Summary Points
- CISA listed a critical ownCloud vulnerability (CVE-2023-49105, CVSS 9.8) in its KEV catalog, exploited by Chinese threat actors to target Philippine nuclear and maritime organizations.
- Attackers used forged WebDAV requests and malicious scripts to access, exfiltrate, and steal sensitive files, including nuclear data and personal information, from a Philippine nuclear research body.
- The threat actors also exploited a WordPress plugin flaw (CVE-2024-28000, CVSS 9.8) and XML-RPC brute-force attacks to compromise other Philippine companies’ systems.
- Additional flaws in Linux Kernel and Artifactory were added to the KEV catalog after being exploited by AI agents; agencies are advised to patch these vulnerabilities by late 2026.
Security Flaw in ownCloud Exposes Sensitive Data
Recently, a major security flaw in ownCloud, a popular file-sharing service, was exploited to access confidential records from a Philippine nuclear research body. The flaw, identified as CVE-2023-49105, allowed hackers to bypass authentication through a WebDAV API vulnerability. This happened because the default system configuration lacked a signing-key, which is necessary for secure access. As a result, cybercriminals could access, modify, or delete files without needing proper login credentials. The issue impacted certain versions of ownCloud from 10.6.0 to 10.13.0 and was fixed in version 10.13.1. Authorities added this flaw to their catalog of exploited vulnerabilities shortly after reports surfaced of a threat actor stealing thousands of files. These stolen files include nuclear material records, strategic plans, and personal employee information, potentially jeopardizing national security. The attackers used malicious scripts hosted on an exposed server to access the organization’s data, revealing how serious the threat was and emphasizing the need for swift cybersecurity responses.
Widespread Impact and Broader Security Risks
In addition to the ownCloud breach, attackers targeted other digital platforms linked to Philippine organizations, including a marine engineering company working with the Navy. Exploiting known vulnerabilities in WordPress, such as the CVE-2024-28000 flaw, hackers gained high-level access to the company’s site. They also used brute-force techniques on XML-RPC protocols to crack account passwords, creating multiple pathways for unauthorized entry. Security analysts identified five Python scripts that enabled these intrusions, with one script tracking all download attempts and allowing the hackers to exfiltrate nearly 372 MB of sensitive data. The stolen information included nuclear research documents, draft strategic plans, and encrypted credentials. Furthermore, unrelated malware activity involved manipulating Ethereum smart contracts and launching covert downloads of malicious scripts. These incidents highlight how vulnerabilities in widely used software and plugins can be exploited by state-affiliated or independent actors to compromise critical national infrastructure. Experts stress the importance of implementing timely patches and stricter security measures to safeguard vital data and prevent future attacks.
Expand Your Tech Knowledge
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
DataProtection-V1
