Chinese-Speaking Hackers Hit Philippine Nuclear Research Agency Through ownCloud Bug

CISA has flagged a critical flaw in the file-sharing tool ownCloud as actively exploited, after attackers used it to steal data from a nuclear research body in the Philippines.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Share

Key points

  • The U.S. Cybersecurity and Infrastructure Security Agency added ownCloud flaw CVE-2023-49105 to its Known Exploited Vulnerabilities list on Thursday.
  • The bug carries a severity score of 9.8 out of 10 and lets attackers reach files without a valid password.
  • A Chinese-speaking hacking crew used the flaw to break into a nuclear research organisation in the Philippines.
  • Federal civilian agencies in the United States must patch affected systems within three weeks.
  • ownCloud published a fix and mitigation guidance in late 2023, but many servers remain unpatched.

The U.S. Cybersecurity and Infrastructure Security Agency, the federal body that tracks active hacking campaigns, has warned that a serious flaw in ownCloud is being used in real attacks. ownCloud is a file-sharing and storage platform used by companies, universities and government agencies to keep documents on their own servers instead of in the public cloud.

The agency, known as CISA, added the bug to its Known Exploited Vulnerabilities catalog on Thursday. That listing is a legal trigger: U.S. federal civilian agencies have to patch it inside a set deadline, usually 21 days.

The flaw is tracked as CVE-2023-49105 and rated 9.8 out of 10 for severity. In plain terms, it lets an attacker access, change or delete files on a vulnerable ownCloud server without needing the right password.

Who got hit?

A nuclear research organisation in the Philippines was breached using the bug, according to reporting from The Hacker News. The attackers were described as a Chinese-speaking group, and the target was a body that handles sensitive scientific records.

No public ransom demand has surfaced. This looks like espionage, not extortion. That fits the pattern of state-linked crews, who tend to steal data quietly rather than lock up files and demand payment.

What is the flaw, exactly?

It is an authentication bypass. That means the software failed to properly check who was on the other end of a request, so an outsider could act as if they were a trusted user. Once inside, an attacker could pull down files, poke around user accounts, and move deeper into the network the ownCloud server sits on.

ownCloud disclosed the issue in November 2023 alongside two other bugs in the same product family. The company published a fix and told customers to update immediately. Many organisations, judging by the fresh exploitation, have still not done so more than a year later.

Should ordinary people worry?

Probably not directly, but the story matters. If your employer runs ownCloud, IT staff should already be patching. If you use a service that stores documents for you, this is a reminder to ask where those files sit and who is responsible for updating the software that holds them.

Anyone whose data may have been kept by the affected Philippine agency should watch for unusual emails claiming to come from that body. Stolen document caches often turn up later in phishing campaigns, where criminals send fake emails that look convincing because they quote real details.

The numbers

Item Detail
Bug ID CVE-2023-49105
Severity 9.8 of 10
Product ownCloud file-sharing server
Disclosed November 2023
Added to CISA KEV Thursday
Federal patch deadline 21 days

CISA's move should push more organisations to patch. The bug has been public for over a year, the fix has been available just as long, and attackers are still finding servers to break into. That is the real story here: not the flaw itself, but how long an easy fix can sit ignored on the internet.

© 2026 Threat Vectr