https://reddit.com/r/cybersecurity/comments/1vyy6zv/philippine_nuclear_agency_and_naval_contractor/: ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
Published Aug 26, 2026
·Updated
Affected Software
2 affected components
ownCloud ownCloud=CVE-2023-49105
LiteSpeed Cache=CVE-2024-28000
Frequently Asked Questions
1
Are new ownCloud installations affected without any configuration changes?
The reported ownCloud intrusion abused an empty signing secret, which is the default on new installations. Administrators should set a real signing key and patch internet-facing ownCloud deployments.
2
What access did the operator need to compromise the naval contractor's WordPress site?
The activity reportedly used CVE-2024-28000 in LiteSpeed Cache and XML-RPC password brute forcing with the rockyou.txt wordlist. This makes exposed WordPress XML-RPC endpoints and administrator accounts without MFA relevant attack paths.
3
What should teams prioritize if they cannot immediately patch?
Disable XML-RPC where it is not needed, set a non-empty ownCloud signing key, and enforce MFA on administrator accounts. Internet-facing collaboration software should be prioritized for patching.