996 devices in 48 countries were compromised on August 17 after a threat actor exploited a high-severity ZyXEL vulnerability, according to GreyNoise.
Scope of the intrusions and the data taken
GreyNoise reports the adversary extracted device configurations, network information, and hashed root-level credentials from 996 ZyXEL GS1900 Smart Managed Switches across 48 countries after exploiting CVE-2026-7273. Separately, the actor leveraged WordPress wp2shell flaws to breach at least 49 organizations in 29 countries. In one prominent intrusion at an unnamed Western government organization, the attacker used recovered backend SQL credentials to gain access to an internal SQL server and stole at least 18,566 records. Those records contained accounts, plaintext passwords, and personally identifiable information tied to government and law-enforcement agencies.
Exploited products and tracked CVEs
The campaign targeted a broad array of technologies and specific vulnerabilities. GreyNoise documented exploitation or targeting of:
- ZyXEL GS1900 Smart Managed Switches — CVE-2026-7273 (compromised 996 devices on August 17)
- WordPress Core wp2shell vulnerabilities — CVE-2026-63030 and CVE-2026-60137 (public exploits appeared in mid‑July and active exploitation followed)
- Ubiquiti UniFi OS vulnerabilities — CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 (the actor attempted to chain these for root-level RCE)
- FlowiseAI — CVE-2026-56271
- Gitea — CVE-2026-60004 (the actor has links to a cluster associated with an earlier critical Gitea exploit)
- Nuclio — CVE-2026-79756; SENAITE LIMS — CVE-2026-54569; Proxmox VE — CVE-2023-54391
- PAN-OS GlobalProtect and the Linux kernel Dirty Pipe flaw (CVE-2022-0847) were also confirmed as targets
CISA has flagged the three Ubiquiti flaws as actively exploited since late June 2026. GreyNoise emphasized that not every security issue used by this threat cluster has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTactics seen in a Western government compromise
GreyNoise described a detailed intrusion at an unnamed Western government organization in which the attacker used a custom wp2shell exploit and conducted intensive Windows and security reconnaissance. Over roughly 36 minutes the actor ran 17 scripts probing Microsoft Defender, AMSI, available services, listening ports, local accounts, application restrictions, and database configuration. The scripts included attempts to bypass AMSI, escalate privileges through token impersonation or theft, create a local administrator account, and extract registry data. After locating credentials for a backend SQL database, the attackers employed a password-spraying technique to access an internal SQL server and exfiltrated at least 18,566 records.
Attribution, timeline, and detection
GreyNoise attributes the activity to a Chinese-speaking threat actor related to a cluster associated with the Red Heron group, which has links to exploitation of a critical Gitea flaw. Scans and attacks tied to this actor have originated from the same IP address and were recorded by GreyNoise sensors since early June 2026. Public exploits for the WordPress wp2shell issues became available in mid‑July; GreyNoise observed active exploitation only days later and says its campaign targeting high-value entities started around the same time. GreyNoise detected the activity via its Global Observation Grid (GOG) network of sensors and has provided indicators of compromise — including hashes for backdoors and command-and-control infrastructure — to aid defenders.
What this means for technologists, policymakers, and affected governments
- Technologists and security teams: GreyNoise’s list of exploited CVEs and IoCs gives immediate artifacts to hunt for, and the campaign shows exploitation can accelerate quickly after public exploit code appears (wp2shell exploits in mid‑July were followed by active attacks days later).
- Policymakers and regulators: The fact that not all exploited issues in this cluster appear in CISA’s KEV catalog highlights a gap between active exploitation observed by researchers and the KEV listings flagged by CISA.
- Affected enterprises and government operators: The campaign demonstrates how initial web application compromises can lead to credential theft, lateral movement, and large-scale data exfiltration — exemplified by the recovery of backend SQL credentials and the theft of 18,566 records from an internal server.
GreyNoise’s reporting ties a rapid, multi‑vector exploitation effort to a single attacker cluster operating from the same IP address since early June 2026, and the list of CVEs and IoCs offers concrete signals for defenders to use. The remaining question for decision-makers is whether the vulnerabilities that GreyNoise recorded as used by this actor but not yet on CISA’s KEV list will receive prioritized, public mitigation guidance.




