Critical ownCloud Flaw Exploited in Attack on Philippine Nuclear Research Agency
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in ownCloud, a popular file-sharing and collaboration platform, to its Known Exploited Vulnerabilities (KEV) catalog. The move follows reports that a Chinese-speaking threat actor exploited the vulnerability, tracked as CVE-2023-49105 with a near-maximum severity score of 9.8, to breach a nuclear research organisation in the Philippines and steal sensitive records.
Addition to the KEV catalog means CISA has confirmed active, real-world exploitation of the flaw, prompting government agencies in the U.S. to patch it within a set deadline. While the direct target was a research body rather than a typical small business, the case is a reminder that organisations using vulnerable versions of widely deployed software can become targets for espionage-linked threat actors, regardless of size or sector.
File-sharing platforms like ownCloud are common in many businesses for internal collaboration and storing sensitive documents, making unpatched instances an attractive entry point for attackers. Organisations should check whether they run ownCloud or similar platforms and confirm they are on patched, supported versions.