By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ownCloud Flaw Used to Steal Philippine Nuclear Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added a critical security flaw affecting the ownCloud file-sharing platform to its Known Exploited Vulnerabilities (KEV) catalog on Thursday. This addition follows confirmed reports that a Chinese-speaking threat actor successfully weaponized this vulnerability to target a nuclear research body located in the Philippines. The specific vulnerability, identified as CVE-2023-49105, carries a high severity score of 9.8 on the Common Vulnerability Scoring System (CVSS), indicating a critical risk. This flaw is described as an authentication bypass vulnerability within the ownCloud server, allowing unauthorized access to sensitive data. The exploitation reportedly enabled the threat actor to exfiltrate nuclear research records from the targeted Philippine institution. ownCloud is a widely used open-source file-sharing and collaboration platform, often deployed by organizations to manage and share documents internally and externally. Its widespread use makes vulnerabilities within the platform a significant concern for cybersecurity professionals. The KEV catalog is a list of known exploited vulnerabilities that CISA has confirmed are being actively exploited in the wild. Inclusion in this catalog mandates that U.S. federal agencies must patch or mitigate these vulnerabilities on their systems by specific deadlines to prevent further compromise. While the immediate focus is on U.S. federal agencies, the inclusion of CVE-2023-49105 in the KEV catalog serves as a strong warning to all organizations utilizing ownCloud, regardless of their location or sector. The nature of the targeted data—nuclear research records—highlights the potential for nation-state actors or sophisticated criminal groups to seek out and exploit vulnerabilities for espionage or disruptive purposes. The involvement of a "Chinese-speaking threat actor" suggests a potential state-sponsored or state-aligned operation, though CISA's advisory typically focuses on the technical aspects of the exploitation rather than definitively attributing the actor's origin or affiliation. The vulnerability itself, CVE-2023-49105, is a critical authentication bypass that allows an attacker to gain administrative privileges on an affected ownCloud instance without proper authentication. This level of access would permit the attacker to read, modify, or delete any data stored on the server, as well as potentially install malicious software or further compromise the network. ownCloud has previously released patches for this vulnerability, and organizations are strongly advised to ensure their ownCloud instances are updated to the latest secure versions to protect against such attacks. The incident underscores the ongoing threat posed by sophisticated cyber actors targeting critical infrastructure and sensitive research data through exploitable software vulnerabilities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.