• Vulnerability/
  • https://reddit.com/r/netsec/comments/1vyxx41/philippine_nuclear_agency_and_naval_contractor/

https://reddit.com/r/netsec/comments/1vyxx41/philippine_nuclear_agency_and_naval_contractor/: ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

Published Aug 26, 2026
·
Updated

Affected Software

3 affected components
ownCloud ownCloud=CVE-2023-49105
LiteSpeed Cache=CVE-2024-28000
WordPress

Frequently Asked Questions

1

Which ownCloud deployments are exposed to the WebDAV issue?

Fresh ownCloud installations with an empty signing secret are affected, because that is the default state described for CVE-2023-49105. The issue allows forged pre-signed WebDAV URLs.

2

What access does an attacker need to exploit the ownCloud weakness?

The described tooling impersonates a target account by setting the OC-Credential header and requesting files under /remote.php/dav/files/<account>/<path>. It retrieves files as that user without credentials and can use PROPFIND with Depth: 1 to enumerate folders.

3

Were the ownCloud and WordPress/LiteSpeed Cache compromises dependent on one another?

No. The reported activity says the ownCloud CVE-2023-49105 exploitation and the LiteSpeed Cache CVE-2024-28000 exploitation each produced unauthorized access independently.

4

What additional attack technique was used against the WordPress site?

The reported toolkit included XML-RPC brute forcing with rockyou.txt. A separate EtherHiding compromise was also found on the same WordPress site, although it may be unrelated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203