decrypted · 22 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security
Zyxel switches, a five-week campaign, and the passwords nobody changed
A Chinese-speaking crew has spent five weeks quietly walking into network switches through a web page nobody designed with strangers in mind, and CISA is now giving US federal agencies until Thursday to lock the door. The vulnerability, CVE-2026-7273, sits in Zyxel's GS1900 series of smart managed switches: the workgroup-level box that lives in a comms cupboard at a branch office, school or small business, switching traffic quietly in the background and rarely getting touched once it is racked.
How a switch became a front door
The flaw is a stack-based buffer overflow in the switch's web management CGI script. Send it a deliberately oversized, crafted HTTP request and the fixed-size buffer it expects to hold gets overwritten, along with the instructions the program was about to execute next. No login is required, and the flaw carries a CVSS score of 8.8. Think of it as a reception desk built to check ID before letting anyone through to the server room, except the check-in form itself has a fault: hand over a name field a few characters too long and you walk straight past the desk. Zyxel patched the flaw in June. CISA added it to its Known Exploited Vulnerabilities catalogue on 21 September, giving federal agencies until 24 September to patch or disconnect.
What the attackers actually did
GreyNoise traced exploitation back to on or about 17 August: a Chinese-speaking threat actor already linked to earlier WordPress and Gitea campaigns ran a Python exploit script, obfuscated with the commercial tool PyArmor, against unpatched GS1900 switches. Once in, it used TFTP to pull down a custom collector and harvest each switch's configuration, network details and hashed root credentials. By the time GreyNoise counted, 996 switches across 48 countries had been compromised, concentrated in Italy, the United States, Taiwan, South Korea and several EU states. The detail worth sitting with: 564 of those 996, well over half, were still running Zyxel's factory default credentials. For those devices, the buffer overflow was almost superfluous.
The design lesson
Two failures stack here, and only one of them needed a patch. The overflow is Zyxel's to fix, and it has. The default credentials are the harder problem, because they are a design choice repeated across an entire product category: ship a device with a known, unchanged password and you are pre-authenticating every attacker who finds it. Secure by Design's answer is to make unique-per-device credentials, or forced rotation on first login, the default rather than an option in a manual nobody reads. For UK organisations, the practical task is less glamorous than patch management: know which switches, routers and access points on the network were racked and forgotten years ago, confirm their management interfaces are not reachable from anywhere they do not need to be, and check nobody left the sticker password in place. It is exactly the estate that the Cyber Security and Resilience Bill wants managed service providers to start being accountable for.
Also this week
Sovereign AI for security teams. Aikido Security released Altar-1 this week, an open-weight AI model for defensive security work built to run entirely inside an organisation's own infrastructure rather than call out to a third-party cloud API. Pruned down from Z.AI's GLM-5.3 to around 328GB and served on-premises, it is aimed at organisations with genuine data-residency reasons to keep vulnerability scanning and penetration-testing traffic in-house: banks, healthcare providers, and industrial sites running air-gapped operational technology. It will not suit most UK organisations' day-to-day needs, but it is a useful marker of where sovereignty concerns are heading in security tooling specifically: not every defensive AI product needs to see your source code to be useful.
The unglamorous machinery of UK cyber policy. DCMS, which absorbed the cyber security brief from DSIT in July, published its September newsletter this week. Over 140 businesses have now signed the Cyber Resilience Pledge, committing to board-level ownership of cyber risk, registration for the NCSC's Early Warning service, and Cyber Essentials requirements across their own supply chains. Cyber Essentials issuance hit a record 61,430 certificates in the year to 30 June. The UK also joined a G7-endorsed call to begin migrating to post-quantum cryptography, and the Cyber Security and Resilience Bill has cleared Lords committee stage, still without the AI vendor scope some peers wanted added. None of it is dramatic, but it is the machinery UK organisations will eventually be measured against.
Sources
- Zyxel security advisory: stack-based buffer overflow in GS1900 series switches
- CISA orders feds to patch Zyxel flaw exploited for data theft
- Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
- Aikido Security Unveils Altar-1 Open-Weight AI for Cybersecurity Defense
- DCMS cyber security newsletter - September 2026
If your network still has kit nobody's looked at since it was racked, get in touch and we'll help you find it.
More like this
- Codex's sandbox escapes: the guard was inside the cell 20 september 2026
- An AI agent hacked a company on its own, and the UK already wrote the fix 18 september 2026
- Cisco's network gatekeeper let attackers in without a login 17 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.