A Chinese threat actor has targeted vulnerable Zyxel GS1900 switches worldwide for sensitive-information exfiltration, SecurityWeek reported. The activity follows reporting on active exploitation of a flaw affecting the switch line.

Network defenders should inventory affected switches, apply Zyxel’s security guidance, restrict management interfaces to trusted networks, and preserve relevant device and network logs before remediation where compromise is suspected.

Source: SecurityWeek.

By Allan