CVE Tools

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Dark ReadingBy Robert Lemos

IncidentownCloudLiteSpeed Cache

Our summary

Hunt.io researchers uncovered an active data exfiltration campaign targeting the Philippines Nuclear Regulatory Authority and a maritime contractor supporting the Philippine Navy, revealing that long-unpatched systems remained exploitable despite available fixes. The intrusion leveraged CVE-2023-49105 in ownCloud and CVE-2024-2800 in the LiteSpeed Cache WordPress plugin, both of which have had remediations available for over two years.

The attackers harvested approximately 9 GB of sensitive material, including reactor core component databases, fuel inventories, radiation safety protocols, and personnel records such as passports and financial disclosures. This incident underscores the persistent risk posed by internet-facing collaboration tools that lack timely patching and hardened configurations, particularly in regions facing heightened geopolitical cyber threats.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store