Find notable cyber news and cases, enriched with sources, timelines, and signals.

Nuclear research body in Philippines hit by network compromise

Incident
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The compromise is tied to CVE-2023-49105, a critical WebDAV authentication bypass that let the attacker access data without supplying credentials. The stolen material included research records, employee personal information, and credential stores, increasing follow-on compromise risk.

Related Happenings

OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)

Vulnerability
H score43 First: 28.08.2026 18:56 Last: 28.08.2026 18:56 Sources 1

How related: The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration.

About this happening: CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The fl...

Philippine nuclear research body ownCloud file leak

Data Leak
H score31 First: 28.08.2026 18:56 Last: 28.08.2026 18:56 Sources 1

How related: In all, the threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories.

About this happening: A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included...

DoJ charges Mabna Institute members and State Department offers reward

Law Enforcement
H score70 First: 20.08.2026 20:23 Last: 20.08.2026 20:23 Sources 1

About this happening: U.S. Department of Justice charged 17 Mabna Institute members in a cyber intrusion case tied to Iran's IRGC, and the U.S. Department of State announced a $10...

Zestix sells stolen corporate data from ShareFile, Nextcloud, and ownCloud

Data Leak
H score87 First: 06.01.2026 00:52 Last: 06.01.2026 00:52 Sources 1

About this happening: Zestix is offering stolen corporate data from dozens of companies, with the files tied to ShareFile, Nextcloud, and ownCloud accounts. The reporting indicates that the activity in...

Latest development: 07.01.2026 16:34

Zestix is reported to be offering corporate data stolen from dozens of companies, with the likely access path described as infostealer malware on employee devices feeding stolen credentials into ShareFile, Nextcloud, and ownCloud accounts. In response to related credential-theft reporting, ownCloud warned users to enable MFA, reset passwords, invalidate active sessions, and review access logs, while saying the platform was not hacked or breached and that no zero-day exploits or platform vulnerabilities were involved.

Timeline

  1. 28.08.2026 18:56 2 articles · 5h ago

    CISA adds CVE-2023-49105 to KEV after ownCloud compromise of a Philippine nuclear research body

    Initial Disclosure

    CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog after Hunt.io reported that a Chinese-speaking threat actor used custom Python scripts to exploit an ownCloud instance operated by a nuclear research body in the Philippines, retrieve files over WebDAV with pre-signed URLs generated from an empty signing secret, and exfiltrate 176 files totaling about 372 MB, including research records, employee personal information, and credential stores.

    Show sources