Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

🔴 Critical: ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2023-49105
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    CISA has added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after reports emerged of active exploitation targeting a nuclear research organization in the Philippines. The flaw, tracked as CVE-2023-49105 with a CVSS score of 9.8, is being leveraged by a Chinese-speaking threat actor according to available reporting.

    The vulnerability is a case of improper authentication handling within ownCloud, allowing an attacker to bypass authentication mechanisms and gain unauthorized access to sensitive files. In this particular campaign, the threat actor used the flaw to steal nuclear-related records from the Philippine research body.

    • Affected component: ownCloud core (specific versions were not disclosed in the initial advisory)
    • Impact: Authentication bypass leading to full file disclosure and potential data exfiltration
    • CVSS v3.1 score: 9.8 (Critical)

    Given the addition to the KEV catalog, federal agencies and organizations running ownCloud are strongly advised to prioritize patching immediately. Even if your organization is not in the nuclear or energy sector, adversaries often reuse infrastructure and TTPs across industries, so this should be treated as an active threat.

    Mitigation steps to consider:

    • Apply the official ownCloud security patch for CVE-2023-49105 without delay.
    • Audit access logs for unusual authentication patterns or large data exports.
    • Review any exposed ownCloud instances for signs of compromise, especially if internet-facing.
    • Monitor for secondary payloads or credential harvesting activity.

    Organizations that cannot patch immediately should consider taking ownCloud instances offline or restricting access to trusted networks only.

    If you suspect exposure, incident responders should treat this as a potential data breach and conduct a thorough forensic review of file access history.

    Source: The Hacker News

    Has your team already patched CVE-2023-49105, or are you still assessing your exposure to this authentication bypass?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World