Act
active
Chinese hackers exploit ZyXEL switches and WordPress to steal govt data
- Engineer — Act: Active exploitation of ZyXEL GS1900 switches and WordPress is confirmed with measurable data theft. Patch both to current versions immediately and audit backend database access logs and switch management interfaces for unauthorized access or lateral movement.
- SOC/IR — Plan: An active Chinese-attributed campaign is targeting ZyXEL switches and WordPress for database exfiltration, but the summary provides no specific IOCs. Build or tune detections for anomalous outbound queries from web servers and unauthorized switch management activity, and begin a retrospective hunt across those log sources.
- Leader — Plan: A Chinese-speaking actor has compromised nearly 1,000 devices and exfiltrated thousands of records in an ongoing government-targeting campaign. Confirm whether the organization runs ZyXEL GS1900 switches or internet-facing WordPress, and escalate to leadership if operating in sectors adjacent to government contracts.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.