CVE Tools

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker NewsBy The Hacker News

Reported exploitedownCloudChinese-speaking threat actor

Our summary

CISA has added ownCloud vulnerability CVE-2023-49105 to its Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor used it to compromise a nuclear research facility in the Philippines. The critical flaw, affecting versions 10.6.0 through 10.13.0, allows unauthenticated file access via WebDAV pre-signed URLs when no signing key is configured, leading to the theft of approximately 372 MB of sensitive documents including strategic plans and reactor data. Federal agencies are advised to upgrade to version 10.13.1 by August 30, 2026.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store