ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
A critical ownCloud vulnerability (CVE-2023-49105) has been added to CISA's Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor exploited it to breach a Philippine nuclear research organization. The flaw carries a CVSS score of 9.8, indicating severe risk, and is actively being weaponized in the wild. Organizations using ownCloud should prioritize patching this vulnerability immediately.
Berlin's state government has refused to pay extortionists following an August breach of its administrative network, confirming the city as a target of an extortion attempt. Forensic investigations uncovered additional data exfiltration beyond the initial compromise, specifically affecting the Senate Department for Mobility, Transport, Climate Protection and Environment.
Love Electric, a UK broker managing electric-vehicle salary sacrifice schemes, has allegedly suffered a data breach exposing 877,000 driver records now being offered for sale at $600 on a data-breach forum. The incident underscores identity risks inherent in third-party salary sacrifice providers that handle sensitive personal information as part of employee benefit programs. The breach was first advertised by the seller on August 26 on an English-language forum.
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims. The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared first on SecurityWeek.
A cyberattack on Manchester Airports Group compromised personal data belonging to approximately 8.7 million customers across three major English airports: Manchester, London Stansted, and East Midlands. The incident involved unauthorized third-party access to customer information, though specific details about the nature of the exposed data and the attack vector remain unclear from the disclosure. This represents a significant breach affecting a substantial portion of the UK's airport passenger base.