<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aowncloudowncloud_server/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 14:16:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aowncloudowncloud_server/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Chinese-Speaking Operator Targets Philippine Nuclear and Naval Infrastructure</title><link>https://feed.craftedsignal.io/briefs/2026-08-philippine-targets/</link><pubDate>Wed, 26 Aug 2026 14:16:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-philippine-targets/</guid><description>A suspected Chinese-speaking operator is targeting Philippine governmental and defense entities by exploiting ownCloud and LiteSpeed Cache vulnerabilities to exfiltrate personnel data and deploy loaders.</description><content:encoded><![CDATA[<p>Security researchers have identified a suspected Chinese-speaking threat actor targeting Philippine governmental organizations and naval contractors. The adversary is leveraging known vulnerabilities in public-facing web applications to gain initial access, facilitate data exfiltration, and establish persistence. Specific targets included the Philippine nuclear research body and a defense-affiliated naval contractor. The campaign exhibits sophisticated tradecraft, including the use of randomized sleep intervals to evade volumetric network detection and the deployment of an EtherHiding loader mechanism that retrieves malicious payloads directly from Ethereum smart contracts. The operator successfully exfiltrated a 192 MB SQL dump containing ZKTeco BioTime attendance and personnel data. The targeting suggests a strategic interest in Philippine science, research, and defense sectors.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access to ownCloud infrastructure obtained by exploiting CVE-2023-49105 (information disclosure vulnerability).</li>
<li>Abuse of WebDAV pre-signed URLs to perform reconnaissance via PROPFIND requests with Depth: 1 headers.</li>
<li>Exfiltration of files distributed across multiple compromised user accounts to evade detection.</li>
<li>Initial access to a naval contractor via exploitation of CVE-2024-28000 in the LiteSpeed Cache WordPress plugin.</li>
<li>Brute force attacks against the WordPress /xmlrpc.php endpoint using wordlists like rockyou.txt to gain administrative or elevated access.</li>
<li>Deployment of an EtherHiding loader on a compromised WordPress site to pull secondary payloads from an Ethereum smart contract.</li>
<li>Successful exfiltration of a ZKTeco BioTime SQL dump containing personnel and attendance records for affiliated research organizations.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The breach resulted in the confirmed exfiltration of sensitive personnel records belonging to multiple Philippine science and research organizations. The impact includes the compromise of PII and operational data stored within ZKTeco BioTime systems. Continued exploitation of these vulnerabilities poses a significant risk to regional defense and research entities, with 174 unique IP addresses observed interacting with the malicious loader mechanism alone.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2023-49105 on all ownCloud instances immediately.</li>
<li>Update LiteSpeed Cache plugins to remediate CVE-2024-28000.</li>
<li>Audit web server logs for PROPFIND requests with Depth: 1 headers originating from anomalous sources.</li>
<li>Disable /xmlrpc.php on all WordPress installations if not strictly required for business operations.</li>
<li>Deploy the Sigma rules below to detect brute-force attempts and suspicious WebDAV enumeration.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>espionage</category><category>web-exploitation</category><category>data-exfiltration</category></item></channel></rss>