Ethical Hacking News
A critical security flaw in the ownCloud platform has been exploited by Chinese-speaking threat actors to target a nuclear research body in the Philippines, resulting in the theft of sensitive nuclear records. The vulnerability, tracked as CVE-2023-49105, is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication. This attack highlights the need for organizations to prioritize security and apply patches to vulnerable systems to prevent similar attacks in the future.
A critical security flaw in the ownCloud platform (CVE-2023-49105) has been exploited to target a nuclear research body in the Philippines, resulting in the theft of sensitive nuclear records. The vulnerability was disclosed by ownCloud in November 2023 and impacts "core" versions from 10.6.0 through 10.13.0. A Chinese-speaking threat actor has been identified as the attacker, who used the vulnerability to exfiltrate data from two Philippine organizations. The attack highlights the need for organizations to prioritize security and apply patches to vulnerable systems. Other vulnerabilities have been exploited by the same threat actor to target critical infrastructure organizations in the Philippines. Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patches by August 30, 2026.
A critical security flaw in the ownCloud platform has been exploited by Chinese-speaking threat actors to target a nuclear research body in the Philippines, resulting in the theft of sensitive nuclear records. The vulnerability, tracked as CVE-2023-49105, is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration.
The vulnerability was disclosed by ownCloud in November 2023, and it impacts "core" versions from 10.6.0 through 10.13.0. However, it was not until recently that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, following reports that a Chinese-speaking threat actor had weaponized the vulnerability to target a nuclear research body in the Philippines.
According to Hunt.io, a threat intelligence firm, the attack began when a Chinese-speaking threat actor identified an open directory on the host "31.58.209[.]241", which staged custom Python scripts, open-source offensive security tooling such as Sliver, Metasploit, and Mettle, and exfiltrated data from two Philippine organizations, including a nuclear research body and a marine engineering and shipbuilding company that provides services to the Philippine Navy.
The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV. The threat actor was able to exploit the vulnerability by using the username of the victim and constructing signed WebDAV requests that would be accepted by the server as an authentication action by that user, without ever supplying credentials.
In all, the threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories. The stolen files included nuclear-material account records, draft strategic plans, research reactor core components, historical fuel inventories, and presentation material, as well as employee personal information and credentials stores such as BitLocker keys, a KeePass database, and AxCrypt-encrypted files.
Furthermore, the threat actor has also exploited a critical flaw in the LiteSpeed Cache plugin for WordPress (CVE-2024-28000) to obtain elevated access to the WordPress site operated by another Philippines company. Separately, a Python script ("brute_xmlrpc.py") identified in the open directory targets the same site with an XML-RPC brute-force attack to guess account credentials, thereby giving the attackers a pathway independent of CVE-2024-28000.
The attack is believed to be part of a larger scheme by a Chinese-speaking threat actor, which has also exploited other vulnerabilities to target critical infrastructure organizations in the Philippines. The threat actor is estimated to have stolen sensitive data from multiple organizations, including a nuclear research body and a marine engineering company, and the attack highlights the need for organizations to prioritize security and apply patches to vulnerable systems.
In light of the active exploitation of CVE-2023-49105, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patches by August 30, 2026. The attack also serves as a reminder of the importance of threat intelligence and the need for organizations to stay vigilant in the face of evolving cybersecurity threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Severe-Security-Flaws-Exploited-to-Steal-Sensitive-Nuclear-Records-in-the-Philippines-ehn.shtml
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
https://nvd.nist.gov/vuln/detail/CVE-2023-49105
https://www.cvedetails.com/cve/CVE-2023-49105/
https://nvd.nist.gov/vuln/detail/CVE-2024-28000
https://www.cvedetails.com/cve/CVE-2024-28000/
Published: Sat Aug 29 17:39:56 2026 by llama3.2 3B Q4_K_M