Find notable cyber news and cases, enriched with sources, timelines, and signals.

Red Heron-linked wp2shell campaign targeting high-value entities

Campaign
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

A Chinese-speaking threat actor tied to Red Heron is running a wp2shell campaign that has breached at least 49 organizations in 29 countries, expanding the risk of credential theft and government data exposure. The operation began in early June 2026 and used the same IP address for scans and attacks. It targeted high-value entities and combined exploitation with post-access recon and credential abuse. The campaign matters because it shows a coordinated, cross-border intrusion effort rather than isolated scanning.

Related Happenings

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Timeline

  1. 22.09.2026 23:35 1 articles · 0h ago

    Red Heron-linked wp2shell campaign targeting high-value entities

    Initial Disclosure

    In early June 2026, the actor’s same-IP scans and attacks began against high-value entities, establishing a cross-border campaign that would later expand to additional targets and technologies.

    Show sources
  2. 22.09.2026 23:35 1 articles · 0h ago

    ZyXEL GS1900 switches exploited on August 17

    Exploitation Observed

    On August 17, a Chinese-speaking threat actor exploited CVE-2026-7273 in ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and extracting device configurations, network information, and hashed root-level credentials.

    Show sources