Kapibala Hackers Steal 18,500+ Government Records via WordPress and Zyxel Flaws
A threat actor tracked as Kapibala, suspected to be Chinese-speaking, breached a Western government organization's database by exploiting a WordPress vulnerability chain combining CVE-2026-63030 and CVE-2026-60137, deploying custom web shells to harvest credentials and access internal SQL databases. The attackers exfiltrated at least 18,566 records containing account details, plaintext passwords, and personally identifiable information linked to government and law-enforcement agencies. Separately, the same actor exploited a stack-based buffer overflow vulnerability in Zyxel GS1900 switches (CVE-2026-7273) to steal device configurations, hashed root credentials, and network data from 996 devices across 48 countries. GreyNoise, which published its findings on September 21, 2026, noted the campaign leveraged shared external infrastructure for continuous scanning and exploitation. CISA has added the relevant CVEs to its Known Exploited Vulnerabilities catalog, and administrators are urged to patch affected systems and monitor for anomalous PHP files, bulk SQL authentication attempts, and unauthorized configuration retrievals.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in