Chinese Operator Breaches Philippine Nuclear and Naval Entities

Chinese Operator Breaches Philippine Nuclear and Naval Entities

First seen 31 Aug 2026, 12:53 UTC Securityaffairs.CoPasqualepillitteri.Ithunt.ioScworldDarkreading+1 80.7

Article Content

Browse articles
ThreatCluster

A suspected Chinese-speaking operator has compromised a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy by exploiting known vulnerabilities. The attacker utilized CVE-2023-49105, an authentication-bypass flaw in ownCloud, allowing unauthorized access to sensitive files, including nuclear material registries and personal information of officials. Additionally, CVE-2024-28000 was exploited in the WordPress site of the marine engineering company. Hunt.io discovered an exposed server containing attack scripts and logs, indicating a significant data breach. The stolen data is estimated to be around 9 GB, with critical documents related to nuclear safety and operational plans. The incident highlights the ongoing cyber threats to critical infrastructure in the Philippines amidst rising geopolitical tensions. The attack was reported on August 31, 2026, after a responsible disclosure process by Hunt.io.

Key Points: • Over 14,000 Dahua cameras compromised in related incidents. • CVE-2023-49105 exploited for unauthorized access to sensitive nuclear data. • Estimated 9 GB of sensitive data stolen, including personal information of officials.

Ask AI about this cluster

Timeline

2023-11-21
CVE-2023-49105 published
Authentication-bypass flaw in ownCloud allows unauthorized file access via WebDAV.
Article 2
2024-08-21
CVE-2024-28000 published
Privilege-escalation flaw in LiteSpeed Cache WordPress plugin allows unauthorized admin access.
Article 3
2026-08-13
Open server discovered
Hunt.io identified an exposed server containing attack scripts and stolen data from two Philippine organizations.
Article 1
2026-08-27
CVE-2023-49105 added to CISA KEV
CISA listed CVE-2023-49105 as actively exploited, highlighting the urgency of patching.
Article 3
2026-08-31
Breach reported
Hunt.io published findings on the breach of Philippine nuclear and naval entities, detailing the attack methods and data stolen.
Article 1