Executive Summary

In September 2026, threat actors exploited unpatched vulnerabilities in ownCloud (CVE-2023-49105) and LiteSpeed Cache WordPress plugin (CVE-2024-2800) to breach a Philippine nuclear agency and naval contractor. The attackers, likely Chinese-speaking based on code comments, exfiltrated 9GB of sensitive data including reactor databases, fuel inventories, radiation safety documents, personnel records, and credential stores. Hunt.io researchers discovered the stolen data on an Amsterdam-based server serving as an operational hub for the attackers.

This incident reflects escalating cyber threats in the Philippines amid South China Sea tensions, with breach incidents nearly tripling in the first half of 2026. The successful exploitation of vulnerabilities patched over two years ago highlights critical gaps in patch management and security fundamentals at sensitive government facilities.

Why This Matters Now

Nation-state actors are increasingly targeting critical infrastructure through basic vulnerabilities, with geopolitical tensions in the South China Sea driving sophisticated espionage campaigns against nuclear facilities and defense contractors using commodity exploits.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers exploited CVE-2023-49105 in ownCloud and CVE-2024-2800 in LiteSpeed Cache WordPress plugin, both of which had patches available for over two years.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly reduced the attack blast radius by implementing network segmentation and controlled access policies. The attackers' ability to move laterally between nuclear agency and naval contractor systems would likely have been constrained through east-west traffic enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation policies would likely have limited the initial compromise scope, constraining attacker access to isolated workload boundaries rather than permitting broad network reach from the compromised web applications.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware access controls would likely have constrained administrative privilege scope, limiting the effectiveness of compromised credentials to specific workload boundaries rather than enabling broad system-wide access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Inter-workload traffic enforcement would likely have blocked unauthorized lateral movement between nuclear agency and naval contractor systems, constraining attackers to their initial compromise foothold rather than enabling cross-organizational access.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility and traffic analysis would likely have detected anomalous communication patterns to Amsterdam infrastructure, potentially constraining persistent command channel establishment through policy-based blocking.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained large-volume data transfers to unauthorized external destinations, reducing the scope of sensitive data exfiltration through automated traffic inspection and blocking.

Impact (Mitigations)

While sensitive nuclear facility data remained at risk, the overall organizational exposure would likely have been reduced to specific workload segments rather than enabling comprehensive cross-organizational intelligence gathering.

Impact at a Glance

Affected Business Functions

  • Nuclear Research Operations
  • Radiation Safety Management
  • Personnel Security Systems
  • Naval Defense Contracting
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Nuclear reactor core-component databases, fuel inventories, radiation safety documentation, authorized user lists, personnel records including passports and financial disclosures, and credential stores totaling 9GB of sensitive government data

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement between critical systems like nuclear databases and administrative networks using identity-based policies and microsegmentation
  • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration attempts and monitor outbound traffic patterns to detect large-scale data transfers
  • Enable Multicloud Visibility & Control to detect anomalous interactions, directory enumeration patterns, and suspicious automation across hybrid infrastructure
  • Implement Inline IPS (Suricata) to identify and block known exploit patterns targeting CVE-2023-49105 and similar vulnerabilities before they reach vulnerable applications
  • Deploy Encrypted Traffic (HPE) controls to protect sensitive nuclear data in transit and prevent interception during legitimate transfers between authorized systems

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image