A suspected Chinese-speaking threat actor has targeted two Philippine organizations, including a nuclear research agency and a marine engineering company that supports the Philippine Navy.
Cybersecurity firm Hunt.io discovered an exposed server in Amsterdam containing attack tools, scripts, logs and stolen data from the two organizations. The researchers said the attackers exploited known vulnerabilities in internet-facing ownCloud and WordPress systems.
The nuclear research organization was targeted through an ownCloud server. The attackers exploited an authentication-bypass flaw (CVE-2023-49105) that could allow access to files without authentication. Hunt.io found about 372 MB of stolen files and said a recovered record indicated that around 9 GB of data may have been taken. The data included nuclear research records, employee personal information and stored credentials.
Following the disclosure, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its KEV list of exploited vulnerabilities, along with an unspecified issue in Linux Kernel (CVE-2026-53362), and a path traversal in JFrog Artifactory (CVE-2026-66384).
The second target was a Philippine marine engineering and shipbuilding company that provides services to the Navy. Attackers compromised its WordPress website and stole a copy of the website, including files and a database.
Hunt.io reported the findings to the Philippine Computer Emergency Response Team (CERT-PH) and delayed publication until August 25, 2026, to allow authorities to notify the affected organizations.