OWNCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

ownCloud users are at risk of a critical security flaw that was exploited to steal sensitive data.

Bottom line: ownCloud users are at risk of a critical security flaw that was exploited to steal sensitive data.

What's happening: ownCloud, a popular open-source file-sharing platform, was targeted by a Chinese-speaking threat actor who used the CVE-2021-22583 vulnerability to gain unauthorized access to sensitive data. The attack targeted a nuclear research body in the Philippines, according to reports. The vulnerability was first identified in July 2021.

What to do: ownCloud users should update to version 20.0.14 or later, and review their data for any unauthorized access. CISA recommends that organizations using ownCloud implement additional security controls, such as multi-factor authentication and data encryption.

Source: The Hacker News