Suspected Chinese-speaking operators exploited the critical ownCloud vulnerability CVE-2023-49105 to steal sensitive information from a Philippine nuclear research organization, including nuclear material records, research-reactor data, radiation-safety documents, personnel files and encryption key material. Hunt.io discovered an exposed directory on August 13, 2026, hosted at 31.58.209[.]241:8000, containing 1,310 files across 86 subdirectories. The server, registered to CGI Global Limited, exposed custom exploit scripts, exfiltration logs, offensive tooling and stolen data. Hunt.io reported the findings to CERT-PH under TLP:AMBER and delayed publication until August 25 to allow coordinated notifications. The attackers’ Python scripts exploited CVE-2023-49105, which affects ownCloud installations using pre-signed URLs without a configured signing secret. By exploiting the empty secret, attackers could forge authenticated WebDAV requests for known accounts. The recovered scripts targeted individual accounts and recursively enumerated files, using random delays to reduce detection. Simplified Chinese comments described objectives including the low-speed collection of nuclear material documents, radiation-safety files and IT-planning data. Five staging directories contained 176 files totaling about 372 MB, while an attacker-created CSV indicated approximately 9 GB had been exfiltrated overall. The stolen material included reactor component databases, fuel inventories, safety documentation, authorized-user lists, strategic plans, financial records, résumés, passport-related documents and personal data. Credential collections included a KeePass database, AxCrypt-encrypted files and a BitLocker recovery key. Researchers also identified a compromise of a Philippine marine engineering and shipbuilding company supporting the Philippine Navy. Attackers exploited LiteSpeed Cache CVE-2024-28000 to create a WordPress administrator account and used XML-RPC password attacks. A separate EtherHiding-style infection used an Ethereum smart contract to deliver a malicious ClickFix lure. Hunt.io assessed with medium confidence that the campaign represented targeted intelligence collection rather than indiscriminate exploitation, although no specific threat group was attributed. Organizations using ownCloud should upgrade to 10.13.3 or later and configure a strong signing secret. WordPress administrators should update LiteSpeed Cache, restrict unnecessary XML-RPC access, enforce MFA, rotate exposed credentials and monitor WebDAV logs for suspicious PROPFIND requests and cross-account file retrieval.
In April 2026, attackers reportedly gained access to an organization through a FortiGate SSL VPN using compromised domain credentials and obtained domain administrator-level privil...
A newly identified information-stealing campaign, tracked as Rapuncel, abuses a Microsoft-attested kernel driver to terminate processes belonging to up to 145 antivirus (AV) and en...
NightEagle, also tracked as APT-Q-95, has expanded its espionage operations from Asian targets to Russian organizations, using a multi-stage intrusion chain aimed at compromising A...