Nuclear research body in Philippines hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The compromise is tied to CVE-2023-49105, a critical WebDAV authentication bypass that let the attacker access data without supplying credentials. The stolen material included research records, employee personal information, and credential stores, increasing follow-on compromise risk.
Related Happenings
OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)
Vulnerability
H score43
First: 28.08.2026 18:56
Last: 28.08.2026 18:56
Sources 1
How related:
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration.
About this happening:
CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The fl...
OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)
VulnerabilityHow related: The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration.
About this happening: CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The fl...
Philippine nuclear research body ownCloud file leak
Data Leak
H score31
First: 28.08.2026 18:56
Last: 28.08.2026 18:56
Sources 1
How related:
In all, the threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories.
About this happening:
A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included...
Philippine nuclear research body ownCloud file leak
Data LeakHow related: In all, the threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories.
About this happening: A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included...
DoJ charges Mabna Institute members and State Department offers reward
Law Enforcement
H score70
First: 20.08.2026 20:23
Last: 20.08.2026 20:23
Sources 1
About this happening:
U.S. Department of Justice charged 17 Mabna Institute members in a cyber intrusion case tied to Iran's IRGC, and the U.S. Department of State announced a $10...
DoJ charges Mabna Institute members and State Department offers reward
Law EnforcementAbout this happening: U.S. Department of Justice charged 17 Mabna Institute members in a cyber intrusion case tied to Iran's IRGC, and the U.S. Department of State announced a $10...
Zestix sells stolen corporate data from ShareFile, Nextcloud, and ownCloud
Data Leak
H score87
First: 06.01.2026 00:52
Last: 06.01.2026 00:52
Sources 1
About this happening:
Zestix is offering stolen corporate data from dozens of companies, with the files tied to ShareFile, Nextcloud, and ownCloud accounts. The reporting indicates that the activity in...
Zestix sells stolen corporate data from ShareFile, Nextcloud, and ownCloud
Data LeakAbout this happening: Zestix is offering stolen corporate data from dozens of companies, with the files tied to ShareFile, Nextcloud, and ownCloud accounts. The reporting indicates that the activity in...
Latest development: 07.01.2026 16:34
Zestix is reported to be offering corporate data stolen from dozens of companies, with the likely access path described as infostealer malware on employee devices feeding stolen credentials into ShareFile, Nextcloud, and ownCloud accounts. In response to related credential-theft reporting, ownCloud warned users to enable MFA, reset passwords, invalidate active sessions, and review access logs, while saying the platform was not hacked or breached and that no zero-day exploits or platform vulnerabilities were involved.
Timeline
-
28.08.2026 18:56 2 articles · 5h ago
CISA adds CVE-2023-49105 to KEV after ownCloud compromise of a Philippine nuclear research body
Initial DisclosureCISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog after Hunt.io reported that a Chinese-speaking threat actor used custom Python scripts to exploit an ownCloud instance operated by a nuclear research body in the Philippines, retrieve files over WebDAV with pre-signed URLs generated from an empty signing secret, and exfiltrate 176 files totaling about 372 MB, including research records, employee personal information, and credential stores.
Show sources
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — thehackernews.com — 28.08.2026 18:56
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — thehackernews.com — 28.08.2026 18:56