news.mlab.sh
Back to the feed
threat-intel

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

CriticalCVSS 9.8
Summary

A Chinese-speaking threat actor exploited unpatched vulnerabilities in ownCloud and the LiteSpeed Cache WordPress plugin to gain access to a Philippines nuclear agency and a naval contractor. The attackers exfiltrated a significant amount of sensitive data, including reactor databases, personnel records, and credentials, highlighting a growing cyber risk in the Philippines due to geopolitical tensions and the exploitation of long-standing vulnerabilities. The incident underscores the importance of patching internet-facing collaboration software and securing default configurations.

A Chinese-speaking threat actor exploited unpatched vulnerabilities in ownCloud and the LiteSpeed Cache WordPress plugin to gain initial access to a Philippines nuclear agency and a marine engineering and shipbuilding company serving the Philippine Navy. The attackers leveraged CVE-2023-49105 (ownCloud) and CVE-2024-2800 (LiteSpeed Cache WordPress plugin), both of which were disclosed and patched over two years prior.

Researchers from threat hunting platform Hunt.io discovered a hub for the attackers in an ownCloud server hosted in Amsterdam, containing offensive tools and stolen data, totaling nearly 1.2 GB. The data included a spreadsheet documenting a far wider impact – approximately 9 GB of data had been exfiltrated from the nuclear agency but moved off the server.

The recovered material included reactor core-component databases, historical fuel inventories, radiation safety manuals, authorized user lists, and personnel data, including resumes, passport documents, foreign travel records, and Philippine government financial disclosures (SALN forms). The incident also revealed potential vulnerabilities for the naval contractor, with the stolen material providing a technical blueprint of the facility.

While Hunt.io couldn't confirm the full extent of the exfiltration, the data strongly suggests a broader breach. The attackers’ use of Chinese language and the strategic value of the stolen information point to a likely Chinese threat actor, though Hunt.io refrained from identifying a specific nation-state group due to the potential for disinformation.

The Philippines is experiencing a surge in breach incidents, nearly tripling in the first half of 2026 compared to the same period in 2025, according to a Viettel Security report. This increase is partly driven by geopolitical tensions between China and countries claiming territory in the South China Sea.

To mitigate the risk, Hunt.io recommends hardening systems by patching internet-facing collaboration software (especially WordPress sites), configuring hardware with minimum permissions and secure defaults, and implementing multi-factor authentication and strong passwords on administrative accounts. They also advise monitoring for patterns like pre-signed URL abuse and directory enumeration.

Read the full article at Dark Reading