ON
← Back to feed
Nextcloud: Confusion over site disruption Cyber Cyberattack is confirmed
Germany🏛️ PoliticsCenter2 days ago

Nextcloud: Confusion over site disruption Cyber Cyberattack is confirmed

On Sunday, Nextcloud's website went temporarily offline, causing confusion among users. Initially, Nextcloud attributed the outage to infrastructure issues and claimed it did not affect customers or downloads. However, after being asked by heise security, Nextcloud confirmed that a cyberattack was the cause. The company isolated the affected server and restored the site from a backup. They emphasized that their other services, such as downloads and the app store, remained unaffected. Further investigation is ongoing, and Nextcloud has noted that recent security vulnerabilities in WordPress, known as 'WP2Shell,' could potentially be related to the incident.

Nextcloud confirmed on Monday that its website was temporarily taken offline due to a cyberattack, following initial confusion and mixed statements from the company. The incident occurred on Sunday, affecting the main website at nextcloud.com. Users expressed concern through the Nextcloud Help Forum, prompting the company’s Developer Relations team to initially attribute the outage to infrastructure issues. They stated that the site would be restored from a backup and emphasized that it had no impact on user data, downloads, or updates. The situation took a turn after further inquiries from heise security. A spokesperson for Nextcloud admitted that a cyberattack was the cause of the disruption. “Our website was the target of an attack on Sunday evening,” they said. “We immediately isolated the affected server and are currently investigating exactly what happened.” The homepage was subsequently restored from a backup onto a new server. The company reiterated that this incident did not affect users' servers or their services, as these operate on separate infrastructure from the public-facing website. Nextcloud runs its website using WordPress as its content management system. Over the weekend, multiple cybersecurity firms identified a chain of vulnerabilities in the WordPress core known as “WP2Shell.” These flaws allow attackers to inject malicious code into websites. Several attacks exploiting these weaknesses have already been documented in the wild. In response to further questions from heise security, Nextcloud acknowledged that it could not rule out the possibility that WP2Shell was responsible for the outage. “We are also examining this direction,” the company added, though it noted that confirmation was still pending. The company has not yet released detailed findings from its investigation. It continues to monitor the situation and plans to provide more information once additional details become available. At present, there is no indication that the breach compromised user data or disrupted other services. Nextcloud has assured customers that all critical operations, including the app store and download functionality, remain unaffected. The incident highlights the growing risks associated with using open-source platforms like WordPress for high-profile websites. While WordPress is widely used and generally secure, recent discoveries of critical vulnerabilities underscore the need for continuous monitoring and timely patching. Cybersecurity experts warn that such vulnerabilities can be exploited by both individual hackers and organized groups seeking to disrupt services or steal sensitive information. In light of the ongoing investigation, Nextcloud is likely to take steps to enhance its security measures, particularly around its public-facing infrastructure. This may include updating its WordPress setup, implementing stronger access controls, and increasing surveillance for potential threats. The company has also advised users to ensure their systems are up to date with the latest security patches, especially given the widespread nature of the WP2Shell vulnerabilities. For now, the focus remains on determining the exact cause of the outage and assessing whether any broader implications exist. As Nextcloud continues its analysis, the broader cybersecurity community will be watching closely to see how the company responds and what lessons might be learned from the incident. Until further details emerge, the situation remains under active review.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 75Objective 602 days ago
Nextcloud: Confusion over site disruption Cyber Cyberattack is confirmed

On Sunday, Nextcloud's website went temporarily offline, causing confusion among users. Initially, Nextcloud attributed the outage to infrastructure issues and claimed it did not affect customers or downloads. However, after being asked by heise security, Nextcloud confirmed that a cyberattack was the cause. The company isolated the affected server and restored the site from a backup. They emphasized that their other services, such as downloads and the app store, remained unaffected. Further investigation is ongoing, and Nextcloud has noted that recent security vulnerabilities in WordPress, known as 'WP2Shell,' could potentially be related to the incident.

Bias read (Center): The article presents a factual account of a technical incident involving a cybersecurity breach at Nextcloud. While the issue involves a potential cyberattack, which could have broader implications for data security and corporate responsibility, the tone remains neutral. The reporting does not take,

Why factuality (75): The article reports that Nextcloud initially stated an infrastructure issue caused the outage but later confirmed a cyberattack upon request. This aligns with the primary source document which mentions the initial explanation and subsequent clarification. However, the article does not mention the sp

Why objectivity (60): The article presents the information in a somewhat sensationalized manner by using terms like 'Wirrwarr' (confusion) and 'Cyberangriff bestätigt' (cyberattack confirmed). It frames the situation as a confirmed cyberattack, which may imply more urgency than the original statement. While it provides b

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories