[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp2zWZeuJLiwO0YsOjAH2zDuHzDoQBw-SqQBZaXa5nkA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"4e9dbd29-aed9-48ee-9cf0-f26c7f4c0e42","unpatched-owncloud-flaw-enables-nuclear-data-theft","84496f44-ab6b-428e-9883-ab7a73d7307b","Unpatched ownCloud Flaw Enables Nuclear Data Theft","A Chinese-speaking threat actor exploited CVE-2023-49105, a critical WebDAV API authentication bypass in ownCloud, to exfiltrate sensitive nuclear research records from a Philippine government body. The root failure was the organization's inability to apply a known, catalogued patch before attackers could leverage it against critical infrastructure. Authentication bypass vulnerabilities are among the most severe class of flaws because they completely nullify access controls, rendering all downstream security measures ineffective. This incident underscores that unpatched internet-facing file-sharing platforms in sensitive environments represent an unacceptable risk, particularly when the vulnerability is actively tracked by CISA's KEV catalog. State-sponsored threat actors routinely scan for and weaponize known CVEs within days of disclosure, leaving organizations with narrow windows to remediate.","**Immediate actions:**\n- Apply the official ownCloud patch for CVE-2023-49105 immediately, or take the service offline until patching is complete.\n- Audit all internet-facing file-sharing and collaboration platforms for unresolved critical CVEs using an automated vulnerability scanner.\n- Revoke and rotate all credentials and access tokens associated with the compromised ownCloud instance.\n\n**Long-term improvements:**\n- Establish a formal emergency patching SLA (e.g., critical CVEs patched within 24–72 hours) with mandatory compliance tracking for all internet-facing systems.\n- Maintain a continuously updated asset inventory that flags systems running software listed in CISA's Known Exploited Vulnerabilities catalog.\n- Implement network segmentation to isolate file-sharing services handling sensitive or classified data from the broader organizational network.\n\n**Detection measures:**\n- Deploy Web Application Firewall (WAF) rules and anomaly-based detection specifically targeting WebDAV API abuse and unauthenticated access patterns.\n- Enable centralised logging of all authentication events on file-sharing platforms and alert on any access where authentication was not completed successfully.\n- Subscribe to threat intelligence feeds (e.g., CISA KEV, NVD) and integrate them into your vulnerability management workflow to ensure zero-day and newly catalogued CVEs trigger immediate review.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 6: Access Control Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST CSF ID.VM-1: Vulnerabilities are identified and documented","NIST CSF PR.AC-3: Remote access is managed","ISO\u002FIEC 27001:2022 A.8.8: Management of technical vulnerabilities","CISA KEV Catalog: CVE-2023-49105","ITIL 4: Change Enablement (emergency change procedure)","published","2026-08-28T20:21:56.05893+00:00","2026-08-28T20:21:55.976+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsnowflake-github-actions-flaw-lets.html","owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body-9ef134","ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"dba25329-5397-4372-abf5-4e824e3c58cd","2026-08-29","morning","ThreatNoir Weekend Brief — August 29","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-29\u002Fthreatnoir-morning-brief-2026-08-29.mp3"]