Chinese-Speaking Hackers Exploit Known Flaws to Steal Philippine Nuclear and Naval Data
Brief
Suspected Chinese-speaking hackers exploited known vulnerabilities to steal sensitive data from a Philippine nuclear research organization and a marine engineering company serving the Philippine Navy.
Researchers at Hunt.io discovered an exposed attacker server on August 13, 2026, containing custom exploit scripts, stolen files, logs, and offensive tools.
The activity comes amid heightened South China Sea tensions and continued cyber espionage targeting Philippine government, defense, research, and infrastructure organizations.
The attackers targeted an internet-facing ownCloud server operated by a Philippine nuclear research body.
They exploited CVE-2023-49105, a critical ownCloud authentication bypass affecting vulnerable versions that use an empty pre-signed URL signing secret.
