The record
Written from the 1 report below. Nothing here is unsourced.
- CISA added a critical ownCloud flaw, CVE-2023-49105, to its Known Exploited Vulnerabilities catalog after reports of active attacks.
- A Chinese-speaking threat actor used the flaw to steal about 176 files, totaling 372 MB, from a Philippine nuclear research organization.
- The stolen material includes nuclear-material account records, draft strategic plans for 2023 through 2028, fuel inventories, employee personal information, and stored credentials such as BitLocker keys and a KeePass database.
- The same actor also attacked a Philippine marine engineering and shipbuilding company that serves the Philippine Navy, exploiting a critical WordPress LiteSpeed Cache plugin flaw.
- The intrusions matter because the targeted organizations are tied to Philippine nuclear research and naval defense amid South China Sea tensions, and federal agencies must patch the ownCloud bug by August 30, 2026.
What to watch next
- Whether Philippine authorities confirm the breach or identify the actor behind the nuclear records theft
- Federal agencies patching CVE-2023-49105 by the August 30, 2026 deadline
- Further details from Hunt.io on the possibly unrelated EtherHiding compromise found in the WordPress site's source code
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Hunt.io
2 quotes · 1 outlet
“The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV”
In the article
…Metasploit, and Mettle, and exfiltrated data from two Philippine organizations, including a nuclear research body and a marine engineering and shipbuilding company that provides services to the Philippine Navy. " The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV ," Hunt.io said. A separate intrusion is said to have exploited a WordPress site managed by the marine engineering and shipbuilding company. The threat intelligence firm attributed the attacks to a Chinese speaker due…
“An attacker with knowledge of valid usernames on the instance could construct signed WebDAV requests that would be accepted by the server as an authentication action by that user, without ever supplying credentials”
In the article
…found to implement an exploit for CVE-2023-49105, allowing an attacker who is in possession of valid usernames on an ownCloud instance to obtain unauthorized access without having to supply the credentials themselves. " An attacker with knowledge of valid usernames on the instance could construct signed WebDAV requests that would be accepted by the server as an authentication action by that user, without ever supplying credentials ," Hunt.io said. Of the five scripts, four target a single account each, while the fifth script includes steps to enumerate the WebDAV directory and log every download attempt. In all, the threat actor is estimated to…
Coverage1
All filed from India
Named United States · Philippines · China · ownCloud · Philippine Navy · ZKTeco · CISA · Hunt.io · OpenAI
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
