Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, espionage, confirmed-breach, government, energy, critical-infrastructure] ยท confidence: high ยท severity: critical ยท affected_sectors: [government, energy, defence] ยท au_impact: true

Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency and Navy Contractor

Summary

Threat-hunting firm Hunt.io discovered a Chinese-speaking operator's Amsterdam-based server holding offensive tools and ~1.2 GB of stolen data, including files identifying at least two victims โ€” a Philippines nuclear agency and a marine engineering/shipbuilding company serving the Philippine Navy โ€” plus a list of targeted personnel at research and science facilities.

Key Facts

  • Exploits: ownCloud CVE-2023-49105 (disclosed November 2023) and LiteSpeed Cache WordPress CVE-2024-2800 (patched August 2024), both fixed more than two years earlier.
  • Stolen material: Reactor core-component database, historical fuel inventories, radiation-safety manuals, authorised-user lists, personnel folders with resumes, passports, foreign-travel records and officials' statements-of-assets (SALN) forms, plus credentials implying a possible ~9 GB exfiltration.
  • Attribution: Hunt.io stopped short of nation-state attribution, noting Chinese-language indicators are easily planted.

Significance

The attack on a nuclear agency via unpatchable/unpatched internet-facing collaboration software is a critical-infrastructure lesson. It reinforces that unpatchable internet-facing collaboration software is a common initial-access failure, and is strategically relevant to Australia given South China Sea-adjacent critical infrastructure exposure.

Related Pages

  • Cve 2024 2800 โ€” LiteSpeed Cache WordPress plugin used in this campaign

Source