The Flock Left the Gate Open and Now Someone Has the Nuclear Recipes

The Flock Left the Gate Open and Now Someone Has the Nuclear Recipes

Oh good. Oh, this is just great.

I've been awake since yesterday morning, my third cup of cold coffee is sitting next to a ticket I'll never close, and I just read that a nuclear research body in the Philippines got absolutely cleaned out because someone didn't patch their ownCloud instance. A file-sharing server. Running a known critical vulnerability. At a nuclear facility.

CVE-2023-49105. CVSS 9.8. That's not a score, that's a cry for help.

CISA just slapped it onto the Known Exploited Vulnerabilities catalog, which is their polite way of saying "we told you so, repeatedly, and you still didn't listen." The Coyote in question here appears to be a Chinese-speaking threat actor who clearly had more time to read CVE advisories than the IT team responsible for, you know, protecting nuclear records.

The flaw itself is a WebDAV API authentication bypass. In plain pasture terms: the Electric Fence had a hole in it so wide you could drive a whole flock through sideways, and someone did exactly that.

I want to be mad at the Wolves here. I really do. But honestly? The Wolves did their homework. They found the hole in the fence, they walked through it calmly, and they took what they wanted. The real tragedy is that the shearing schedule existed. The ointment was available. Someone just decided patching could wait until after the weekend.

The weekend came. The nuclear documents did not stay.

The Shepherds are probably in a meeting right now discussing "cyber posture" and "risk appetite" while the actual sysadmin, who is definitely me in a different timezone, is filing incident reports and questioning every life choice that led to this moment.

CISA adding this to KEV is good. It means agencies on the list are required to remediate. Whether they actually do it before the next Coyote shows up is a different conversation I'm too tired to have.

Remediation

Look. I'm begging you. With whatever energy I have left in my body.

  • Patch ownCloud immediately. Version 10.13.1 or later. No excuses. No "we'll get to it." Now.
  • Disable WebDAV if you don't need it. If you don't know what it is, you definitely don't need it.
  • Audit your exposed file-sharing services. If they're facing the internet, they'd better be current and locked down tighter than the Sky Pasture during a thunderstorm.
  • Check CISA's KEV catalog regularly. It's a list of things actively being used against real targets. Treat it like the fence inspection you keep skipping.

The Lambs are not going to save themselves. They never do.

Gonna go find out if my coffee is salvageable. It isn't.


Original Report: https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html