Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Cybersecurity Threats in the Philippines Take a Dire Turn as Nuclear Agency Breached

A recent cybersecurity incident has left the Philippines’ nuclear agency vulnerable, with attackers exploiting old and unpatched vulnerabilities to gain access to sensitive information. The breach highlights the growing threat landscape in the region, where political tensions between China and neighboring countries have fueled an uptick in cyber attacks.

The attack on the Philippine nuclear agency was orchestrated by a cyber threat group that exploited vulnerabilities in ownCloud, a popular open source project used for creating cloud services. Researchers from Hunt.io discovered a server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data. The files identified at least two victims: the Philippines’ nuclear agency and a marine engineering company serving the Philippine Navy.

The coding comments and folder names on the compromised server were written in Chinese, suggesting that a Chinese-speaking threat actor was behind the breach. While Hunt.io did not attribute the attacks, the presence of three popular open source offensive frameworks on the server suggests that the attackers used these tools to collect and exfiltrate data from the targeted organizations.

The incident is particularly concerning as it highlights the ease with which attackers can exploit old vulnerabilities in internet-facing systems. The two exploited vulnerabilities – CVE-2023-49105 and CVE-2024-2800 – were disclosed more than two years ago, but remained unpatched on internet-facing systems belonging to sensitive organizations. This incident serves as a stark reminder that cybersecurity teams must prioritize patching and inventorying their internet-facing software, especially collaboration platforms like WordPress.

Esteban Borges, head of research at Hunt.io, emphasizes the importance of hardening systems and doing the basics: configuring hardware with minimum permission and secure defaults, changing ownCloud signing keys, and implementing multifactor authentication. He also warns that security teams should watch for patterns such as pre-signed URL abuse and directory enumeration hitting multiple accounts from a single source.

The Philippines has seen a significant increase in breach incidents this year, with nearly 18% of attacks targeting government agencies. This trend is likely fueled by the ongoing tensions between China and countries claiming territory in the South China Sea. China has been known to use cyber operations against its rivals in the region, from Taiwan to Vietnam and from South Korea to the Philippines.

As cybersecurity threats continue to escalate in the Philippines, it’s essential for organizations to take proactive measures to secure their systems. By patching vulnerabilities promptly and implementing robust security controls, organizations can minimize the risk of a breach. In this case, the attackers’ success was largely due to old flaws being left unpatched – a stark reminder that cybersecurity is an ongoing process that requires continuous attention and effort.

In conclusion, the Philippines nuclear agency breach serves as a wake-up call for organizations in the region to prioritize their cybersecurity posture. By doing so, they can mitigate the risk of similar attacks and protect sensitive information from falling into the wrong hands.


Source: Dark Reading — 2026-09-02