Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited a known vulnerability in ownCloud to breach the Philippines' nuclear agency, gaining access to sensitive systems without requiring patching or updates. The compromise resulted in the theft of reactor databases, personnel records, and stored credentials, highlighting the critical risk posed by delayed security remediation in high-value infrastructure environments.
Researchers from Bern University of Applied Sciences developed an AI script capable of solving rotational image CAPTCHAs in just 0.006 seconds, demonstrating a significant vulnerability in this common security mechanism. The exploit highlights the diminishing effectiveness of image-based CAPTCHAs against machine learning approaches, raising concerns about the reliability of this authentication method for protecting against automated attacks.
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.