environment.

The attacker searched for security tools, local users, network services, database software, WordPress configuration files, and security settings.

GreyNoise observed the actor attempting to bypass Microsoft’s Antimalware Scan Interface (AMSI), elevate privileges, create local administrator accounts, and access registry data.

WordPress Breach Exposes Passwords (Source: greynoise)
WordPress Breach Exposes Passwords (Source: greynoise)

The actor also searched readable files for cleartext credentials and found working credentials for a backend SQL database. The stolen credentials were then used in password-spraying attempts against internal systems.

The attacker successfully accessed the SQL server, extracted data in bulk, compressed the stolen files into ZIP archives, and placed them in a web-accessible location before downloading them.

At least 18,566 records containing accounts, plaintext passwords, and personally identifiable information were exfiltrated. GreyNoise said the attacker continued password-spraying activity after the theft in an apparent attempt to expand access inside the organization.

The WordPress activity was only one component of a broader campaign. GreyNoise observed the actor scanning or attacking products from Ubiquiti, Gitea, FlowiseAI, Nuclio, SENAITE LIMS, Proxmox, and ZyXEL.

WordPress Breach Exposes Passwords (Source: greynoise)
WordPress Breach Exposes Passwords (Source: greynoise)

The group also exploited CVE-2026-7273 in ZyXEL GS1900 Smart Managed Switches beginning around August 17. GreyNoise said this was the first publicly documented exploitation of the flaw in the wild.

The campaign compromised 996 switches across 48 countries and collected device configurations, network information, and hashed root credentials.

Notably, 564 of the affected ZyXEL devices still used factory-default credentials, increasing the attacker’s ability to access and collect sensitive device data.

Indicators of Compromise

IOC TypeIndicatorDescription
SHA-2560e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480fMalicious backdoor
SHA-2560f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6Malicious back

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

The post Hackers Breach Government WordPress Site and Steal 18,566 Records With Plaintext Passwords appeared first on Cyber Security News.



Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete

LimeLeads - 17,838,396 breached accounts

1 Share
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode.
Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

1 Share

A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries. CVE-2026-7273 exploitation is part of an unfolding operation The Zyxel GS1900 Series is a line of Gigabit Ethernet switches aimed at small and mid-sized business … More

The post Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) appeared first on Help Net Security.

Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete

Gemini AI Autonomously Hacked 3 Companies, Google Confirms

1 Share

Three more companies were compromised due to an enterprise AI breach. 



Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

1 Share
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

1 Share
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
Read the whole story
NerdsToGo
2 hours ago
reply
Share this story
Delete
Next Page of Stories