Search
Find merged stories by title or summary.
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2023-49105 ownCloud Improper Authentication Vulnerability • CVE-2026-53362 Linux Kernel Unspecified Vulnerability • CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability CVE-2023-49105 (CVSS score of 9. 8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2023-49105 ownCloud Improper Authentication Vulnerability • CVE-2026-53362 Linux Kernel Unspecified Vulnerability • CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Chinese-Speaking Hackers Exploit Known Flaws to Steal Philippine Nuclear and Naval Data
Suspected Chinese-speaking hackers exploited known vulnerabilities to steal sensitive data from a Philippine nuclear research organization and a marine engineering company serving the Philippine Navy. Researchers at Hunt.io discovered an exposed attacker server on August 13, 2026, containing custom exploit scripts, stolen files, logs, and offensive tools. The activity comes amid heightened South China Sea tensions and continued cyber espionage targeting Philippine government, defense, research, and infrastructure organizations. The attackers targeted an internet-facing ownCloud server operated by a Philippine nuclear research body. They exploited CVE-2023-49105, a critical ownCloud authentication bypass affecting vulnerable versions that use an empty pre-signed URL signing secret.
CVE-2023-49105 - ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
You've reached the end of current stories for this search.
