Incident
Published 2026-09-21
Verified 2026-09-22

GreyNoise: Kapibala actor uses WordPress wp2shell (CVE-2026-63030 / CVE-2026-60137) → 18,566 gov records stolen; also Zyxel GS1900 mass targeting

GreyNoise (Andrew Thompson, Mark Mager; 21 September 2026) tracks a suspected Chinese-speaking malicious cyber actor (“Kapibala” tooling) that from ~20 July 2026 exploited the WordPress wp2shell chain CVE-2026-63030 and CVE-2026-60137 against ≥49 organisations in 29 countries (SMB and government). In the most serious observed intrusion against a western government victim, the actor deployed a custom webshell/plugin, created a hidden admin, harvested credentials, pivoted to an internal SQL server, and downloaded ≥18,566 records including accounts, plaintext passwords, and PII tied to law enforcement/government agencies (timeline on 22 July 2026). GreyNoise also observed the same actor targeting Zyxel GS1900 switches (996 devices / 48 countries compromised or had sensitive data exfiltrated) — related desk context: cve-2026-7273 KEV card. Distinct from wordpress-click2shell-20260918 / Comment2Shell (different flaw family). Primary: GreyNoise blog; wire: Cyber Security News 22 Sep 2026.

Product
WordPress (wp2shell CVE-2026-63030 / CVE-2026-60137); Kapibala webshell/plugin; also Zyxel GS1900 targeting by same MCA
Versions
WordPress installs vulnerable to wp2shell chain (CVE-2026-63030 / CVE-2026-60137) as exploited from ~20 Jul 2026 per GreyNoise
Exploited in Australia?
unknown
Patch to
Patch WordPress / remove wp2shell exposure; hunt kapibala_plugin / unexpected admin users and webshells under wp-content/plugins; rotate DB and admin credentials; review Zyxel GS1900 exposure (see cve-2026-7273); monitor GreyNoise IoCs when published

Primary: GreyNoise — Open Season on Kapibala / WordPress wp2shell gov theft (21 Sep 2026) · Vendor: GreyNoise Threat Signals — Kapibala · CVE: CVE-2026-63030, CVE-2026-60137, CVE-2026-7273 · Cyber Security News — WordPress flaws / 18,566 records amplify (22 Sep 2026)

breaches cloud network