Chinese-speaking threat actor exploits ZyXEL and WordPress vulnerabilities to exfiltrate government data
Actor targets Smart Managed Switches and WordPress instances to steal sensitive records from government entities

Key Takeaways
- A Chinese-speaking threat actor is exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress platforms.
- The campaign has affected 996 devices and over 18,500 records stored in backend databases.
- Government entities are the primary targets of this campaign.
- The actor leverages multiple technologies to gain access and exfiltrate sensitive data.
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




