Chinese hackers hit 996 Zyxel switches and WordPress sites
A Chinese-speaking threat actor exploited flaws in Zyxel GS1900 switches and WordPress, compromising 996 devices across 48 countries and stealing over 18,500 records from backend databases. Activity has been tracked since early June 2026, targeting government and small-business entities in 29 countries.
- 996 Zyxel GS1900 switches compromised across 48 countries
- At least 18,566 records with passwords and PII stolen
- wp2shell attacks hit at least 49 organizations in 29 countries
- Exploits also targeted PAN-OS, FlowiseAI, Proxmox and Ubiquiti
Read next
Security