Security News

QNAP patches QTS vulnerabilities allowing NAS device takeover
2020-12-07 09:10

Network-attached storage maker QNAP today released security updates to address vulnerabilities that could enable attackers to take control of unpatched NAS devices following successful exploitation. The eight vulnerabilities patched today by QNAP affect all QNAP NAS devices running vulnerable software.

Routers, NAS Devices, TVs Hacked at Pwn2Own Tokyo 2020
2020-11-09 09:39

Bug bounty hunters have hacked routers, network-attached storage devices and smart TVs at the Zero Day Initiative's Pwn2Own Tokyo 2020 hacking competition. Due to the COVID-19 pandemic, the competition has been turned into a virtual event and Pwn2Own Tokyo is actually coordinated by Trend Micro's ZDI from Toronto, Canada, with participants demonstrating their exploits remotely.

NETGEAR Router, WD NAS Device Hacked on First Day of Pwn2Own Tokyo 2020
2020-11-06 15:52

Bug bounty hunters hacked a NETGEAR router and a Western Digital network-attached storage device on the first day of the Zero Day Initiative's Pwn2Own Tokyo 2020 hacking competition. On the first day of the event, the NETGEAR Nighthawk R7800 router was targeted by Team Black Coffee, Team Flashback, and teams from cybersecurity firms Starlabs and Trapa Security.

QNAP warns of Windows Zerologon flaw affecting some NAS devices
2020-10-21 13:06

Network-attached storage device maker QNAP warns customers that some NAS storage devices running vulnerable versions of the QTS operating system are exposed to attacks attempting to exploit the critical Windows ZeroLogon vulnerability. While NAS devices aren't commonly used as a Windows domain controller, some organizations might want to use this feature to allow IT admins to use some NAS models to manage user accounts, authentication, and enforce domain security.

Hackers Are Targeting a Three-Year Old Vulnerability in QNAP NAS Devices
2020-09-02 17:21

Recent attacks targeting QNAP Network Attached Storage devices were attempting to exploit a vulnerability that was addressed in July 2017, 360 Netlab security researchers say. Analysis of the QNAP NAS vulnerability revealed that it resides in the CGI program /httpd/cgi-bin/authLogout.

Seagate updates its IronWolf and IronWolf Pro NAS drive portfolio with 18TB HDD and new SSDs
2020-09-02 01:00

The company also announced an update to its IronWolf and IronWolf Pro Network Attached Storage drive lines, aimed at home and small office environments, with new 18TB capacity HDD and new SATA SSD models. "Our upgrades to the IronWolf and IronWolf Pro family of NAS products will provide small and medium businesses with the robust data management infrastructure they need as they plan for the future."

US, UK Warn of Malware Targeting QNAP NAS Devices
2020-07-28 10:44

In a joint alert this week, the United States and the United Kingdom warned that a piece of malware has infected over 62,000 QNAP network-attached storage devices. "Due to these data breach concerns, QNAP devices that had been infected may still be vulnerable to reinfection after removing the malware," the company said.

62,000 QNAP NAS devices infected with persistent QSnatch malware
2020-07-28 10:21

There are approximately 62,000 malware-infested QNAP NAS devices located across the globe spilling all the secrets they contain to unknown cyber actors, the US CISA and the UK NCSC have warned. Dubbed QSnatch, the sophisticated malware targets QTS, the Linux-based OS powering QNAP's NAS devices, and is able to log passwords, scrape credentials, set up an SSH backdoor and a webshell, exfiltrate files and, most importantly, assure its persistence by preventing users from installing updates that may remove it and by preventing the QNAP Malware Remover app from running.

QSnatch Data-Stealing Malware Infected Over 62,000 QNAP NAS Devices
2020-07-27 23:57

Called QSnatch, the data-stealing malware is said to have compromised 62,000 devices since reports emerged last October, with a high degree of infection in Western Europe and North America. "All QNAP NAS devices are potentially vulnerable to QSnatch malware if not updated with the latest security fixes," the US Cybersecurity and Infrastructure Security Agency and the UK's National Cyber Security Centre said in the alert.

QSnatch Data-Stealing Malware Infected Over 62,000 QNAP NAS Devices
2020-07-27 23:57

Called QSnatch, the data-stealing malware is said to have compromised 62,000 devices since reports emerged last October, with a high degree of infection in Western Europe and North America. "All QNAP NAS devices are potentially vulnerable to QSnatch malware if not updated with the latest security fixes," the US Cybersecurity and Infrastructure Security Agency and the UK's National Cyber Security Centre said in the alert.