VMTech
Discuss a project

CISA adds exploited ownCloud flaw after Philippine nuclear data theft

CISA adds exploited ownCloud flaw after Philippine nuclear data theft

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2023-49105, a critical ownCloud vulnerability with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog after reports of its use against a Philippine nuclear research body. Hunt.io estimated that the operators downloaded 176 files, totalling about 372 MB, from the organisation.

The issue is a WebDAV API authentication bypass in ownCloud core versions 10.6.0 through 10.13.0. ownCloud disclosed the vulnerability in November 2023 and corrected it in version 10.13.1. CISA has directed U.S. Federal Civilian Executive Branch agencies to apply the patch by August 30, 2026.

Known usernames can enable unauthenticated file access

CVE-2023-49105 can let an attacker access, modify or delete files without authentication when the victim username is known and the account has no signing key configured. The latter is the default configuration described in the disclosure.

Hunt.io said the intrusion relied on pre-signed URLs generated with an empty signing secret. That condition allowed unauthenticated retrieval of files through WebDAV. Its analysis of an exposed directory found five custom Python scripts implementing the exploit: four targeted individual accounts, while a fifth enumerated a WebDAV directory and logged download attempts.

The firm said an attacker who knows valid usernames can construct signed WebDAV requests that the server accepts as an authentication action for those users, without supplying their credentials. The exposed infrastructure also contained Sliver, Metasploit and Mettle, alongside the custom scripts and data staging directories.

Staged material included records and credential stores

The stolen material reportedly included nuclear-material account records, draft strategic plans for 2023 to 2028, research reactor core-component information, historical fuel inventories, presentations and employee personal information. Hunt.io also identified a 192 MB SQL dump of a ZKTeco BioTime attendance and personnel database.

Credential-related material in the staged data included BitLocker keys, a KeePass database and AxCrypt-encrypted files. Hunt.io attributed the activity to a Chinese speaker based on simplified Chinese in source-code comments, docstrings, log output and folders used to organise stolen data. The firm did not identify the operator beyond that assessment.

A parallel intrusion targeted a defence-adjacent company

The same exposed directory was linked to a separate attack on a marine engineering and shipbuilding company serving the Philippine Navy. Hunt.io said the attackers exploited CVE-2024-28000, a critical vulnerability in the LiteSpeed Cache WordPress plugin, to obtain elevated access to the company's WordPress site.

A script named brute_xmlrpc.py also targeted that site with an XML-RPC credential-guessing attack, providing a path independent of CVE-2024-28000. Separately, analysis of the site code found an active, possibly unrelated compromise using EtherHiding to pull HTML from an Ethereum smart contract and serve a Google-verification lure associated with ClickFix-style attacks.

Business implication

Organisations running ownCloud should identify systems on affected core versions, upgrade to 10.13.1 or later, examine WebDAV activity and account signing-key settings, and investigate exposed usernames and sensitive files for signs of unauthorised retrieval. Where credential stores or keys may have been accessible, teams should treat them as potentially exposed and rotate them through established incident-response procedures.

#cybersecurity#owncloud#vulnerability#databreach
Open analytics
On the site 0 views
min read 4 28.08.2026
Instagram

CISA adds exploited ownCloud flaw after Philippine nuclear data theft

Open the post on Instagram ↗