<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WordPress (&lt; Latest Patched Version) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wordpress--latest-patched-version/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 13:50:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wordpress--latest-patched-version/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>WordPress Exploitation and Data Exfiltration by Red Heron Affiliate</title><link>https://feed.craftedsignal.io/briefs/2026-09-kapibala-wordpress-exploitation/</link><pubDate>Mon, 21 Sep 2026 13:50:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-kapibala-wordpress-exploitation/</guid><description>An adversary linked to the Red Heron group is exploiting multiple vulnerabilities in WordPress, Ubiquiti, and ZyXEL devices to conduct reconnaissance, gain persistence, and exfiltrate sensitive records, including over 18,000 government documents.</description><content:encoded><![CDATA[<p>GreyNoise has identified a cyber actor associated with the &quot;Red Heron&quot; group exploiting a range of edge technologies since mid-2026. The actor leverages custom tools, suspected to be generated via large language models (LLMs), to perform rapid, multi-stage attacks. The primary objective observed is the theft of sensitive data, culminating in the exfiltration of over 18,000 records from a western government entity. The actor demonstrates sophistication in blending into target environments, such as backdating illegitimate administrative accounts and utilizing custom WordPress plugins for environment enumeration. Key targeted technologies include WordPress (CVE-2026-63030, CVE-2026-60137), Ubiquiti UniFi OS (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910), and ZyXEL GS1900 switches (CVE-2026-7273). The actor's tradecraft involves staging backdoors on compromised infrastructure and using AMSI-bypass techniques on Windows hosts to maintain persistence and escalate privileges.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Access: Adversary uses a custom exploit chain (CVE-2026-63030 and CVE-2026-60137) to gain unauthenticated access to WordPress installations.</li>
<li>Persistence: Attacker creates a new administrative user, masquerading as a legitimate email address, and modifies metadata to blend into site history.</li>
<li>Reconnaissance: Attacker uploads a custom information collection plugin to enumerate the WordPress database and filesystem.</li>
<li>Tooling: Webshells are deployed to conduct command execution, enabling the adversary to run reconnaissance commands such as <code>net user</code> and <code>appcmd.exe list site</code>.</li>
<li>Evasion: Attacker utilizes custom scripts to attempt bypasses of Microsoft Antimalware Scan Interface (AMSI) and checks for installed security products.</li>
<li>Exfiltration: Attacker queries database configuration files (<code>wp-config.php</code>) to extract credentials and subsequently dumps sensitive backend database records.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign has impacted at least 49 organizations across 29 countries, primarily targeting small business and governmental sectors. Notably, 996 ZyXEL switches were compromised globally, and over 18,000 sensitive government records were stolen from a single western governmental organization.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch WordPress installations against CVE-2026-63030 and CVE-2026-60137 immediately.</li>
<li>Audit WordPress administrator accounts for suspicious entries, specifically focusing on account creation dates that do not match the expected user lifecycle.</li>
<li>Search for unauthorized account additions and custom plugins uploaded to <code>wp-content/plugins/</code> directories.</li>
<li>Monitor network traffic for connections to the C2 domain <code>p3.981666.xyz</code> and the staging server <code>74.48.66.73</code>.</li>
<li>Deploy Sigma rules to detect suspicious <code>powershell</code> and <code>cmd</code> execution patterns observed in the brief, specifically commands querying <code>wp-config.php</code> or <code>Get-MpComputerStatus</code>.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>wordpress</category><category>data-theft</category><category>exfiltration</category><category>vulnerability-exploitation</category></item></channel></rss>