Hackers widen WordPress attacks across 29 countries
A suspected Chinese-speaking cyber actor has exploited a two-vulnerability WordPress attack chain to breach at least 49 organisations in 29 countries, with one Western government body losing more than 18,000 sensitive records, according to threat intelligence findings published on Monday. GreyNoise said it had tracked the activity through its Global Observation Grid and linked the campaign to a…
A Chinese-speaking cyber actor has exploited a two-vulnerability chain in WordPress to breach at least 49 organizations in 29 countries, according to threat intelligence reports. The campaign, which began in July, primarily targeted government entities and small businesses. GreyNoise, a cybersecurity intelligence company, tracked the activity through its Global Observation Grid and traced the campaign back to May.
The attacker used vulnerabilities CVE-2026-63030 and CVE-2026-60137 to gain database access and achieve remote code execution. In one Western government breach, the attacker obtained sensitive records, including plaintext credentials. The stolen data included account details, personally identifiable information, and plaintext passwords associated with law-enforcement and government agencies.
The actor also installed a custom information-gathering plugin and created custom tools for bulk data extraction. GreyNoise cautioned that their timeline was based on preserved file timestamps and may not match a formal forensic investigation. The same infrastructure and tactics were linked to another threat cluster identified as Red Heron.
WordPress released fixes for the vulnerabilities on July 17, urging administrators to update immediately.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.