Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Philippine research and defense-related organizations
Incident: Exploitation of an ownCloud authentication bypass to steal nuclear and industrial data.
Impact: Theft of sensitive nuclear material records, strategic plans, and personnel databases.
Attacker: Chinese-speaking threat actors
Analysis: The attacker leveraged CVE-2023-49105, a WebDAV API authentication bypass, to gain unauthorized access to files without providing credentials. By utilizing pre-signed URLs and exploiting default configurations lacking signing keys, the actor exfiltrated strategic plans and personnel data. Forensic evidence, including simplified Chinese in source code and logs, suggests the operation was conducted by a Chinese-speaking threat actor.
Recommendations: Update ownCloud installations to version 10.13.1 or later immediately.; Ensure a signing key is configured for WebDAV to prevent authentication bypass.; Audit server logs for unauthorized WebDAV requests and unusual file download volumes.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source