A Chinese-speaking threat actor linked to the Red Heron group exploited WordPress wp2shell flaws and other vulnerabilities to steal sensitive data from organizations across dozens of countries. GreyNoise observed attacks against ZyXEL GS1900 switches, Ubiquiti, PAN-OS GlobalProtect, and several other platforms, including intrusions that exposed credentials, PII, and backend database records. #RedHeron #wp2shell #ZyXELGS1900 #WordPress #Ubiquiti #PANOSGlobalProtect #GreyNoise
Keypoints
- The attacker used wp2shell flaws in WordPress to breach at least 49 organizations in 29 countries.
- One intrusion at a Western government organization led to theft of 18,566 records.
- The stolen data included accounts, plaintext passwords, and PII tied to government and law-enforcement agencies.
- The threat actor also exploited ZyXEL GS1900 switches to extract configurations and hashed root credentials.
- GreyNoise observed targeting of Ubiquiti, PAN-OS GlobalProtect, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, and Proxmox VE.