Critical ownCloud Vulnerability Exploited in Cyber Espionage Attack on Philippine Nuclear Research Institution
A critical WebDAV API authentication bypass vulnerability (CVE-2023-49105) in ownCloud was exploited by a Chinese-speaking threat actor to steal sensitive nuclear research data from a Philippine institution. The attack involved unauthenticated file access via pre-signed URLs and exfiltration of 176 files, including strategic plans and database dumps.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
*** END OF TRANSMISSION ***