A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity to a malicious cyber actor (MCA) it has tracked through its Global Observation Grid since early June. The […] The post Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/wordpress-vulnerability-exploitation/
![]()

