[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Cyberattacks

GreyNoise reports government data theft via WordPress and Zyxel

GreyNoise reports that attackers used two WordPress vulnerabilities against at least 49 organizations and stole more than 18,000 records from an unnamed Western government. It also reports exploitation and data extraction from 996 Zyxel GS1900 switches in 48 countries. The observations come from the firm's sensors and attacker infrastructure; the government victim remains unnamed and state sponsorship is not established.

All updates
Reported ReportedPublished 25 September 2026

Incident timing: GreyNoise dates WordPress exploitation to around July 20 and Zyxel exploitation to August 17, 2026. It says the government data theft occurred in July; exact timing may differ from victim-side forensics.

GreyNoise describes a suspected actor exploiting multiple technologies, including WordPress and Zyxel networking equipment. Its report links two WordPress vulnerabilities to attacks on at least 49 organizations and theft of more than 18,000 records from an unnamed Western government. It also reports that attackers exploited CVE-2026-7273 and extracted information from 996 Zyxel GS1900 switches across 48 countries.

Scope and limits

GreyNoise based its findings on sensor observations and attacker infrastructure. It did not name the government victim or provide that organization's forensic report. Attribution to a suspected Chinese-speaking actor is a research assessment, not an official government finding. The report dates the WordPress activity to July and Zyxel exploitation to August, with publication on September 21.

Source & attribution

Read the original reporting at GreyNoise

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections