Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2023-49105] Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

Summary

Hunt.io details intrusions on two Philippine organizations by a suspected Chinese-speaking operator: ownCloud at a nuclear research body breached via CVE-2023-49105 (empty signing secret allowing unauthenticated WebDAV reads), and a naval contractor's WordPress site, with roughly 9GB stolen.

Why it matters

This threat intelligence report documents active targeting of critical national infrastructure and defense contractors through edge application vulnerabilities.
Published
Collected

original ↗

Related coverage

back