FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Espionage Campaign Exploiting ownCloud CVE-2023-49105 to Target Philippine Nuclear Research

A sophisticated espionage campaign, attributed to Chinese-speaking threat actors, successfully compromised the Philippine Nuclear Research Agency by exploiting CVE-2023-49105. This critical authentication bypass vulnerability in ownCloud, stemming from an empty signing secret, enabled unauthorized access to sensitive document repositories. Post-exploitation, the adversary employed Microsoft Teams-based vishing, deployed the GoGRPC backdoor, and utilized the Sliver C2 framework to maintain persistence. The breach resulted in the exfiltration of critical nuclear research and naval defense documentation, highlighting the extreme risks of misconfigured authentication secrets in centralized document management systems.


LINK COPIED TO CLIPBOARD