<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body]]></title><description><![CDATA[<p dir="auto">CISA has added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after reports emerged of active exploitation targeting a nuclear research organization in the Philippines. The flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49105" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2023-49105</a></strong> with a CVSS score of <strong>9.8</strong>, is being leveraged by a Chinese-speaking threat actor according to available reporting.</p>
<p dir="auto">The vulnerability is a case of improper authentication handling within ownCloud, allowing an attacker to bypass authentication mechanisms and gain unauthorized access to sensitive files. In this particular campaign, the threat actor used the flaw to steal nuclear-related records from the Philippine research body.</p>
<ul>
<li>Affected component: ownCloud core (specific versions were not disclosed in the initial advisory)</li>
<li>Impact: Authentication bypass leading to full file disclosure and potential data exfiltration</li>
<li>CVSS v3.1 score: 9.8 (Critical)</li>
</ul>
<p dir="auto">Given the addition to the KEV catalog, federal agencies and organizations running ownCloud are strongly advised to prioritize patching immediately. Even if your organization is not in the nuclear or energy sector, adversaries often reuse infrastructure and TTPs across industries, so this should be treated as an active threat.</p>
<p dir="auto">Mitigation steps to consider:</p>
<ul>
<li>Apply the official ownCloud security patch for <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49105" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2023-49105</a></strong> without delay.</li>
<li>Audit access logs for unusual authentication patterns or large data exports.</li>
<li>Review any exposed ownCloud instances for signs of compromise, especially if internet-facing.</li>
<li>Monitor for secondary payloads or credential harvesting activity.</li>
</ul>
<p dir="auto"><em>Organizations that cannot patch immediately should consider taking ownCloud instances offline or restricting access to trusted networks only.</em></p>
<p dir="auto">If you suspect exposure, incident responders should treat this as a potential data breach and conduct a thorough forensic review of file access history.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team already patched <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49105" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2023-49105</a></strong>, or are you still assessing your exposure to this authentication bypass?</p>
]]></description><link>https://xploitlk.com/topic/141/critical-owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:27:49 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/141.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 29 Aug 2026 10:30:25 GMT</pubDate><ttl>60</ttl></channel></rss>