The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical ownCloud security flaw to its Known Exploited Vulnerabilities catalog after reports indicated that a Chinese speaking threat actor exploited the issue to target a Philippine nuclear research organization. The vulnerability, tracked as CVE 2023 49105 with a CVSS score of 9.8, affects the WebDAV API and allows attackers to access, modify, or delete files without authentication under specific conditions. According to CISA, the flaw impacts ownCloud Core versions 10.6.0 through 10.13.0 and was addressed in version 10.13.1 after being disclosed by ownCloud in November 2023. The vulnerability can be exploited if an attacker knows a valid username and the targeted user account has no signing key configured, which is the default setting. CISA added the vulnerability to its catalog after threat intelligence firm Hunt.io reported that the flaw had been actively used in attacks against organizations in the Philippines, including a nuclear research body. Federal Civilian Executive Branch agencies have been instructed to apply the security updates by August 30, 2026.
According to Hunt.io, researchers identified an exposed directory hosted on a remote server that contained custom Python scripts, offensive security tools including Sliver, Metasploit, and Mettle, along with evidence of data collection from two Philippine organizations. One target was a nuclear research institution, while the other was a marine engineering and shipbuilding company that provides services to the Philippine Navy. Investigators said the custom Python scripts specifically targeted an ownCloud deployment by generating pre signed URLs with an empty signing secret, allowing unauthenticated access to files through WebDAV. Hunt.io also reported a separate compromise involving the engineering company, where attackers exploited the LiteSpeed Cache plugin vulnerability tracked as CVE 2024 28000 to obtain elevated access to a WordPress website. In addition, another custom Python script attempted XML RPC brute force attacks to obtain account credentials, providing an alternative method of access independent of the LiteSpeed Cache vulnerability. Researchers attributed the activity to a Chinese speaking operator after identifying simplified Chinese comments, folder names, log outputs, and source code references within the recovered tools and scripts.
Hunt.io found five custom Python scripts designed to exploit CVE 2023 49105. Four of the scripts focused on accessing individual user accounts, while the fifth automated the enumeration of WebDAV directories and recorded every attempted download. Investigators estimated that the threat actor downloaded 176 files totaling approximately 372 megabytes from the nuclear research organization. The reported files included nuclear material account records, draft strategic plans covering the period from 2023 through 2028, research reactor core component documentation, historical fuel inventory records, presentation materials, employee personal information, and a 192 megabyte SQL database dump from a ZKTeco BioTime attendance and personnel management system. Researchers also identified credential related information among the stolen data, including BitLocker recovery keys, a KeePass password database, and AxCrypt encrypted files. Additional analysis of the compromised WordPress website also uncovered an active and possibly unrelated compromise using EtherHiding to retrieve malicious HTML content from an Ethereum smart contract before presenting users with a Google verification page commonly associated with ClickFix style attacks. The attack chain then launched pcalua.exe to execute mshta.exe and download a Visual Basic Script payload.
Hunt.io stated that the activity appeared to be a deliberate intrusion targeting organizations connected to the Philippine nuclear and defense sectors. Researchers noted that the marine engineering company’s relationship with the Philippine Navy aligns with broader regional interests, while the information obtained from the nuclear organization indicates a separate but related objective. Alongside CVE 2023 49105, CISA also added two additional vulnerabilities to its Known Exploited Vulnerabilities catalog. These include CVE 2026 53362 affecting the Linux Kernel and CVE 2026 66384 impacting Artifactory. The additions followed OpenAI’s disclosure that its artificial intelligence agents had exploited both vulnerabilities during internal security testing last month. OpenAI clarified that those activities were unrelated to the incident involving Hugging Face. CISA has directed Federal Civilian Executive Branch agencies to remediate the Linux Kernel vulnerability by August 30, 2026, while patches for the Artifactory vulnerability must be applied by September 10, 2026.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.