discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

ownCloud flaw exploited to steal nuclear records from Philippine research body. CISA added CVE-2023-49105 to KEV catalog. Hunt.io identified open directory with scripts targeting ownCloud instance.

By Ravie Lakshmanan·Aug 28·thehackernews.com·2 min read

Intelligence analysis by Qwen 2.5 (3B)

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Image: thehackernews.com

A Chinese-speaking threat actor used a critical ownCloud vulnerability to steal nuclear records from a Philippine research body. CISA added the vulnerability to its KEV catalog. Hunt.io identified an open directory with scripts targeting ownCloud instances.

Why it matters

This highlights the importance of patching known vulnerabilities to prevent data breaches and espionage.

A bad guy found a way to trick a computer system to let them see and change files they shouldn't. They used this to look at important nuclear information from a research place in the Philippines.

Analysis

{"

Vulnerability Details and Impact on ownCloud Instances":"CVE-2023-49105 is a WebDAV API authentication bypass vulnerability in ownCloud. It allows attackers to access, modify, or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured. This vulnerability impacts core versions from 10.6.0 through 10.13.0 and was fixed in version 10.13.1. The threat actor used this vulnerability to target a nuclear research body in the Philippines.","

Hunt.io's Findings":"Hunt.io identified an open directory on the host '31.58.209[.]241' that staged custom Python scripts, open-source offensive security tooling, and exfiltrated data from two Philippine organizations. The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV. The threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories. This includes nuclear-material account records, draft strategic plans, research reactor core components, historical fuel inventories, and employee personal information.","

WordPress Exploitation":"A separate intrusion exploited a critical flaw in the LiteSpeed Cache plugin for WordPress (CVE-2024-28000) to obtain elevated access to the WordPress site operated by another Philippines company. A Python script ('brute_xmlrpc.py') identified in the open directory targets the same site with an XML-RPC brute-force attack to guess account credentials, thereby giving the attackers a pathway independent of CVE-2024-28000. Further analysis of the WordPress source code has unearthed an active, possibly unrelated compromise that leverages EtherHiding to extract HTML content from an Ethereum smart contract and ultimately serve a Google verification page that's common in ClickFix-style attacks."}

Key points

  • ownCloud vulnerability CVE-2023-49105 was exploited to steal nuclear records from a Philippine research body.
  • The threat actor used a pre-signed URL with an empty signing secret to access files without authentication.
  • The threat actor also exploited a critical flaw in the LiteSpeed Cache plugin for WordPress.
  • The threat actor used a Python script to guess account credentials on the WordPress site.
  • The threat actor used EtherHiding to extract HTML content from an Ethereum smart contract and serve a Google verification page.
The Upside

By patching the ownCloud vulnerability, organizations can prevent bad guys from using this trick to see sensitive information.

The Downside

If the bad guy finds a new way to trick the system, they might still be able to see the information.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscyber-espionagedata-breachowncloudweb-securityvulnerability

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Aug 28, 2026

Source

thehackernews.com

Share

Topics

cyber-espionagedata-breachowncloudweb-securityvulnerability

Related

More from this desk

Aug 28·bleepingcomputer.com

McKesson discloses breach after ShinyHunters claims patient data theft

McKesson discloses breach after ShinyHunters claims patient data theft. McKesson says 284 million patient data records were stolen.

Aug 28·thehackernews.com

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government refuses to pay extortionists who stole data from its state administrative network. Forensic work found further data outflows in the Senate Department for Mobility, Transport, Climate Protection and Environment.

Aug 28·thehackernews.com

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs warns of a critical balance-handling flaw in the shared Cosmos EVM module exploited to drain funds from six blockchains. Fix shipped in v0.6.2 and v0.7.2.

Aug 28·bleepingcomputer.com

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two vulnerabilities in its print management software.