Security News

New Linux Malware Exploits SambaCry Flaw to Silently Backdoor NAS Devices (The Hackers News)
2017-07-19 01:23

Remember SambaCry? Almost two months ago, we reported about a 7-year-old critical remote code execution vulnerability in Samba networking software, allowing a hacker to remotely take full control...

Attackers are taking over NAS devices via SambaCry flaw (Help Net Security)
2017-07-18 20:57

A Samba remote code execution flaw patched in May is being exploited to compromise IoT devices running on different architectures (MIPS, ARM, PowerPC, etc.), Trend Micro researchers warn. Samba is...

Malware Targets NAS Devices Via SambaCry Exploit (Security Week)
2017-07-18 16:24

A piece of malware dubbed by researchers SHELLBIND leverages a recently patched Samba vulnerability in attacks aimed at Internet of Things (IoT) devices, particularly network-attached storage...

Travel Routers, NAS Devices Among Easily Hacked IoT Devices (Threatpost)
2017-04-10 19:04

A researcher poked holes in seven different IoT devices at last week's Security Analyst Summit, including a host of travel routers, NAS devices, and an IP-enabled camera.

QNAP NAS devices open to remote command execution (Help Net Security)
2017-04-07 20:14

If you’re using one of the many QNAP NAS devices and you haven’t yet upgraded the QTS firmware to version 4.2.4, you should do so immediately if you don’t want it to fall prey to attackers. Among...

Western Digital My Cloud NAS devices wide open to attackers (Help Net Security)
2017-03-08 16:51

Western Digital My Cloud NAS devices have again been found wanting in the security department, as two set of researchers have revealed a number of serious flaws in the devices’ firmware. WD My...

Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack (Threatpost)
2017-03-07 18:58

Western Digital NAS owners were warned of critical flaws in the company’s My Cloud line of hardware that opened up data stored on those devices to attack.

Insecure NAS Device Exposes 350 Ameriprise Investment Accounts (Threatpost)
2016-12-19 17:18

A trove of data belonging to Ameriprise Financial was found earlier this month and included Social Security number, decryption keys and confidential internal company documents.