A suspected Chinese-speaking threat actor tracked by GreyNoise as Kapibala, and assessed as the same as or related to Red Heron, exploited the wp2shell WordPress chain—CVE-2026-63030 and SQL-injection flaw CVE-2026-60137—to compromise at least 49 organizations across 29 countries. The campaign deployed custom webshells, created hidden WordPress administrator accounts, stole database configuration and credential data, and used password spraying to access internal SQL services. A Western government organization lost at least 18,566 records containing account data, plaintext passwords, and personally identifiable information.
The actor also exploited CVE-2026-7273 in ZyXEL GS1900 switches, targeting 996 devices in 48 countries and collecting configurations, hashed root credentials, and network data, while scanning other exposed products including Ubiquiti UniFi OS, Gitea, Proxmox VE, FlowiseAI, and Nuclio. WordPress has patched CVE-2026-60137 in versions 6.8.6, 6.9.5, and 7.0.2; affected organizations should update immediately, rotate potentially exposed credentials, remove unauthorized administrator accounts, investigate for webshells, restrict database access, and monitor for password spraying and bulk archive downloads.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
On or about this date, the actor began exploiting CVE-2026-7273 in ZyXEL GS1900 Smart Managed Switches. The activity compromised 996 devices in 48 countries and exfiltrated device configurations, hashed root credentials, and network information; 564 affected devices used factory-default credentials.
The actor exploited a western government organization's WordPress site, deployed a custom webshell, and stole 13 administrator accounts. It then obtained backend SQL credentials, accessed an internal SQL database through password spraying, and exfiltrated at least 18,566 records containing accounts, plaintext passwords, and PII associated with law-enforcement and government agencies.
Around 20 July 2026, the actor began exploiting the wp2shell chain, involving CVE-2026-63030 and CVE-2026-60137. The campaign ultimately compromised at least 49 organizations in 29 countries, primarily affecting small-business and government targets.
CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to its Known Exploited Vulnerabilities catalog after exploitation activity involving the UniFi OS flaw chain.
The actor attempted to chain CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 for remote code execution against unpatched Ubiquiti UniFi OS devices, attempting to download and execute a backdoor from staging infrastructure.
GreyNoise assessed activity attributable to a suspected Chinese-speaking actor, potentially related to Red Heron, from 7 May 2026 onward. The actor subsequently targeted or exploited products including PAN-OS GlobalProtect, UniFi OS, Gitea, WordPress, and other internet-facing systems.
WordPress addressed CVE-2026-60137, an SQL injection vulnerability affecting several WordPress release branches. Fixed versions are 6.8.6, 6.9.5, and 7.0.2 for their respective affected branches.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceboho.or.kr
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.