type: cve ยท created: 2026-08-29 ยท updated: 2026-08-29 ยท tags: [cve, liteloader, privilege-escalation, exploit-lite] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, defence] ยท au_impact: true
CVE-2024-28000
CVE-2024-28000 is a privilege-escalation vulnerability in the LiteSpeed Cache WordPress plugin. In the August 2026 context it was one of two years-old, known flaws weaponised by a suspected Chinese-speaking espionage operator against Philippine targets โ alongside the ownCloud authentication bypass CVE-2023-49105.
| Attribute | Detail |
|---|---|
| CVE | CVE-2024-28000 |
| Type | Privilege escalation |
| Product | LiteSpeed Cache (WordPress plugin) |
| Exploitation case | Weaponised against Philippine nuclear research agency + marine engineering/shipbuilding contractor (Aug 2026) |
| Notable | Years-old, previously patched flaw โ used as an illustration of the supply-chain/patch-lag problem |
| Source | Hunt.io (via digest) โ Tier 2/4 |
The Philippine campaigns exfiltrated nuclear-material accounts, research-reactor core-component databases, personnel records and encrypted credential stores (KeePass, BitLocker recovery keys). Hunt.io recovered ~9 GB of nuclear-agency data staged on an exposed attacker server. The reuse of a known, older CVE underscores that unpatched legacy flaws remain a first-order espionage vector.