Incident timing: GreyNoise dates WordPress exploitation to around July 20 and Zyxel exploitation to August 17, 2026. It says the government data theft occurred in July; exact timing may differ from victim-side forensics.
GreyNoise describes a suspected actor exploiting multiple technologies, including WordPress and Zyxel networking equipment. Its report links two WordPress vulnerabilities to attacks on at least 49 organizations and theft of more than 18,000 records from an unnamed Western government. It also reports that attackers exploited CVE-2026-7273 and extracted information from 996 Zyxel GS1900 switches across 48 countries.
Scope and limits
GreyNoise based its findings on sensor observations and attacker infrastructure. It did not name the government victim or provide that organization's forensic report. Attribution to a suspected Chinese-speaking actor is a research assessment, not an official government finding. The report dates the WordPress activity to July and Zyxel exploitation to August, with publication on September 21.
Source & attribution
Read the original reporting at GreyNoiseBleepingComputer: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.