logo

Chinese-Speaking Hackers Exploit Known Flaws to Steal Philippine Nuclear and Naval Data

ID: 711357fe-1678-5095-9220-d3ab62c14e2a

STIX ID: report--711357fe-1678-5095-9220-d3ab62c14e2a

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Varshini

...
...

Researchers discovered a hostile campaign by suspected Chinese-speaking actors who exploited a critical ownCloud authentication bypass (CVE-2023-49105) and a LiteSpeed Cache WordPress plugin privilege-escalation flaw (CVE-2024-28000) to steal sensitive data from a Philippine nuclear research organization and a marine engineering company; an exposed attacker server contained custom Python scripts, stolen documents (including nuclear-material records, passports, BitLocker recovery keys, and a KeePass database), logs, and indicators such as IP 31.58.209.241 used to stage tools and exfiltrate data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.