securityaffairs.com 8/29/2026, 9:56:03 AM · external

9GB Philippine Nuclear Data Stolen via ownCloud, WordPress Flaws

9GB Philippine Nuclear Data Stolen via ownCloud, WordPress Flaws
CyberSIXT Evidence Panel
Primary Source hunt.io

A suspected Chinese-speaking cyber operator breached Philippine nuclear and naval targets, exploiting vulnerabilities in internet-facing ownCloud and WordPress systems. Hunt.io discovered an exposed server containing attack scripts and logs, revealing the theft of sensitive data totaling around 9 GB. The incident involved an authentication-bypass flaw in ownCloud, allowing unauthorized file access, while the WordPress site faced a privilege-escalation exploit enabling admin account creation.

The compromised data included nuclear reactor component databases, strategic plans, and personnel information. This breach highlights the continued risk of known vulnerabilities impacting critical infrastructure amidst rising tensions in the South China Sea.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline