Security News

Cybersecurity news aggregator

CRITICAL Attacks Dark Reading

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited a critical vulnerability (CVE-2023-49105, CVSS 9.8) in ownCloud to gain initial access to unpatched servers, including those at a Philippines nuclear agency and naval contractor, leading to data exfiltration. The vulnerability affects ownCloud server versions 10.6.0 through 10.13.0, and it is fixed in version 10.13.1.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK THREAT INTELLIGENCE VULNERABILITIES & THREATS NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America. Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores. Robert Lemos,Contributing Writer September 2, 2026 4 Min Read SOURCE: AUSTRALIANCAMERA VIA SHUTTERSTOCK Unpatched servers at a Philippines nuclear agency, a naval contractor, and other organizations allowed a cyberthreat group to breach the networks and steal information nuclear-material processes and other sensitive data. Researchers from threat hunting platform Hunt.io discovered the files on an ownCloud server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data, including 1,310 files totaling nearly 1.2 GB. The files identified at least two of the victims: a nuclear agency in the Philippines and a marine engineering and shipbuilding company serving the Philippine Navy, Hunt.io stated in a blog post published on August 26. A third database appears to be a list of potential targeted personnel at research and science facilities in the country as well. While Hunt.io did not attribute the attacks, the coding comments and folder names were written in Chinese, suggesting a Chinese-speaking threat actor. In addition, three popular open source offensive frameworks were also present on the server, but the vendor did not find any indications that they were used to attack the targeted organizations, says Esteban Borges, head of research for Hunt.io. Related:Dark Caracal Adds New Malware to Cyber Espionage Arsenal "Everything we saw is collection and exfiltration, no disruption tooling," he says. "The naval shipbuilder works with the Navy, which fits in with the South China Sea interests... [but] nothing we recovered points to staging for a destructive effect." The incident highlights the growing threat landscape in the Philippines, with breach incidents nearly tripling in the first half of 2026, compared to the same period in 2025, according to a report from Vietnam-based cybersecurity services firm Viettel Security. While most attacks (51%) have targeted the banking, financial services, and insurance (BFSI) sector, government agencies are targeted in 18% of incidents, the report found. A significant factor in the burgeoning cyber risk in the region are political tensions between the China and countries claiming territory in the South China Sea. China has often used cyber operations against its rivals in the region, from Taiwan to Vietnam and from South Korea to the Philippines. Old Flaws, New Breaches Tellingly, the attacks on highly sensitive systems succeeded through exploiting vulnerabilities disclosed — and patched — more than two years ago. The nuclear agency uses ownCloud, a popular open source project allowing users and organizations to create their own cloud service. In November 2023, the project disclosed a vulnerability, tracked as CVE-2023-49105, that allows an attacker to bypass authentication in the software's pre-signed URL mechanism that enables the operator to access data on servers. The second security issue affected the LiteSpeed Cache WordPress plugin (CVE-2024-2800) and was patched in August 2024. Related:Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Yet, more than 24 months after their disclosures, the vulnerabilities remained exploitable on internet-facing systems belonging to highly sensitive organizations. Borges says organizations need to harden their systems and do the basics: Patch and inventory internet-facing collaboration software, especially WordPress sites; configure hardware with minimum permission and secure defaults, such as changing the ownCloud signing key; and have multifactor authentication and strong passwords on administrative accounts. "In this case the way in was known, already-patched bugs in internet-facing software plus weak configurations," he says, adding that security teams should "watch for the pattern we saw: pre-signed URL abuse and directory enumeration hitting a lot of accounts from one source." Nuclear Agency Data Exfiltrated While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agency" documented a far wider impact, suggesting that 9 GB of data had been exfiltrated from the agency but had been moved off the server, the firm stated in its analysis. Related:'Grandoreiro' Malware Resurfaces With Mexico Campaign While Hunt.io cannot confirm that "9 gigabytes left the building," the credentials, documents, and data all indicate a broader breach, Borges says. "We didn't see anything touching the systems that run a reactor or a shipyard," he says. "[But] they took a research reactor core-component database, fuel inventories, radiation safety docs, an authorized-user list, and a lot of personnel data and credential stores." The recovered material likely provides a technical blueprint of the nuclear facility, including reactor core-component databases, historical fuel inventories, radiation safety manuals, and authorized user lists, according to the Hunt.io report. Personnel folders could have sensitive information on government workers and scientists, as they include resumes, passport documents, foreign travel records, and Philippine government financial disclosures — known as statement of assets, liabilities, and net worth (SALN) forms — required of public officials. In addition, some of the material recovered contain development secrets and other credentials, such as a valid login to the agency's ownCloud instance, according to the analysis. The documents also contain details that could provide ways for the naval contractor to be re-compromised, Borges says. Based on the strategic interest of what was taken, as well as the Chinese language use, the threat actor is likely Chinese, but Hunt.io stopped short of identifying a nation-state actor. "We didn't name a Chinese state group, because language is one of the easiest indicators to plant," he says. "[We're] not saying this is a false flag — we have no evidence it is — but we can't rule one out on language alone, and that's why we stopped at 'speaker.'" Read more about: DR Global Asia Pacific About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discover

Share this article