Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploit ZyXEL Switch Vulnerability

Chinese Hackers Exploit ZyXEL Switch Vulnerability

Posted on September 22, 2026 By CWS

A recent cybersecurity incident has highlighted vulnerabilities in ZyXEL GS1900 switches, exploited by a Chinese hacking group for extracting sensitive data globally. This critical security issue, identified as CVE-2026-7273, poses a significant threat, according to the threat intelligence firm GreyNoise.

Details of the Vulnerability

The flaw, marked with a CVSS score of 8.8, is a stack-based buffer overflow vulnerability that attackers can exploit without requiring authentication. By sending specially crafted HTTP requests, hackers can execute OS commands on affected devices. ZyXEL addressed this issue by releasing security updates for ten models of the GS1900 switches in June.

Despite these patches, GreyNoise reported that a Chinese hacking collective exploited the vulnerability in August, targeting ZyXEL devices across 48 countries. The malicious actors used an obfuscated Python script to steal crucial information such as hashed root credentials and network configurations from nearly 1,000 compromised devices.

Targeted Firmware and Exploitation Details

The attackers directed their efforts specifically at firmware versions 2.10-2.90 of the GS1900-24 model, although their script allowed for adaptability to other versions affected by the vulnerability. Alarmingly, 564 devices still utilized factory default credentials, making them easy targets for future breaches.

In response to this threat, the US Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-7273 in its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have been urged to apply patches within a three-day window, in compliance with directive BOD 26-04.

Broader Implications and Additional Attacks

The same hacking group was previously observed leveraging a series of Ubiquiti vulnerabilities to achieve remote code execution, as well as exploiting WordPress installations in attacks conducted in July. These attacks primarily targeted small businesses and government entities, with one significant breach involving over 18,000 sensitive records from a western governmental organization.

GreyNoise suggests that the responsible hackers may be associated with the Red Heron group, known for exploiting vulnerabilities in Gitea and targeting numerous systems globally. The unfolding situation underscores the critical need for organizations to update their systems and remain vigilant against cybersecurity threats.

As the cybersecurity landscape evolves, staying informed and proactive in patching vulnerabilities is crucial for safeguarding sensitive information and maintaining network integrity.

Security Week News Tags:Chinese hackers, CISA, CVE-2026-7273, Cybersecurity, data breach, GreyNoise, network security, RCE, Red Heron, security patch, threat actor, Ubiquiti vulnerabilities, Vulnerability, WordPress, Zyxel

Post navigation

Previous Post: Critical Vulnerability in VeloCloud Orchestrator Exploited
Next Post: Critical ARM64 Linux Vulnerability Exposes Hosts

Related Posts

Creating Realistic Deepfakes Is Getting Easier Than Ever. Fighting Back May Take Even More AI Creating Realistic Deepfakes Is Getting Easier Than Ever. Fighting Back May Take Even More AI Security Week News
Socket Secures  Million, Reaches  Billion Valuation Socket Secures $60 Million, Reaches $1 Billion Valuation Security Week News
Cybersecurity M&A Roundup: 44 Deals Announced in July 2025 Cybersecurity M&A Roundup: 44 Deals Announced in July 2025 Security Week News
Cisco Routers Hacked for Rootkit Deployment Cisco Routers Hacked for Rootkit Deployment Security Week News
OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity Security Week News
TransUnion Data Breach Impacts 4.4 Million TransUnion Data Breach Impacts 4.4 Million Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation
  • Critical Linux Kernel Bug Threatens ARM64 Systems
  • Critical ARM64 Linux Vulnerability Exposes Hosts
  • Chinese Hackers Exploit ZyXEL Switch Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation
  • Critical Linux Kernel Bug Threatens ARM64 Systems
  • Critical ARM64 Linux Vulnerability Exposes Hosts
  • Chinese Hackers Exploit ZyXEL Switch Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark