
CISA Adds Critical ownCloud Flaw to KEV Catalog After Exploitation by Chinese Threat Actor
CybersecurityVulnerabilitiesThreatActorsDataTheft
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical ownCloud flaw (CVE-2023-49105, CVSS score: 9.8) to its Known Exploited Vulnerabilities (KEV) catalog. A Chinese-speaking threat actor exploited this vulnerability to target a nuclear research body in the Philippines. The attack involved weaponizing the flaw to steal nuclear records.