A threat actor exploited a long-patched vulnerability in the file-sharing platform ownCloud to steal reactor data, personnel records and stored credentials from a Philippine nuclear research organization, according to researchers who found the stolen material staged on attacker-controlled infrastructure.
A Two-Year-Old Bug in a Default Configuration
Threat-hunting firm Hunt.io published a blog post on August 26, 2026 identifying an ownCloud server hosted in Amsterdam that appeared to function as a staging hub for a suspected Chinese-speaking operator, containing offensive tooling alongside data taken from at least two victims: a Philippine nuclear research agency and a marine engineering and shipbuilding company serving the Philippine Navy. The intrusion exploited CVE-2023-49105, an authentication bypass in ownCloud’s pre-signed URL mechanism disclosed by the vendor in November 2023 and carrying a CVSS score of 9.8. On installations left in ownCloud’s default configuration, with no signing key configured, an attacker who knows a valid username can construct requests the system accepts as authenticated, letting them access, modify or delete files without ever supplying a password.
Reactor Records, Personnel Files and Stored Credentials
The material recovered from the nuclear agency’s staging folders, roughly 372 MB across 176 files, included a database of research-reactor core components, historical fuel inventories, radiation-safety documentation, incident records, and a 192 MB database dump from a biometric attendance and personnel system, alongside employee resumes, travel records and financial disclosures. Investigators also found a KeePass password database, AxCrypt-encrypted files and a PDF containing a BitLocker recovery key among the stolen material, credential artifacts that could help an attacker move further into connected systems. A separate recovered inventory suggested roughly 9 GB of data may have been taken from the agency in total, though only a fraction was directly recovered by researchers.
CISA Adds the Flaw to Its Exploited Catalog
The US Cybersecurity and Infrastructure Security Agency added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog on August 27, 2026, one day after Hunt.io’s disclosure, formally flagging a nearly three-year-old bug as under active exploitation. The incident illustrates a recurring pattern in intrusions against sensitive government and research infrastructure: the vulnerability exploited was neither novel nor unpatched by the vendor, but a long-available fix that an internet-facing, self-hosted file-sharing system had apparently never received.

Leave a Reply