← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 22, 2026 · 09:39via CyberInsider

WordPress “wp2shell” attacks stole 18,000 government records

Brief

A suspected Chinese-speaking threat actor exploited WordPress vulnerabilities to breach dozens of organizations worldwide, stealing more than 18,000 sensitive records from one Western government agency. GreyNoise researchers tracked the attacker through the company’s Global Observation Grid (GOG), a network of internet-facing sensors designed to attract scanning and exploitation attempts.

GreyNoise says it has monitored malicious …

The post WordPress “wp2shell” attacks stole 18,000 government records appeared first on CyberInsider .

Read more on CyberInsider→