Find notable cyber news and cases, enriched with sources, timelines, and signals.

Philippine nuclear research body ownCloud file leak

Data Leak
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

A Philippine nuclear research body suffered a confirmed data leak after a threat actor used an ownCloud flaw to download and stage files. The exposed material included nuclear records, employee personal information, and credential stores, creating theft and follow-on abuse risk.

Related Happenings

Nuclear research body in Philippines hit by network compromise

Incident
H score33 First: 28.08.2026 18:56 Last: 28.08.2026 18:56 Sources 1

How related: The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV," Hunt.io said.

About this happening: A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The...

ShellForce-affiliated leak site publishes stolen identity, corporate, and résumé records

Data Leak
H score29 First: 09.02.2026 23:14 Last: 09.02.2026 23:14 Sources 1

About this happening: A ShellForce-affiliated leak site is publicly posting stolen identity records, corporate data, and résumé databases, turning intrusions into immediate exposure ris...

Timeline

  1. 28.08.2026 18:56 2 articles · 5h ago

    CISA adds ownCloud CVE-2023-49105 to the KEV catalog after Philippine nuclear research body theft reports

    Initial Disclosure

    CISA added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog after reports that a Chinese-speaking threat actor used custom Python scripts and ownCloud WebDAV requests against a Philippine nuclear research body, including pre-signed URLs generated with an empty signing secret. Hunt.io said the operator exfiltrated 176 files totaling about 372 MB from the target and staged the data on host 31.58.209[.]241, with the stolen material including nuclear records, employee information, a ZKTeco BioTime SQL dump, and credential stores.

    Show sources