Critical

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

darkreading
Actively Exploited

Overview

A recent security incident has exposed vulnerabilities in the Philippines' nuclear agency, where attackers exploited weaknesses in the ownCloud software. This breach allowed them to gain initial access, leading to the theft of sensitive data, including reactor databases, personnel records, and credential stores. The implications of this breach are serious, as it not only compromises national security but also raises concerns about the protection of critical infrastructure. Authorities are now faced with the urgent task of assessing the damage and reinforcing security measures to prevent future incidents. This situation serves as a reminder of the importance of patching known vulnerabilities in software systems.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: ownCloud software, Philippines Nuclear Agency systems
  • Action Required: Update ownCloud to the latest version and apply all security patches.
  • Timeline: Disclosed on October 2023

Original Article Summary

Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.

Impact

ownCloud software, Philippines Nuclear Agency systems

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on October 2023

Remediation

Update ownCloud to the latest version and apply all security patches.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Data Breach, Critical.

Related Coverage

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News

A security vulnerability has been discovered in Meta's Muse assistant that could allow malware already on a Mac to hijack the assistant. Researcher Patrick Wardle demonstrated that by modifying a hidden setting, attackers could redirect voice commands meant for Muse to themselves. This means that any sensitive information users dictate could be intercepted by malicious actors. The issue stems from the broad permissions granted to the Muse app, which can be exploited if the malware is already present on the device. This incident raises concerns about the security of AI assistants and the potential for them to be weaponized against users.

Sep 22, 2026

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News

A recently discovered vulnerability in WordPress, known as 'Comment2Shell' and tracked as CVE-2026-93485, allows anonymous users to leave comments that can inject hidden scripts into web pages. If an administrator then views the page, the script can execute code on the server, potentially allowing attackers to take control of the site. This issue was addressed in version 7.1.1, released on September 17, 2023. Site owners are urged to update their WordPress installations immediately to protect against this flaw, which poses significant risks to website security. Failure to patch could leave sites vulnerable to remote code execution attacks.

Sep 22, 2026

How AI Agents Can Trigger Runaway Costs for Enterprises

darkreading

A new concern has emerged regarding the use of AI agents, particularly in the context of unbounded consumption, which OWASP ranks as a significant risk for large language model (LLM) applications. This issue arises when AI systems operate without proper constraints, potentially leading to excessive resource usage and runaway costs for enterprises. Companies leveraging LLM technologies could face financial strain as these agents consume resources beyond expected limits, which could impact budgets and operational efficiency. It’s crucial for organizations to implement controls and monitor AI usage to mitigate these risks effectively. Understanding and addressing this issue is essential for businesses to avoid unexpected expenses and ensure sustainable AI deployment.

Sep 21, 2026

BigCommerce alerts merchants of data breach linked to Ribon apps

BleepingComputer

BigCommerce has informed several merchants about data breaches linked to third-party Ribon applications. Attackers gained access to credentials for these apps and exploited them to insert malicious scripts into online stores. This breach poses a significant risk to affected merchants, potentially compromising customer data and undermining the integrity of their online platforms. The incident raises concerns about the security of third-party integrations and emphasizes the need for merchants to review their app permissions and security practices. Merchants using Ribon applications should take immediate action to secure their accounts and monitor for unusual activity.

Sep 21, 2026

CISA alerts of active exploitation of three Linux kernel flaws

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three vulnerabilities in the Linux kernel, with one being classified as critical. These flaws could allow attackers to gain unauthorized access or control over affected systems, posing significant risks to organizations that rely on Linux-based infrastructure. Users and administrators of Linux systems are urged to take immediate action to protect their environments. The vulnerabilities affect various distributions of Linux, and failure to address them could lead to serious security breaches. As these exploits are currently active, it is crucial for those using Linux to stay informed and apply necessary updates promptly.

Sep 21, 2026

ShinyHunters Hacked Clop. Now What About Clop's Victims?

darkreading

ShinyHunters, a notorious hacking group, has reportedly defaced Clop’s Dark Web site and claims to have stolen data belonging to Clop's victims. This action raises concerns for organizations that previously paid ransoms to Clop, as they could face renewed extortion attempts. The stolen data could expose sensitive information, putting these companies at further risk. This incident highlights the ongoing cycle of ransomware attacks and the challenges organizations face in protecting their data after paying ransoms. As the situation develops, affected organizations will need to assess their security postures and prepare for potential follow-up attacks.

Sep 21, 2026