Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploit ZyXEL Switch Vulnerability

Chinese Hackers Exploit ZyXEL Switch Vulnerability

Posted on September 22, 2026 By CWS

A recent cybersecurity incident has highlighted vulnerabilities in ZyXEL GS1900 switches, exploited by a Chinese hacking group for extracting sensitive data globally. This critical security issue, identified as CVE-2026-7273, poses a significant threat, according to the threat intelligence firm GreyNoise.

Details of the Vulnerability

The flaw, marked with a CVSS score of 8.8, is a stack-based buffer overflow vulnerability that attackers can exploit without requiring authentication. By sending specially crafted HTTP requests, hackers can execute OS commands on affected devices. ZyXEL addressed this issue by releasing security updates for ten models of the GS1900 switches in June.

Despite these patches, GreyNoise reported that a Chinese hacking collective exploited the vulnerability in August, targeting ZyXEL devices across 48 countries. The malicious actors used an obfuscated Python script to steal crucial information such as hashed root credentials and network configurations from nearly 1,000 compromised devices.

Targeted Firmware and Exploitation Details

The attackers directed their efforts specifically at firmware versions 2.10-2.90 of the GS1900-24 model, although their script allowed for adaptability to other versions affected by the vulnerability. Alarmingly, 564 devices still utilized factory default credentials, making them easy targets for future breaches.

In response to this threat, the US Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-7273 in its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have been urged to apply patches within a three-day window, in compliance with directive BOD 26-04.

Broader Implications and Additional Attacks

The same hacking group was previously observed leveraging a series of Ubiquiti vulnerabilities to achieve remote code execution, as well as exploiting WordPress installations in attacks conducted in July. These attacks primarily targeted small businesses and government entities, with one significant breach involving over 18,000 sensitive records from a western governmental organization.

GreyNoise suggests that the responsible hackers may be associated with the Red Heron group, known for exploiting vulnerabilities in Gitea and targeting numerous systems globally. The unfolding situation underscores the critical need for organizations to update their systems and remain vigilant against cybersecurity threats.

As the cybersecurity landscape evolves, staying informed and proactive in patching vulnerabilities is crucial for safeguarding sensitive information and maintaining network integrity.

Security Week News Tags:Chinese hackers, CISA, CVE-2026-7273, Cybersecurity, data breach, GreyNoise, network security, RCE, Red Heron, security patch, threat actor, Ubiquiti vulnerabilities, Vulnerability, WordPress, Zyxel

Post navigation

Previous Post: Critical Vulnerability in VeloCloud Orchestrator Exploited
Next Post: Critical ARM64 Linux Vulnerability Exposes Hosts

Related Posts

Vulnerabilities in Xerox Print Orchestration Product Allow Remote Code Execution Vulnerabilities in Xerox Print Orchestration Product Allow Remote Code Execution Security Week News
Men Who Hacked Law Enforcement Database for Doxing Sentenced to Prison Men Who Hacked Law Enforcement Database for Doxing Sentenced to Prison Security Week News
GitHub Vulnerability Exposes Private Data to Attacks GitHub Vulnerability Exposes Private Data to Attacks Security Week News
Medusa Ransomware Exploits Vulnerabilities Rapidly Medusa Ransomware Exploits Vulnerabilities Rapidly Security Week News
New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  Security Week News
Forget Predictions: True 2026 Cybersecurity Priorities From Leaders Forget Predictions: True 2026 Cybersecurity Priorities From Leaders Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark