ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
ID: eabc9f96-c8b8-5cd0-9699-3b532d048d57
STIX ID: report--eabc9f96-c8b8-5cd0-9699-3b532d048d57
Feed Name: The Hacker News
CISA added ownCloud CVE-2023-49105 (CVSS 9.8) to its Known Exploited Vulnerabilities list after Hunt.io discovered an exposed staging host (31.58.209.241) containing custom Python exploits and offensive tooling used to weaponize the WebDAV authentication bypass and exfiltrate 176 files (~372 MB) from a Philippine nuclear research agency; attackers also exploited a LiteSpeed Cache WordPress flaw (CVE-2024-28000) and used XML-RPC brute-force and click-fraud/dropper techniques, with indicators pointing to a Chinese-speaking operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
