Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited old unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing reactor databases, personnel records, and credentials.
Attackers used commodity vulnerabilities in ownCloud as their initial access vector to compromise the Philippines nuclear agency. Stolen data reportedly includes reactor databases, personnel records, and credential stores. The flaws had gone unpatched, allowing sustained access to internal systems. The incident underscores continued exploitation of known file-sharing vulnerabilities against critical infrastructure targets.
- Initial access gained through unpatched, commodity ownCloud vulnerabilities
- Reactor databases, personnel records, and credential stores were stolen
- Victim is a national nuclear agency, a critical-infrastructure target
- Incident highlights defenders' ongoing struggles patching known vulnerabilities
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.