Security News

Qlocker ransomware returns to target QNAP NAS devices worldwide
2022-01-15 16:20

Threat actors behind the Qlocker ransomware are once again targeting Internet-exposed QNAP Network Attached Storage devices worldwide. Qlocker has previously targeted QNAP customers in a massive ransomware campaign that started during the week of April 19, moving victims' files within password-protected 7-zip archives with the.7z extension after breaching their NAS devices.

QNAP: Get NAS Devices Off the Internet Now
2022-01-07 16:14

Get your internet-exposed, network-attached storage devices off the internet now, Taiwanese manufacturer QNAP warns: Ransomware and brute-force attacks are widely targeting all network devices. "The most vulnerable victims will be those devices exposed to the Internet without any protection," QNAP said on Friday, urging all QNAP NAS users to follow security-setting instructions that the Taiwanese NAS maker included in its alert.

QNAP warns of ransomware targeting Internet-exposed NAS devices
2022-01-07 13:20

QNAP has warned customers today to secure Internet-exposed network-attached storage devices immediately from ongoing ransomware and brute-force attacks. "QNAP urges all QNAP NAS users to follow the security setting instructions below to ensure the security of QNAP networking devices," the Taiwanese NAS maker said in a press release issued today.

QNAP NAS devices hit in surge of ech0raix ransomware attacks
2021-12-27 16:19

Users of QNAP network-attached storage devices are reporting attacks on their systems with the eCh0raix ransomware, also known as QNAPCrypt. BleepingComputer forum users managing QNAP and Synology NAS systems have been regularly reporting eCh0raix ransomware attacks but more of them started to disclose incidents around December 20.

QNAP NAS devices targeted by new bitcoin miner
2021-12-09 09:56

Unsecured QNAP NAS devices are getting covertly saddled with a new bitcoin miner, QNAP has warned users. "Once a NAS is infected, CPU usage becomes unusually high where a process named '[oom reaper]' could occupy around 50% of the total CPU usage. This process mimics a normal, legitimate kernel process with the same name. However, while the legitimate kernel process PID is usually below 1000, the bitcoin miner PID is usually greater than 1000," the company explained.

Warning: Yet Another Bitcoin Mining Malware Targeting QNAP NAS Devices
2021-12-07 22:33

Network-attached storage appliance maker QNAP on Tuesday released a new advisory warning of a cryptocurrency mining malware targeting its devices, urging customers to take preventive steps with immediate effect. "A bitcoin miner has been reported to target QNAP NAS. Once a NAS is infected, CPU usage becomes unusually high where a process named '[oom reaper]' could occupy around 50% of the total CPU usage," the Taiwanese company said in an alert.

QNAP warns users of bitcoin miner targeting their NAS devices
2021-12-07 13:53

QNAP warned customers today of ongoing attacks targeting their NAS devices with cryptomining malware, urging them to take measures to protect them immediately. Customers who suspect their NAS is infected with this bitcoin miner are advised to restart their device, which may remove the malware.

QNAP Working on Patches for OpenSSL Flaws Affecting its NAS Devices
2021-09-02 04:56

Network-attached storage appliance maker QNAP said it's currently investigating two recently patched security flaws in OpenSSL to determine their potential impact, adding it will release security updates should its products turn out to be vulnerable. "A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash," according to the advisory for CVE-2021-3711.

QNAP works on patches for OpenSSL bugs impacting its NAS devices
2021-08-30 18:21

Network-attached storage maker QNAP is investigating and working on security updates to address remote code execution and denial-of-service vulnerabilities patched by OpenSSL last week. The security flaws tracked as CVE-2021-3711 and CVE-2021-3712, impact QNAP NAS device running QTS, QuTS hero, QuTScloud, and HBS 3 Hybrid Backup Sync, according to advisories [1, 2] published earlier today.

Week in review: Realtek chips vulnerabilities, NAS devices under attack, security teams burnout
2021-08-22 08:00

NAS devices under attack: How to keep them safe?Network-attached storage devices are a helpful solution for storing, managing, and sharing files and backups and, as such, they are an attractive target for cyber criminals. 65 vendors affected by severe vulnerabilities in Realtek chipsA vulnerability within the Realtek RTL819xD module allows attackers to gain complete access to the device, installed operating systems and other network devices.