Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Hunt.io researchers uncovered an active data exfiltration campaign targeting the Philippines Nuclear Regulatory Authority and a maritime contractor supporting the Philippine Navy, revealing that long-unpatched systems remained exploitable despite available fixes. The intrusion leveraged CVE-2023-49105 in ownCloud and CVE-2024-2800 in the LiteSpeed Cache WordPress plugin, both of which have had remediations available for over two years.
The attackers harvested approximately 9 GB of sensitive material, including reactor core component databases, fuel inventories, radiation safety protocols, and personnel records such as passports and financial disclosures. This incident underscores the persistent risk posed by internet-facing collaboration tools that lack timely patching and hardened configurations, particularly in regions facing heightened geopolitical cyber threats.