Feels like I'm going to lose this whole day to new networking/backup/NAS issues. A few things snowballing together here I suspect.
There was a silent app change on my NAS (#QNAP) I didn't know about which now is causing probs, simultaneous with a #MacOS update and a new weird routing issue within my LAN.
Chipping away at it and hoping I'll still get to address an item or two from my to-do list for today.
If you have a QNAP NAS please check you're on the latest firmware.
There's been updates for all models and versions, including some 12+ years old. And the releases are done during their new year holidays so something tells me this might be serious.
They have a convenient RSS feed of their releases (thank me) here:
📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #06/2024 is out! It includes the following and much more:
➝ 🔓 #Juniper Support Portal Exposed Customer Device Info
➝ 🔓 🇹🇭 Major #DataBreach in #Thailand Exposes Personal Data of 20 Million Elderly Citizens
➝ 🔓 🇫🇷 Millions at risk of fraud after massive health data hack in #France
➝ 🔓 🇺🇸 #Verizon employee inadvertently leaks data of 63 thousand colleagues
➝ 🔓 🖥️ #AnyDesk Hacked: Revokes Passwords, Certificates in Response
➝ 🔓 🇺🇸 #Clorox says #cyberattack caused $49 million in expenses
➝ 💸 📈 #Ransomware Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline
➝ 🇺🇸 💰 US offers $10 million for tips on #Hive ransomware leadership
➝ 🇨🇳 🇺🇸 #China-backed Volt Typhoon hackers have lurked inside US #criticalinfrastructure for ‘at least five years’
➝ 🇨🇳 🇳🇱 Chinese Hackers Exploited #FortiGate Flaw to Breach Dutch #Military Network
➝ 🇮🇷 🇮🇱 #Iran accelerates cyber ops against #Israel from chaotic start
➝ 🇧🇾 🇺🇸 Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion #Crypto Money Laundering
➝ 🇭🇰 💸 #Finance worker pays out $25 million after video call with #deepfake ‘chief financial officer’
➝ 🇺🇦 #ukraine is Creating a ‘Cyber Diplomat’ Post
➝ 🇩🇰 #Denmark orders schools to stop sending student data to #Google
➝ 🇪🇺 ⚖️ #EU proposes criminalizing AI-generated child sexual abuse and deepfakes
➝ 🇳🇱 💰 #Uber Fined 10 Million Euros by Dutch Data Regulator
➝ 🇺🇸 🛂 US to Roll Out Visa Restrictions on People Who Misuse #Spyware to Target Journalists, Activists
➝ 🦠 💬 Raspberry Robin #Malware Upgrades with #Discord Spread and New Exploits
➝ 🦠 🍎 New #macOS Backdoor Linked to Prominent Ransomware Groups
🦠 🪥 Surprising 3 Million Hacked #Toothbrushes Story Goes Viral—Is It True?
➝ 🇨🇦 🐬 #Canada declares #FlipperZero public enemy No. 1 in car-theft crackdown
➝ 🩹 #Ivanti: Patch new Connect Secure auth bypass bug immediately
➝ 🐛 📍 Security flaw in a popular smart helmet allowed silent location tracking
➝ 🩹 Critical Patches Released for New Flaws in #Cisco, #Fortinet, #VMware Products
➝ 🐛 🐧 Critical Boot Loader #Vulnerability in Shim Impacts Nearly All #Linux Distros
➝ 🐛 ✈️ #Airbus App Vulnerability Introduced Aircraft Safety Risk
➝ 🩹 #QNAP Patches High-Severity Bugs in QTS, Qsync Central
--
📚 This week's recommended reading is: "x86 Software Reverse-Engineering, Cracking, and Counter-Measure" by Stephanie Domas & Christopher Domas
--
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️
I was chosen as beta tester for new #NAS hardware! This is gonna be exciting. Let's see if #Synology & #QNAP has a new competitor worth anything...
BTW: They're sending the unit, but no drives. Weird. You think they'd want to control the entire experience in a beta. Ya' know, so everyone is using the same brand, size, etc...
📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #02/2024 is out! It includes the following and much more:
➝ 🔓 🎽 Halara probes breach after hacker leaks data for 950,000 people
➝ 🔓 💥 #Mandiant's X Account Was Hacked Using Brute-Force Attack
➝ 🔓 🇵🇾 #Paraguay warns of Black Hunt #ransomware attacks after Tigo Business #breach
➝ 🇺🇸 💸 US SEC’s X account hacked to announce fake #Bitcoin ETF approval
➝ 🔓 🇨🇦 Toronto Zoo: Ransomware attack had no impact on animal #wellbeing
➝ 🔓 Mortgage firm loanDepot #cyberattack impacts IT systems, payment portal
➝ 🇫🇮 💸 #Finland warns of Akira ransomware wiping NAS and tape #backup devices
➝ 🇩🇰 🇷🇺 #Sandworm probably wasn’t behind Danish critical infrastructure cyberattack, report says
➝ 🇺🇦 🇷🇺 Pro-Ukraine hackers breach Russian ISP in revenge for #KyivStar attack
➝ 🇫🇷 🇺🇸 French Computer Hacker Jailed in US
➝ 🇳🇬 ⚖️ Nigerian gets 10 years for laundering millions stolen from elderly
➝ 🇹🇷 Turkish Hackers Exploiting Poorly Secured #MSSQL Servers Across the Globe
➝ 🇹🇷 🇳🇱 Turkish #Cyberspies Targeting Netherlands
➝ ☁️ 🇪🇺 #Microsoft Lets Cloud Users Keep Personal Data Within #Europe to Ease #Privacy Fears
➝ 🇺🇸 🇨🇳 #AI is helping US spies catch stealthy Chinese hacking ops, #NSA official says
➝ 🇱🇧 ✈️ Beirut Airport Screens Hacked with Anti-Hezbollah Message
➝ 🇸🇦 Saudi Ministry exposed sensitive data for 15 months
➝ 🇬🇷 #Greece to Establish New Authority to Counter Cyber-Attacks
➝ 🩹 #Siemens, #SchneiderElectric Release First #ICS Patch Tuesday Advisories of 2024
➝ 🐍 ☁️ New #Python-based FBot Hacking Toolkit Aims at #Cloud and #SaaS Platforms
➝ 🦠 📺 #YouTube Videos Promoting Cracked Software Distribute Lumma Stealer
➝ 🦠 🐧 #Linux devices are under attack by a never-before-seen worm
➝ 🦠 🇳🇱 Dutch Engineer Used Water Pump to Get Billion-Dollar #Stuxnet#Malware Into Iranian Nuclear Facility
➝ 🐡 🔐 DSA removal from #OpenSSH
➝ 🩹 #PatchTuesday
➝ 🐛 🔓 Actively exploited 0-days in #Ivanti VPN are letting hackers #backdoor networks
➝ 🔓 🔧 Hackers can infect network-connected wrenches to install ransomware
➝ 🇨🇳 🔓 #AirDrop cracked by #China, revealing phone number and email address of sender
➝ 🩹 #QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products
➝ 🐛 🔓 KyberSlash attacks put #quantum#encryption projects at risk
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️
Security researchers reveal a Mirai-based botnet is exploiting a vulnerability in QNAP VioStor NVR. The botnet has been exploiting two zero-day flaws, tracked as CVE-2023-49897 and CVE-2023-47565, and can result in remote code execution when exploited. QNAP has released software updates to address both vulnerabilities. Administrators are advised to update ASAP. QNAP also recommends a factory reset and changing the default password.
My NAS died last night. It's bricked and won't POST. Apparently there's a way to circumvent the CPU clock design flaw that causes this issue, but it involves soldering a 100 Ohm resistor to the main board. This is quickly getting to "fuck it, I'll buy a new NAS" but I need to get the data off of the drives first (my last backup is a couple of months old)
Anyone else on here with a #QNAP NAS have this issue?
Title: "🚨 QNAP blocks extensive brute-force attacks on Internet-exposed NAS devices 🚨"
QNAP, a networking hardware company, successfully thwarted extensive brute-force attacks on Internet-exposed NAS devices by eliminating a malicious server behind the assault. They swiftly responded to the discovery of weak password attacks, blocking numerous compromised network IPs and locating the source C&C server within 7 and 48 hours, respectively. Brute force attacks involve hackers trying various combinations to crack encryption keys or login credentials. To mitigate such risks, QNAP advises users to disable the "admin" account, use strong passwords, keep firmware and apps updated, employ the QuFirewall application, and utilize myQNAPcloud Link's relay service with non-default ports. Protecting internet-facing NAS devices is crucial, and constant network security vigilance is essential, as highlighted by Stanley Huang, Manager of QNAP's Product Security Incident Response Team.
Hallo fediverse,
Ich will/muss ein paar meiner #homelab Systeme loswerden und bevor ich direkt zu eBay gehe frag ich Mal hier.
U.a. ein kompletter 4U Ryzen 9 3900x Server, Intel x299 HEDT Board inkl. CPU, #Synology ds620 slim, #qnap ts-253Be.
Well, isn't that just great. Want to leave for vacation today and then I see that my #QNAP NAS (TS-453BT3) has just died, and I cannot access the files I need from it.