WordPress Flaws Expose 18,566 Government Records
Hackers have exploited WordPress flaws to expose records from 49 organizations across 29 countries. A suspected Chinese-speaking threat actor targeted vulnerabilities, gaining unauthorized access to download 18,566 records from a Western government’s SQL database. This campaign underscores how WordPress flaws expose records, becoming a launchpad for broader network intrusions. Utilizing the wp2shell chain (CVE-2026-63030 and CVE-2026-60137), attackers deployed a webshell, added a secret administrator account, and moved toward internal systems. They also probed other systems, including ZyXEL switches, emphasizing a wide attack surface. GreyNoise identified how perpetrators exploited these weaknesses to execute commands, search databases, and extract password files. Organizations must urgently patch WordPress cores and plugins, remove rogue accounts, and tighten security controls. Protecting against such sophisticated threats requires vigilance and continuous monitoring. For more details on these exploits and potential countermeasures, read the full article at Cyber Security News.
Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords
