logo

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

ID: eabc9f96-c8b8-5cd0-9699-3b532d048d57

STIX ID: report--eabc9f96-c8b8-5cd0-9699-3b532d048d57

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-08-28

Date Updated: 2026-08-29

Author: [email protected] (The Hacker News)

...
...

CISA added ownCloud CVE-2023-49105 (CVSS 9.8) to its Known Exploited Vulnerabilities list after Hunt.io discovered an exposed staging host (31.58.209.241) containing custom Python exploits and offensive tooling used to weaponize the WebDAV authentication bypass and exfiltrate 176 files (~372 MB) from a Philippine nuclear research agency; attackers also exploited a LiteSpeed Cache WordPress flaw (CVE-2024-28000) and used XML-RPC brute-force and click-fraud/dropper techniques, with indicators pointing to a Chinese-speaking operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.