Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitLab Patches Critical AI Agent Flaw Allowing Code Execution
August 27, 2026
CISA Warns of Critical Citrix NetScaler ADC, Gateway CVE-2023-3519 N-Day Exploits
August 27, 2026
Stolen SSNs of Corporate Execs Sold for 25 Cents on Dark Web
August 27, 2026
Home/Threats/Critical ownCloud and WordPress Flaws Exploited to Steal Philippine Naval Data
Threats

Critical ownCloud and WordPress Flaws Exploited to Steal Philippine Naval Data

Key Takeaways A suspected Chinese-speaking threat actor leveraged known vulnerabilities in ownCloud and WordPress to exfiltrate sensitive data from a Philippine nuclear research agency and a naval...

Jennifer sherman
Jennifer sherman
August 27, 2026 4 Min Read
8 0

Key Takeaways

  • A suspected Chinese-speaking threat actor leveraged known vulnerabilities in ownCloud and WordPress to exfiltrate sensitive data from a Philippine nuclear research agency and a naval contractor.
  • The stolen information includes critical nuclear reactor data, staff records, financial documents, and a complete archive of the naval contractor’s website.
  • The attacks exploited CVE-2023-49105 in ownCloud (CVSS score 9.8, critical) and CVE-2024-28000 in the LiteSpeed Cache WordPress plugin.
  • The incident highlights the severe risks posed by unpatched, internet-facing systems, particularly those holding national security-related data.
  • Both ownCloud and WordPress users should apply immediate patches and implement robust security measures to prevent similar breaches.

A sophisticated cyber operation, attributed to a suspected Chinese-speaking individual or group, has successfully compromised a Philippine nuclear research facility and a marine engineering firm contracted by the Philippine Navy. The attackers exploited critical, known vulnerabilities in ownCloud and WordPress platforms to extract a significant volume of sensitive data, underscoring the persistent threat posed by unpatched systems.

Table Of Content

  • Key Takeaways
  • Exploiting ownCloud and WordPress Vulnerabilities
  • Nuclear Agency Compromised via ownCloud Flaw
  • Naval Contractor Breached Through WordPress Vulnerability

This intrusion came to light following the discovery of an openly accessible server containing the attacker’s tools, logs of data transfers, and a portion of the exfiltrated files. The compromised data reportedly encompasses highly sensitive information, including documents related to nuclear reactor operations, personnel records, strategic planning materials, encrypted credential stores, and a full backup of the naval contractor’s WordPress site. Further details are available in this report.

Security researchers at Hunt.io discovered the exposed server on August 13 and subsequently linked the scripts found on it to the attacks targeting the two Philippine entities. While Hunt.io did not name a specific threat group, Hunt.io said in a report that the evidence points to a Chinese-speaking operator.

The scale of the data exfiltration is considerable. An inventory found on the server indicated approximately 9 GB of data was stolen from the nuclear agency. Researchers were able to directly recover 176 files, totaling about 372 MB, from five separate staging folders. This discrepancy suggests that the publicly accessible server likely contained only a fraction of the total data collected by the attackers.

Exploiting ownCloud and WordPress Vulnerabilities

Nuclear Agency Compromised via ownCloud Flaw

The attackers gained unauthorized access to the nuclear agency’s self-hosted ownCloud service by exploiting CVE-2023-49105, a critical authentication bypass vulnerability (CVSS score 9.8). This flaw exists in the platform’s pre-signed link feature. On ownCloud installations where a signing key is not configured, attackers can craft valid WebDAV requests for known usernames without needing to provide a password.

The attackers utilized five custom Python scripts to systematically download files, account by account. These scripts also leveraged WebDAV directory requests to map out folder structures and incorporated brief, random pauses between downloads. This methodical approach was likely designed to evade detection by making the data transfer appear less suspicious and more like routine activity.

The exfiltrated data from the nuclear agency included highly sensitive information such as databases related to research-reactor core components, fuel inventory records, radiation safety protocols, incident reports, staff resumes, travel documents, and financial disclosures. Furthermore, investigators found a KeePass database, AxCrypt-encrypted files, and a PDF containing a BitLocker recovery key, all of which could facilitate future access or decrypt additional sensitive information. The stolen files were meticulously organized into folders labeled in simplified Chinese, categorized by areas such as finance, radiation safety, nuclear material accounts, and IT planning.

Naval Contractor Breached Through WordPress Vulnerability

The second victim, a Philippine marine engineering and shipbuilding company with ties to naval services, was compromised through a vulnerability in its WordPress installation. The attackers exploited CVE-2024-28000, a flaw in the LiteSpeed Cache plugin affecting versions prior to 6.4. This allowed them to create a new administrator account via the WordPress REST API after successfully deriving the plugin’s security hash.

Analysis of logs revealed that the exploit process ran for nearly three hours and 45 minutes before a valid hash was found and the rogue administrator account was created. In parallel, the attackers targeted the site’s XML-RPC interface, attempting password guesses against the administrative account, eventually recording a successful credential pair in a separate output file.

The attackers staged three archives from the naval contractor’s site, totaling 195 MB. These included the complete WordPress installation, a database dump, and the media library. Such comprehensive data can expose critical information like password hashes, plugin configurations, and site secrets. The establishment of a rogue administrator account also provides a persistent backdoor for future unauthorized access. This incident highlights the ongoing risk of rogue WordPress admin accounts.

Separately, researchers identified an active EtherHiding-style compromise on the same WordPress site, though evidence did not link it to the current operator. This additional compromise utilized a fake verification page to deliver malware and a service worker for persistence, illustrating how a single compromised site can host multiple, unrelated threats. This aligns with broader trends where <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/286837fb-df95-49a7-9c7c-d4dba34898d5/Hackers-Exploit-ownCloud-and-WordPress-Flaws-to-Steal-Philippine-Nuclear-and-Naval-Data.pdf?AWSAccessKeyId=ASIA2F3EMEYE6ZOFWJPY&Signature=GOvV86daqyCtGKlIj7%2BkfjmAfY

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitHackerMalwarePatchSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency

Next Post

AWS Details How Stolen Cloud Credentials Lead to Full-Scale Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Two Australians Charged for TeamPCP Supply Chain Attacks
August 27, 2026
Critical TeamViewer Flaws Allow Remote Code Execution
August 27, 2026
AWS Details How Stolen Cloud Credentials Lead to Full-Scale Attacks
August 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us