$ techbeacon▋
CVE & Exploits

Chinese-Speaking Hackers Compromise ZyXEL Switches and WordPress Sites to Exfiltrate Thousands of Records

Chinese-Speaking Hackers Compromise ZyXEL Switches and WordPress Sites to Exfiltrate Thousands of Records

A threat actor communicating in Chinese has been linked to a coordinated campaign that leveraged flaws in ZyXEL GS1900 smart managed switches and vulnerable WordPress installations to pilfer data from nearly a thousand network devices and more than 18,500 database records.

The intrusion chain began with the exploitation of unpatched firmware in ZyXEL's GS1900 series, a line of low‑cost switches widely deployed in small‑ to medium‑size enterprises and municipal networks. By gaining administrative access to the switches, the attackers were able to move laterally across internal networks, identify WordPress sites running on the same infrastructure, and then exploit known WordPress vulnerabilities to elevate privileges and reach backend databases.

Security researchers who first uncovered the operation say the attackers systematically harvested credentials, configuration files, and other sensitive information stored on the compromised devices. The data dump, which includes more than 18,500 records, appears to contain internal communications, network diagrams, and possibly personally identifiable information, though the exact contents have not been publicly disclosed.

While the campaign’s ultimate motive remains unclear, analysts note that the combination of network‑level hardware exploitation and web‑application attacks is characteristic of state‑aligned actors seeking broad visibility into target environments. The use of a Chinese‑language command‑and‑control infrastructure further points to a group with regional ties, though attribution to any specific nation‑state has not been formally confirmed.

Experts warn that the incident highlights the risks of relying on legacy networking gear that may no longer receive timely security updates. Organizations that continue to run older ZyXEL firmware without applying the latest patches are especially vulnerable. Likewise, the prevalence of outdated WordPress plugins and themes provides an easy foothold for attackers once they have breached the perimeter.

In response, ZyXEL has issued a security advisory urging customers to upgrade to the newest firmware version and to audit device configurations for unauthorized changes. Security firms recommend that affected entities conduct thorough forensic examinations, reset all compromised credentials, and implement network segmentation to limit the impact of any future breach. The broader community is watching closely, as the tactics demonstrated in this campaign could be repurposed against a wider array of critical infrastructure worldwide.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related