Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploiting Vulnerabilities in the Philippines: A Chinese-Speaking Actor's Attack on Nuclear and Naval Targets




A suspected Chinese-speaking operator has carried out a cyber attack on Philippine nuclear and naval targets, exploiting known vulnerabilities in ownCloud and WordPress systems to gain access to sensitive data. The attack highlights the importance of upgrading to the latest versions of software, applying vendor-relevant fixes, and improving cybersecurity infrastructure and training. The incident also raises concerns about the increasing sophistication of state-sponsored hacking operations and the need for international cooperation in addressing this threat.

  • The recent cyber attack on Philippine nuclear and naval targets was carried out by a suspected Chinese-speaking operator.
  • The attack exploited known vulnerabilities in ownCloud and WordPress systems to gain access to sensitive data.
  • The attack was uncovered by Hunt.io, a security firm that specializes in identifying and analyzing cyber threats.
  • The main entry point for the attack was the nuclear research body's internet-facing ownCloud service.
  • The attack also targeted a WordPress site operated by the marine engineering company, exploiting a privilege-escalation flaw in the LiteSpeed Cache plugin.
  • The attack highlights the need for organizations to upgrade to the latest versions of software and apply vendor-relevant fixes.
  • The incident raises concerns about the increasing sophistication of state-sponsored hacking operations.
  • The Philippine government has been criticized for its lack of cybersecurity measures, and this attack highlights the need for improved cybersecurity infrastructure and training.
  • The attack underscores the importance of international cooperation in addressing the threat of state-sponsored hacking.



  • A recent cyber attack on Philippine nuclear and naval targets has raised concerns about the increasing threat of state-sponsored hacking. The attack, which was carried out by a suspected Chinese-speaking operator, exploited known vulnerabilities in internet-facing ownCloud and WordPress systems to gain access to sensitive data.

    The attack was uncovered by Hunt.io, a security firm that specializes in identifying and analyzing cyber threats. According to Hunt.io, the attacker used a combination of custom Python scripts, logs, and stolen files to breach the systems of a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy.

    The main entry point for the attack was the nuclear research body's internet-facing ownCloud service, which was compromised by exploiting the CVE-2023-49105 authentication-bypass flaw. The attacker was able to generate WebDAV requests that were accepted by the server as if they were made by a valid username, without ever supplying credentials.

    The attack also targeted a WordPress site operated by the marine engineering company, exploiting the CVE-2024-28000 privilege-escalation flaw in the LiteSpeed Cache WordPress plugin. The attacker was able to create a WordPress admin account without authentication by exploiting a predictable security hash through the REST API.

    In addition to the stolen data, which included nuclear reactor component databases, fuel inventories, and strategic plans, the attacker also left behind evidence of a breach involving the marine engineering company. The company's systems were compromised by exploiting the same vulnerability in the LiteSpeed Cache plugin.

    The attack highlights the importance of upgrading to the latest versions of software and applying vendor-relevant fixes to prevent similar breaches. It also emphasizes the need for organizations to examine WebDAV logs for suspicious PROPFIND directory-enumeration requests, large volumes of file retrieval across multiple accounts, or recurring requests from a single source with artificial gaps between them.

    The incident also raises concerns about the increasing sophistication of state-sponsored hacking operations. The attacker used a combination of custom Python scripts, logs, and stolen files to breach the systems of the two organizations, suggesting a high level of planning and expertise.

    The Philippine government has been criticized in the past for its lack of cybersecurity measures, and this attack highlights the need for improved cybersecurity infrastructure and training. The incident also underscores the importance of international cooperation in addressing the threat of state-sponsored hacking.

    In conclusion, the recent cyber attack on Philippine nuclear and naval targets is a sobering reminder of the increasing threat of state-sponsored hacking. The attack highlights the importance of upgrading to the latest versions of software, applying vendor-relevant fixes, and improving cybersecurity infrastructure and training. It also underscores the need for international cooperation in addressing this threat.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploiting-Vulnerabilities-in-the-Philippines-A-Chinese-Speaking-Actors-Attack-on-Nuclear-and-Naval-Targets-ehn.shtml

  • https://securityaffairs.com/198041/intelligence/philippine-nuclear-and-naval-targets-hit-by-suspected-chinese-operator.html

  • https://nvd.nist.gov/vuln/detail/CVE-2023-49105

  • https://www.cvedetails.com/cve/CVE-2023-49105/

  • https://nvd.nist.gov/vuln/detail/CVE-2024-28000

  • https://www.cvedetails.com/cve/CVE-2024-28000/


  • Published: Sat Aug 29 22:50:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us