ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Summary
A critical security flaw in ownCloud, identified as CVE-2023-49105, has been added to CISA's Known Exploited Vulnerabilities catalog. A Chinese-speaking threat actor reportedly exploited this vulnerability to steal nuclear records from a Philippine research organization.
IFF Assessment
The exploitation of a critical vulnerability by a threat actor to steal sensitive data is bad news for defenders, highlighting successful attacks and ongoing risks.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 30, 2026. Known ransomware use: Unknown.
Defender Context
This incident highlights the critical importance of promptly patching known exploited vulnerabilities, especially in organizations handling sensitive data. Defenders should prioritize monitoring for indicators of compromise related to CVE-2023-49105 and similar critical flaws in file-sharing and collaboration software.