Critical ownCloud Flaw Exploited in Nuclear Data Theft
A critical ownCloud vulnerability was used by a Chinese-speaking group to steal sensitive nuclear research data from a Philippine institute. CISA has added the flaw to its KEV catalog.
TL;DR
- CVE-2023-49105 (CVSS 9.8) in ownCloud was exploited by a Chinese-speaking threat actor.
- The attack targeted a Philippine nuclear research organization.
- CISA has added the flaw to its Known Exploited Vulnerabilities catalog.
- The vulnerability allows unauthorized access and data theft.
- Organizations using ownCloud should patch immediately.
A high-severity vulnerability in ownCloud has been actively exploited to compromise sensitive systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
The issue, identified as CVE-2023-49105, carries a near-maximum CVSS score of 9.8. It has reportedly been weaponized by a Chinese-speaking advanced persistent threat (APT) group to infiltrate a nuclear research institution in the Philippines. This incident underscores the real-world risks posed by unpatched collaboration platforms.
Vulnerability Details
- CVE-2023-49105 is a critical flaw in ownCloud with a CVSS score of 9.8.
- It enables unauthorized remote attackers to gain access to sensitive files and user credentials.
- The vulnerability affects certain versions of ownCloud Server prior to specific patches.
- Exploitation does not require authentication, increasing its severity.
Attack Impact and Response
- A Chinese-speaking threat actor used the flaw to access a Philippine nuclear research body's data.
- Stolen information included sensitive nuclear-related records.
- CISA has mandated federal agencies to remediate the flaw within set deadlines.
- Security experts recommend immediate patching and monitoring for indicators of compromise.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.