Security1 distinct publisher2 min readPublished
Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The bypass works because the signing routine ran regardless. In ownCloud builds before 10.13.1, pre-signed URLs are generated with a signing key, and where no key was configured, the default state on new installs, the routine still executed using an empty secret [5]. An attacker who knows a valid username can then construct signed WebDAV requests that the server accepts as authenticated action by that user, without ever supplying credentials [6]. Hunt.io recovered five Python scripts implementing exactly that technique: four hardcoded to one account each, and a fifth that enumerated directories and logged every attempted download [7]. Random delays were built in to keep collection under volume-based alerting [8].
Then the arithmetic. The operator's own CSV references roughly 9 GB taken from the nuclear agency, most of it absent from the directory as captured [13]. What was actually sitting there was 176 files, about 372 MB [12]. That is near 4 percent of what the CSV describes [1]. The wider directory ran to 1,310 files and 1.17 GB [11], which leaves roughly 800 MB of tooling, scripts and logs [2], among them Sliver, Metasploit and Mettle [11].
The recovered fraction alone covers reactor component databases, fuel inventories, radiation-safety documents, incident records and authorised-user lists [17], plus strategic plans, IT documentation, staff records, CVs, passport and travel data, and financial disclosures from Philippine officials [18]. A KeePass database was in the haul [19]. The CSV also logs a compromised project management application, which points to a third victim nobody has named [14].
On attribution, keep the two registers apart. Documented: scripts, logs and folder names consistently in Simplified Chinese, with labels for nuclear, radiation-safety, finance and IT files [15]. Inferred: Hunt.io says this suggests a Chinese-speaking operator and states plainly that it does not prove links to a specific government or threat group [16]. The surrounding context, sustained South China Sea tension and continuing reports of suspected Chinese activity against Philippine government, defence and critical-infrastructure targets, is public and is not evidence of tasking [21].
The flaw carries a 2023 identifier [4] and the staging host was live in August 2026 [2], so call it three years of a patched authentication bypass still serving files off an internet-facing service [3]. The chain used well-known vulnerabilities in internet-facing ownCloud and WordPress [1] and open-source offensive tooling [11]. Edge inventory and version discipline were the control. They still are.
Ranked by verification strength, evidence, and original report placement.
On August 13, 2026, Hunt.io Attack Capture identified an open directory on the host 31.58.209[.]241 that staged custom Python scripts, per-file transfer logs, open-source offensive security tooling and exfiltrated data from two Philippine organisations.
The activity was uncovered after Hunt.io found the exposed server in Amsterdam containing attack scripts, logs, offensive tooling and data taken from the two organisations.
In vulnerable instances where no signing key was configured, a default state on new installs, the signing routine still executed using an empty secret, so pre-signed URLs allowed unauthenticated retrieval of files over WebDAV.
An attacker who knows a valid username on the instance could construct signed WebDAV requests that the server accepts as an authenticated action by that user, without supplying credentials.
A separate intrusion was observed exploiting a WordPress site operated by a Philippine marine engineering and shipbuilding company that provides services to the Philippine Navy.
A CSV created by the attacker referenced roughly 9 GB of material stolen from the nuclear agency, most of it absent from the current directory contents.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 29, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Attackers pulled 372 MB of Philippine nuclear records through a 2023 ownCloud bypass1 distinct publisher
security
Six bugs, one order of operations: Avada's zero-click chain is a same-day patch1 distinct publisher
build
Six MariaDB versions, one real difference: the only reason to leave 10.6 is the July 2026 clock1 distinct publisher
security
Nearly four in ten breached German companies now name a foreign intelligence service1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Rich artifacts, one witness
The specificity is real: a host address, a discovery date, 1,310 files in 86 folders, five scripts with their differing scopes, two named CVEs with an affected version cutoff, and logs showing which downloads succeeded. But every one of those details reaches us through Hunt.io's own report as relayed by Security Affairs, and neither victim, nor CERT-PH, nor a second researcher appears anywhere to confirm it. The weakest link is the headline volume: 9 GB is what the attacker's spreadsheet says he took, not what anyone recovered.
Live exploitation, files on disk
This is not a proof of concept or a scanner statistic. Two intrusions were in progress with working tooling, transfer logs and stolen files sitting in a directory anyone could browse, and coordinated disclosure through CERT-PH triggered real victim notification. What holds the number below the high band is scope: one operator, two confirmed organisations, no indication of how widely the ownCloud default or the LiteSpeed flaw is being worked elsewhere.
Scale runs ahead of the recovery
The framing leans on the biggest available figure. Calling the agency drained rests on 9 GB from the attacker's inventory when 372 MB is what was actually recovered — a twenty-five-fold difference that the reporting does flag but does not carry into its own emphasis. Pulling the other way, the attribution is unusually disciplined: Hunt.io stops at a Chinese-speaking operator and says plainly that no government or named group is established, and Security Affairs keeps the hedge in its headline. Overstated, then, but narrowly and about volume rather than about who did it.
Vendor discovery, vendor product name
The finding and the marketing share a byline: Hunt.io Attack Capture is a commercial product, and this is a showcase of what it catches. Threat-intel vendors are paid to be the ones who saw it first, and superlatives about victim sensitivity are the currency. Two things temper it — the attribution restraint costs the vendor the most quotable line available, and the delay to 25 August 2026 to let CERT-PH notify victims is the opposite of a rush to publish. Security Affairs adds no competing interest that our coverage discloses; it also adds no independent check.
Act on the mechanism, hedge the magnitude
Split the story in two and confidence follows. The technical core — which flaws, which versions, which tooling, how the forged WebDAV requests worked — is concrete enough to hunt against today, and the file-level logs make it hard to fake. The parts about how much was taken, who else was hit and who ultimately directed it stay soft: one spreadsheet, one unnamed possible third victim, one language signal. With a single outlet relaying a single vendor, there is no second account to test either half against.