A suspected Chinese-speaking threat actor breached Philippine nuclear research and naval-related organizations by exploiting known vulnerabilities in internet-facing ownCloud and WordPress systems, stealing sensitive data including nuclear reactor component databases and personnel records, according to Security Affairs and independent research from Hunt.io.
Known Vulnerabilities, High-Value Targets
The intrusions exploited two previously disclosed vulnerabilities — CVE-2023-49105 and CVE-2024-28000 — rather than a novel zero-day, underscoring how unpatched, internet-exposed systems remain a viable entry point into sensitive government and defense-adjacent networks years after fixes became available. Hunt.io researchers linked the activity to infrastructure including an IP address at 31.58.209[.]241, and found that stolen data was organized using Chinese-language folder and file names, including terms corresponding to “Nuclear Material Accounts” and “IT Planning,” along with code comments and docstrings that strongly suggest the operator is a native Chinese speaker or highly fluent in the language.
Intelligence Collection, Not Opportunistic Crime
Researchers characterized the operation as consistent with targeted intelligence collection against high-value defense and scientific institutions rather than financially motivated cybercrime. The theft of nuclear reactor component data and personnel records from two organizations raises particular concern given the sensitivity of nuclear material accounting information, which is typically subject to international safeguards and non-proliferation reporting requirements.
Recommended Response
Security Affairs and Hunt.io both recommend that organizations running ownCloud and WordPress promptly apply available patches, upgrade to supported versions, and enforce strong authentication measures given the continued exploitation of these older, publicly known flaws. The incident adds to a broader pattern of suspected Chinese state-linked operators targeting critical infrastructure and defense-adjacent organizations across the Indo-Pacific region, an area of persistent concern for U.S. and allied cybersecurity agencies monitoring pre-positioning activity ahead of potential regional conflict scenarios.









