TI Mindmap HUB
Threat Intelligence Report

Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation

📅 September 21, 2026 📰 www.greynoise.io 🔍 6 CVE(s) referenced

A sophisticated threat actor, suspected to be a Chinese-speaking individual or group, leveraged novel WordPress and ZyXEL exploits—potentially developed with AI assistance—to steal over 18,000 sensitive government records and compromise nearly a thousand network devices across 48 countries.

unclassified
CVE-2026-63030, CVE-2026-34908, CVE-2026-34910, CVE-2026-34909, CVE-2026-60137, CVE-2026-7273

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle