Skip to content
RegionEurope

MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday

Chinese-speaking Red Heron group compromised 996 Zyxel switches in 48 countries and 49 organisations in 29 countries

According to GreyNoise, a Chinese-speaking threat actor has compromised at least 49 organisations in 29 countries and 996 network switches in 48 countries since June 2026 through WordPress and Zyxel flaws. 18,566 records were stolen from a Western government agency; CISA gave federal agencies until 24 September.

ITALY

According to reports by BleepingComputer and CyberInsider dated 22 September 2026, GreyNoise found that the group it tracks as Red Heron has been active since early June 2026 and began using the wp2shell chain in WordPress (CVE-2026-63030 and CVE-2026-60137) in mid-July. The group compromised at least 49 organisations in 29 countries; in one case at a Western government agency on 22 July, 13 administrator accounts were stolen in about 11 minutes, and 18,566 records, plaintext passwords and personal data linked to law enforcement agencies were pulled from the database.

According to Help Net Security, from 17 August the same actor exploited the CVE-2026-7273 flaw in Zyxel GS1900 switches to compromise 996 devices in 48 countries, concentrated in Italy, the US, Taiwan, South Korea and EU countries. 564 of the victims were using the factory default password; device configurations, network information and root password hashes were stolen. The flaw was patched in June 2026; CISA added it to its catalogue of known exploited vulnerabilities and gave federal agencies until 24 September.

Based on the actor's working hours and Chinese comments in its scripts, GreyNoise assesses that it may be a Chinese speaker operating in the UTC+8 time zone. The sources do not allege a link between the group and any state agency, and none could be independently verified.

Talay assessment

Bottom line

The campaign relies not on expensive zero-days but on flaws that were patched but not applied and on default passwords: 564 of the 996 switches were running with the factory password. The configurations and root password hashes taken from network switches amount to preparation for deeper intrusions later. The most likely path is national CERT warnings and a patching campaign in Europe; the campaign should not be expected to stop in the near term.

Likely effects

  • European public networksNegative1–6 months

    Switch compromises concentrated in Italy and EU countries raise the risk of persistent access at the network edge of small institutions and municipalities.

  • Law enforcement dataNegativeWeeks

    The theft of 18,566 records with plaintext passwords from a Western government agency increases the risk of lateral movement into other systems through password reuse.

  • Turkish SME and public networksNegativeWeeks

    WordPress and low-cost managed switches are also widespread in Türkiye; the 29-country target list is a direct warning for Turkish institutions with default-password and delayed-patching habits.

Possibilities, ranked

  1. 1
    Wave of warnings and patches55%

    European national CERTs issue warnings on the Zyxel and WordPress flaws, and the number of compromised devices starts to fall.

    Watch: A CVE-2026-7273 warning from the Italian or EU CERT and GreyNoise's updated device count

  2. 2
    Campaign expands35%

    The actor moves to a new edge-device flaw, and the number of target countries rises above 48.

    Watch: A new CVE exploitation attributed to the same actor by GreyNoise or other firms

  3. 3
    State link disclosed10%

    A government or joint advisory attributes the campaign to a state-backed group.

    Watch: The Red Heron name in a CISA, NCSC or joint Five Eyes advisory

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Zyxel switches compromised 996
  • Devices with default passwords 564
  • Government records stolen 18,566

Sources

  1. BleepingComputer — Chinese hackers exploit multiple technologies to steal govt data
  2. Help Net Security — Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
  3. CyberInsider — WordPress wp2shell attacks stole 18,000 government records