A suspected Chinese-speaking operator has targeted a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy, exploiting well-known vulnerabilities in internet-facing systems. The activity was uncovered after Hunt.io found an exposed server containing attack scripts, logs, and data stolen from the two organizations, with further coverage provided by Security Affairs.The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to gain access to the nuclear research body's systems. This allowed for unauthenticated retrieval of files, including databases on nuclear reactor components, fuel inventories, and radiation safety documents. Additionally, a Philippine marine engineering company supporting the Navy was compromised by exploiting CVE-2024-28000, a privilege-escalation flaw in the LiteSpeed Cache WordPress plugin, enabling the attacker to create an administrator account without authentication. The stolen data also included strategic plans, IT documents, and personal information from Philippine officials.The exposed server contained evidence of the intrusions, including custom Python scripts, logs written in Simplified Chinese, and various tools. While the language suggests a Chinese-speaking operator, no direct link to a specific government or threat group has been confirmed. The incident highlights the continued risk posed by unpatched, known vulnerabilities to critical infrastructure and defense targets.Source: Security Affairs
Threat Intelligence
Suspected Chinese actor targets Philippine nuclear and naval entities using known vulnerabilities
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
