ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME18:01:57 UTC
← All briefs
CRITICALCyber IntelligenceSaturday, August 29, 2026

Chinese Actor Exploits ownCloud Flaw, Steals Philippine Nuclear Records

CISA adds critical vulnerability to exploit catalog after breach at Philippine research body. Chinese-speaking threat actor weaponized file-sharing flaw.

The U.S. Cybersecurity and Infrastructure Security Agency added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities catalog Thursday following a confirmed breach at a Philippine nuclear research institution.

The flaw, tracked as CVE-2023-49105 with a CVSS score of 9.8, was exploited by a Chinese-speaking threat actor to access and exfiltrate nuclear research records. The vulnerability's addition to the KEV catalog signals active exploitation in the wild and mandates remediation by federal agencies within prescribed timelines.

ownCloud, an open-source file-sharing and collaboration platform, is deployed across research institutions, enterprises, and government agencies globally. The severity rating reflects the ease of exploitation and the potential for unauthorized access to sensitive data stores. CISA's catalog inclusion typically follows confirmed incidents where adversaries have successfully weaponized a vulnerability against operational targets.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Federal agencies must patch ownCloud instances per CISA binding operational directive timelines.
  • 02Research institutions and defense contractors face elevated risk from targeted exploitation campaigns.
  • 03Nuclear sector entities should audit file-sharing platforms for unauthorized access indicators.
  • 04Organizations in Indo-Pacific region should review exposure to Chinese-attributed threat actors.
Source
The Hacker News
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#owncloud#cve-2023-49105#cisa kev#nuclear research#chinese threat actor#philippines
Related Briefs