Executive Summary
In September 2026, threat actors exploited unpatched vulnerabilities in ownCloud (CVE-2023-49105) and LiteSpeed Cache WordPress plugin (CVE-2024-2800) to breach a Philippine nuclear agency and naval contractor. The attackers, likely Chinese-speaking based on code comments, exfiltrated 9GB of sensitive data including reactor databases, fuel inventories, radiation safety documents, personnel records, and credential stores. Hunt.io researchers discovered the stolen data on an Amsterdam-based server serving as an operational hub for the attackers.
This incident reflects escalating cyber threats in the Philippines amid South China Sea tensions, with breach incidents nearly tripling in the first half of 2026. The successful exploitation of vulnerabilities patched over two years ago highlights critical gaps in patch management and security fundamentals at sensitive government facilities.
Why This Matters Now
Nation-state actors are increasingly targeting critical infrastructure through basic vulnerabilities, with geopolitical tensions in the South China Sea driving sophisticated espionage campaigns against nuclear facilities and defense contractors using commodity exploits.
Attack Path Analysis
Chinese-speaking threat actors exploited unpatched ownCloud vulnerabilities (CVE-2023-49105) and WordPress LiteSpeed Cache flaws (CVE-2024-2800) to gain initial access to Philippines nuclear agency and naval contractor systems. After compromising authentication mechanisms, attackers maintained persistence and established command channels through the compromised ownCloud infrastructure. They systematically exfiltrated 9GB of sensitive data including reactor databases, fuel inventories, personnel records, and credentials to an Amsterdam-based server acting as their operational hub.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited unpatched ownCloud vulnerability CVE-2023-49105 to bypass authentication via pre-signed URL mechanism abuse, combined with WordPress LiteSpeed Cache vulnerability CVE-2024-2800 exploitation
Related CVEs
CVE-2023-49105
CVSS 9.8ownCloud allows authentication bypass in pre-signed URL mechanism enabling unauthorized access to server data.
Affected Products:
ownCloud ownCloud Server – < 10.13.1
Exploit Status:
exploited in the wildCVE-2024-2800
CVSS 7.5LiteSpeed Cache WordPress plugin contains vulnerability allowing unauthorized access and potential code execution.
Affected Products:
LiteSpeed Technologies LiteSpeed Cache WordPress Plugin – < 6.3.0.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Credentials In Files
File and Directory Discovery
Data from Local System
Exfiltration to Cloud Storage
Archive Collected Data
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Vulnerability Management
Control ID: 500.02(g)
PCI DSS 4.0 – Security Vulnerabilities
Control ID: 6.3.1
CISA Zero Trust Maturity Model 2.0 – Asset Management
Control ID: ID.AM-5
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Nuclear agencies face nation-state espionage targeting reactor databases and fuel inventories through unpatched ownCloud vulnerabilities, requiring enhanced zero trust segmentation.
Defense/Space
Naval contractors exposed to Chinese-speaking threat actors stealing shipbuilding secrets via commodity CVEs, demanding improved egress security and multicloud visibility controls.
Government Administration
Philippine government agencies experiencing tripled breach incidents with personnel records and credential stores compromised through exploited WordPress and ownCloud vulnerabilities.
Shipbuilding
Marine engineering firms serving military clients targeted for South China Sea intelligence gathering via unpatched systems requiring inline IPS protection.
Sources
- Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agencyhttps://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agencyVerified
- ownCloud Security Advisory CVE-2023-49105https://owncloud.com/security-advisories/Verified
- NVD - CVE-2023-49105 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-49105Verified
- Hunt.io Threat Research Bloghttps://hunt.io/blogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly reduced the attack blast radius by implementing network segmentation and controlled access policies. The attackers' ability to move laterally between nuclear agency and naval contractor systems would likely have been constrained through east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have limited the initial compromise scope, constraining attacker access to isolated workload boundaries rather than permitting broad network reach from the compromised web applications.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely have constrained administrative privilege scope, limiting the effectiveness of compromised credentials to specific workload boundaries rather than enabling broad system-wide access.
Control: East-West Traffic Security
Mitigation: Inter-workload traffic enforcement would likely have blocked unauthorized lateral movement between nuclear agency and naval contractor systems, constraining attackers to their initial compromise foothold rather than enabling cross-organizational access.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and traffic analysis would likely have detected anomalous communication patterns to Amsterdam infrastructure, potentially constraining persistent command channel establishment through policy-based blocking.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained large-volume data transfers to unauthorized external destinations, reducing the scope of sensitive data exfiltration through automated traffic inspection and blocking.
While sensitive nuclear facility data remained at risk, the overall organizational exposure would likely have been reduced to specific workload segments rather than enabling comprehensive cross-organizational intelligence gathering.
Impact at a Glance
Affected Business Functions
- Nuclear Research Operations
- Radiation Safety Management
- Personnel Security Systems
- Naval Defense Contracting
Estimated downtime: N/A
Estimated loss: N/A
Nuclear reactor core-component databases, fuel inventories, radiation safety documentation, authorized user lists, personnel records including passports and financial disclosures, and credential stores totaling 9GB of sensitive government data
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between critical systems like nuclear databases and administrative networks using identity-based policies and microsegmentation
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration attempts and monitor outbound traffic patterns to detect large-scale data transfers
- • Enable Multicloud Visibility & Control to detect anomalous interactions, directory enumeration patterns, and suspicious automation across hybrid infrastructure
- • Implement Inline IPS (Suricata) to identify and block known exploit patterns targeting CVE-2023-49105 and similar vulnerabilities before they reach vulnerable applications
- • Deploy Encrypted Traffic (HPE) controls to protect sensitive nuclear data in transit and prevent interception during legitimate transfers between authorized systems



