Suspected Chinese actor breaches Philippine nuclear and naval entities via known flaws

This digest was compiled by AI from multiple sources — links to the originals are below.
A suspected Chinese-speaking operator breached a Philippine nuclear research body and a marine engineering firm supporting the Philippine Navy, exploiting known vulnerabilities in ownCloud and LiteSpeed Cache. The intrusions exposed databases on nuclear reactor components, fuel inventories, and strategic plans. The attacker's identity remains unconfirmed despite logs written in Simplified Chinese.
Key Facts
- The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to access the Philippine nuclear research body's systems.
- A Philippine marine engineering company supporting the Navy was compromised via CVE-2024-28000, a privilege-escalation flaw in the LiteSpeed Cache WordPress plugin.
- Stolen data included databases on nuclear reactor components, fuel inventories, radiation safety documents, strategic plans, IT documents, and personal information from Philippine officials.
- Hunt.io discovered an exposed server containing attack scripts, logs written in Simplified Chinese, and custom Python scripts.
Intrusion Methods
The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to gain unauthenticated access to the nuclear research body's systems. This flaw allowed retrieval of files including databases on nuclear reactor components, fuel inventories, and radiation safety documents. The marine engineering company was compromised through CVE-2024-28000, a privilege-escalation vulnerability in the LiteSpeed Cache WordPress plugin. Exploiting this flaw enabled the attacker to create an administrator account without authentication.
Stolen Data and Evidence
The stolen data included strategic plans, IT documents, and personal information from Philippine officials. An exposed server contained evidence of the intrusions, including custom Python scripts and logs written in Simplified Chinese. Hunt.io uncovered the server, and Security Affairs provided further coverage of the incident.
Attribution and Risk
The language of the logs suggests a Chinese-speaking operator, but no direct link to a specific government or threat group has been confirmed. The incident highlights the continued risk posed by unpatched, known vulnerabilities to critical infrastructure and defense targets.