Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A threat actor is targeting government and enterprise networks by exploiting known vulnerabilities in ZyXEL switches and WordPress.

A Chinese-speaking threat actor has launched a targeted campaign exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and the WordPress platform. According to reports from BleepingComputer, the campaign aims to extract sensitive data from government networks and backend systems.
The attacks have successfully compromised 996 devices and resulted in the theft of over 18,500 records stored in backend databases. The hackers leverage these software and hardware flaws to gain unauthorized access and siphon off critical information.
This cyber espionage activity highlights the growing risk associated with unpatched network infrastructure and enterprise software. Threat actors continue to weaponize standard vulnerabilities in routers, switches, and content management systems to breach high-value targets.
For technology and security professionals worldwide, this incident emphasizes the critical need for proactive vulnerability management. Ensuring that all network hardware firmware and web applications are kept up to date is essential for mitigating such advanced persistent threats.
Security experts advise organizations to audit their internet-facing assets immediately, apply the latest security patches for WordPress and ZyXEL devices, and monitor network traffic for any anomalous behavior that could indicate a potential breach.



