CVE-2024-28000 — exposed on the internet
CVE-2024-28000: Incorrect Privilege Assignment in LiteSpeed Technologies LiteSpeed Cache
Internet exposure observed by OffSeq scans · last 30 days
Found on 2 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2024-28000
A suspected Chinese-speaking threat actor conducted targeted intrusions against Philippine nuclear research and defense organizations. On August 13, 2026, an open directory on a VPS exposed custom Python scripts exploiting CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress LiteSpeed Cache. The operator exfiltrated approximately 9 GB from a nuclear agency, including reactor core databases, radiation safety documentation, employee PII, BitLocker keys, and strategic planning materials. A second victim, a marine engineering firm serving the Philippine Navy, had its complete WordPress installation compromised. Simplified Chinese language usage throughout scripts, logs, and folder structures indicates operator origin. The methodical targeting of nuclear and naval defense sectors aligns with South China Sea tensions and broader Chinese espionage activities against Philippine government infrastructure.
Vendor: LiteSpeed Technologies
OffSeq internet scanning found CVE-2024-28000 on 2 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Exposed-host countries
Exposed via
wordpress