Skip to main content
Threat Intelligence · September 22, 2026

Kapibala, Red Heron, and the Blind Spot Between Your Tools

Three unrelated products, three separate disclosures, one operational lesson: attackers don't respect your vendor categories, and neither should your monitoring.

Vijilan· 7 min read
Kapibala, Red Heron, and the Blind Spot Between Your Tools

Three Products, Three Disclosures, One Week

In the span of a few days, three attack campaigns against three completely unrelated products landed in the security press almost on top of each other. A WordPress core vulnerability. A self-hosted Git server. A network switch. None of these vendors compete with each other. None of the affected organizations necessarily share a stack. And that is exactly what makes the pattern worth stopping for.

Kapibala: WordPress core, plaintext passwords, 29 countries

A campaign researchers are tracking as Kapibala has been exploiting two WordPress core flaws, CVE-2026-63030 (nicknamed wp2shell, a critical pre-auth remote code execution bug) and CVE-2026-60137, to compromise government websites. Reporting puts the theft at more than 18,500 government records, including passwords stored in plaintext, with affected agencies spanning 29 countries. GreyNoise flagged the activity as it escalated, and the WordPress core team's own advisory partners have been pushing patch guidance since the flaw's disclosure.

Red Heron: a Gitea n-day, a new rootkit, stolen source code

A separate cluster, tracked as Red Heron and assessed by Acronis as Chinese-speaking, weaponized an n-day remote code execution flaw in Gitea, the self-hosted Git service many engineering teams run instead of a SaaS alternative. Within days of the flaw becoming public, Red Heron had compromised at least 13 organizations across six countries, deploying a previously undocumented Linux rootkit and exfiltrating source code, industrial and government targets among the victims.

And a Zyxel switch, for good measure

At the same time, CISA ordered federal agencies to patch an actively exploited Zyxel switch vulnerability, giving them until Thursday. Reporting ties the exploitation to Chinese threat actors using the flaw for data theft, on network hardware that most security teams check twice a year if that.

Is This One Actor or Three Coincidences?

Honestly: the researchers who found these haven't published a single-attribution link tying Kapibala, Red Heron, and the Zyxel activity to one operator, and we're not going to manufacture one. What we can say, because it's observable in every incident description above, is that the operational shape is identical across all three. Gain a foothold through whatever unpatched, internet-facing software is reachable. Harvest credentials. Move laterally. Persist. Exfiltrate. The product category is incidental. The playbook is not.

That's the uncomfortable part for anyone running security the traditional way, one console per product. A WordPress security plugin has no idea what's happening on your Gitea server. Gitea's audit log has no idea what your switch is doing. A switch doesn't know what your identity provider just approved. Each of these tools does exactly what it was built to do, watch its own front door, and none of them was built to notice that the same set of stolen credentials just walked through three different doors in three different weeks.

What a Partner Should Actually Do This Week

  1. Inventory your exposure. Find every internet-facing WordPress instance and self-hosted Gitea deployment across your client base. Confirm patch status against CVE-2026-63030, CVE-2026-60137, and check firmware on Zyxel switch models named in CISA's advisory.
  2. Assume compromise, don't just assume vulnerability. If a system was exposed to any of these flaws before the patch landed, check for indicators of prior access, not just current patch status. Kapibala stole plaintext passwords; Red Heron stole source code that may contain embedded secrets or tokens. Both outcomes mean rotating credentials, not just closing the CVE.
  3. Look past the entry point. The exploited product is where the story starts, not where it ends. Pull identity provider logs (Okta, Entra), EDR telemetry (CrowdStrike Falcon, SentinelOne, Defender for Endpoint), and network flow data for the days following any suspected exposure. Lateral movement and anomalous credential use are the tell, and they show up outside the product that got exploited.
  4. Stop treating edge hardware as out of scope. A switch doesn't file its own incident report. If it's not in your monitoring perimeter, it's a gap, and gaps are exactly what campaigns like these are built to find.

Where a Correlated SOC Actually Earns Its Keep

Here's the part that no single vendor's alert can do for you: catch an actor working across a dozen unrelated products, because no single vendor sees a dozen unrelated products. A WAF vendor sees WAF traffic. A Git hosting vendor sees repo activity. A switch vendor sees switch logs. None of them see the credential that got stolen on one and reused on another.

This is the case for correlation over per-tool alerting, and it's the actual job of Vijilan's Global SOC. ThreatRespond™, our Managed XDR service, ingests across the stack, CrowdStrike Falcon Next-Gen SIEM, Microsoft Sentinel and Defender, Cribl-routed logs, Corelight network sensors, identity platforms like Okta and Entra, and correlates identity and lateral-movement patterns across all of it, not just the alert queue of whichever product got hit first. When a credential that touched a compromised WordPress admin panel shows up authenticating somewhere it's never authenticated before, that's the pattern a per-product console has no way to surface, and it's the pattern our analysts are trained to chase.

When the pattern confirms, containment isn't a ticket sitting in a partner's inbox at 2 a.m. ThreatContain™ acts on anomalous credential use and lateral movement directly, isolating the session or the endpoint while the investigation continues, because the value of catching a cross-stack actor evaporates if the response still has to wait for someone to notice the ticket.

For MSSP partners, this runs white-label under your brand, our Global SOC in the background, your relationship in front. We never compete with our partners for their clients. If you're evaluating whether your current monitoring setup can actually see across the products your clients run, not just the ones you have consoles for, that conversation starts at /msp. Pricing questions go to /pricing.

Attackers already stopped organizing their work around your product categories. It might be time your monitoring did the same.

Frequently asked questions

What is Kapibala?

Kapibala is the name researchers gave to a campaign exploiting WordPress core flaws, CVE-2026-63030 and CVE-2026-60137, to steal government records, including plaintext passwords, from agencies across 29 countries.

What is Red Heron?

Red Heron is a separate cluster, assessed by Acronis as Chinese-speaking, that exploited an n-day remote code execution flaw in Gitea to compromise at least 13 organizations across six countries, deploying a new Linux rootkit and stealing source code.

Are Kapibala and Red Heron confirmed to be the same actor?

No. Researchers have not published a single attribution linking the two campaigns. The connection worth paying attention to is operational, not confirmed identity: both follow the same access-to-lateral-movement playbook across unrelated products.

Why didn't existing monitoring catch this pattern sooner?

Each affected product, WordPress, Gitea, Zyxel switches, has its own vendor telemetry with no visibility into the others. A per-product console can flag its own exploit but has no way to see that the same stolen credential is being reused across systems it doesn't monitor.

How does Vijilan address this kind of cross-product campaign?

ThreatRespond correlates logs across the full stack, including EDR, identity providers, network telemetry, and SIEM sources, so our Global SOC can identify anomalous credential use and lateral movement regardless of which product served as the entry point, and ThreatContain acts on it.

Found this useful? Send it to someone who needs it.

Threat notes, once a week

What our SOC actually saw this week: new attack patterns, the detections we shipped against them, and what it means if you run an MSP. Written by the analysts, not by marketing.

One email a week. One click to stop, and we do not sell your address to anyone.

Talk to a security expert

See what 24/7 looks like when the SOC actually acts.

Book a 20-minute platform walkthrough: no slide deck, just the console.

Book a walkthrough →