thoralf, to random German

Mein uraltes #QNAP NAS schwächen zusehends.

Es steht also die Entscheidung an: Womit ersetzen?

Mittels Raspberry Pi und NAS had selbst was bauen?
Irgendwas fertiges kaufen?
Das Budget darf natürlich auch nicht überbordend groß ausfallen.

Auf keinen Fall wird es eine proprietäre Software werden.

Ideen?

ottaross, to random
@ottaross@mastodon.social avatar

Feels like I'm going to lose this whole day to new networking/backup/NAS issues. A few things snowballing together here I suspect.

There was a silent app change on my NAS (#QNAP) I didn't know about which now is causing probs, simultaneous with a #MacOS update and a new weird routing issue within my LAN.

Chipping away at it and hoping I'll still get to address an item or two from my to-do list for today.

governa, to random
@governa@fosstodon.org avatar
leakix, to random
@leakix@mastodon.social avatar

🚨 New plugin for #QNAP indexing hosts vulnerable to CVE-2024-21899.

~8500 vulnerable hosts were found.

Hosting providers & CERTs have been notified.

Patch now!

Thanks: @Gi7w0rm

image/png

certbund, to random German
@certbund@social.bund.de avatar

❗️#CERTWarnung❗️
Für eine OS Command Injection #Schwachstelle in den sehr weitverbreiteten #QNAP NAS-Lösungen wurde #PoC-Code veröffentlicht. Betreiber sollten schnellstmöglich die empfohlenen Schutzmaßnahmen prüfen! #PatchNow
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213941-1032

peturdainn, (edited ) to random
@peturdainn@mastodon.social avatar

If you have a QNAP NAS please check you're on the latest firmware.

There's been updates for all models and versions, including some 12+ years old. And the releases are done during their new year holidays so something tells me this might be serious.

They have a convenient RSS feed of their releases (thank me) here:

https://www.qnap.com/en/release-notes/qts/feed

A security advisories feed is here:

https://www.qnap.com/en/security-advisory/feed

Or check my forum if you speak Dutch

#QNAP

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🔓 Support Portal Exposed Customer Device Info
➝ 🔓 🇹🇭 Major in Exposes Personal Data of 20 Million Elderly Citizens
➝ 🔓 🇫🇷 Millions at risk of fraud after massive health data hack in
➝ 🔓 🇺🇸 employee inadvertently leaks data of 63 thousand colleagues
➝ 🔓 🖥️ Hacked: Revokes Passwords, Certificates in Response
➝ 🔓 🇺🇸 says caused $49 million in expenses
➝ 💸 📈 Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline
➝ 🇺🇸 💰 US offers $10 million for tips on ransomware leadership
➝ 🇨🇳 🇺🇸 -backed Volt Typhoon hackers have lurked inside US for ‘at least five years’
➝ 🇨🇳 🇳🇱 Chinese Hackers Exploited Flaw to Breach Dutch Network
➝ 🇮🇷 🇮🇱 accelerates cyber ops against from chaotic start
➝ 🇧🇾 🇺🇸 Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Money Laundering
➝ 🇭🇰 💸 worker pays out $25 million after video call with ‘chief financial officer’
➝ 🇺🇦 is Creating a ‘Cyber Diplomat’ Post
➝ 🇩🇰 orders schools to stop sending student data to
➝ 🇪🇺 ⚖️ proposes criminalizing AI-generated child sexual abuse and deepfakes
➝ 🇳🇱 💰 Fined 10 Million Euros by Dutch Data Regulator
➝ 🇺🇸 🛂 US to Roll Out Visa Restrictions on People Who Misuse to Target Journalists, Activists
➝ 🦠 💬 Raspberry Robin Upgrades with Spread and New Exploits
➝ 🦠 🍎 New Backdoor Linked to Prominent Ransomware Groups
🦠 🪥 Surprising 3 Million Hacked Story Goes Viral—Is It True?
➝ 🇨🇦 🐬 declares public enemy No. 1 in car-theft crackdown
➝ 🩹 : Patch new Connect Secure auth bypass bug immediately
➝ 🐛 📍 Security flaw in a popular smart helmet allowed silent location tracking
➝ 🩹 Critical Patches Released for New Flaws in , , Products
➝ 🐛 🐧 Critical Boot Loader in Shim Impacts Nearly All Distros
➝ 🐛 ✈️ App Vulnerability Introduced Aircraft Safety Risk
➝ 🩹 Patches High-Severity Bugs in QTS, Qsync Central

--

📚 This week's recommended reading is: "x86 Software Reverse-Engineering, Cracking, and Counter-Measure" by Stephanie Domas & Christopher Domas

--

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-062024

jann, to Synology
@jann@twit.social avatar

I was chosen as beta tester for new #NAS hardware! This is gonna be exciting. Let's see if #Synology & #QNAP has a new competitor worth anything...

BTW: They're sending the unit, but no drives. Weird. You think they'd want to control the entire experience in a beta. Ya' know, so everyone is using the same brand, size, etc...

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🔓 🎽 Halara probes breach after hacker leaks data for 950,000 people
➝ 🔓 💥 's X Account Was Hacked Using Brute-Force Attack
➝ 🔓 🇵🇾 warns of Black Hunt attacks after Tigo Business
➝ 🇺🇸 💸 US SEC’s X account hacked to announce fake ETF approval
➝ 🔓 🇨🇦 Toronto Zoo: Ransomware attack had no impact on animal
➝ 🔓 Mortgage firm loanDepot impacts IT systems, payment portal
➝ 🇫🇮 💸 warns of Akira ransomware wiping NAS and tape devices
➝ 🇩🇰 🇷🇺 probably wasn’t behind Danish critical infrastructure cyberattack, report says
➝ 🇺🇦 🇷🇺 Pro-Ukraine hackers breach Russian ISP in revenge for attack
➝ 🇫🇷 🇺🇸 French Computer Hacker Jailed in US
➝ 🇳🇬 ⚖️ Nigerian gets 10 years for laundering millions stolen from elderly
➝ 🇹🇷 Turkish Hackers Exploiting Poorly Secured Servers Across the Globe
➝ 🇹🇷 🇳🇱 Turkish Targeting Netherlands
➝ ☁️ 🇪🇺 Lets Cloud Users Keep Personal Data Within to Ease Fears
➝ 🇺🇸 🇨🇳 is helping US spies catch stealthy Chinese hacking ops, official says
➝ 🇱🇧 ✈️ Beirut Airport Screens Hacked with Anti-Hezbollah Message
➝ 🇸🇦 Saudi Ministry exposed sensitive data for 15 months
➝ 🇬🇷 to Establish New Authority to Counter Cyber-Attacks
➝ 🩹 , Release First Patch Tuesday Advisories of 2024
➝ 🐍 ☁️ New -based FBot Hacking Toolkit Aims at and Platforms
➝ 🦠 📺 Videos Promoting Cracked Software Distribute Lumma Stealer
➝ 🦠 🐧 devices are under attack by a never-before-seen worm
➝ 🦠 🇳🇱 Dutch Engineer Used Water Pump to Get Billion-Dollar Into Iranian Nuclear Facility
➝ 🐡 🔐 DSA removal from
➝ 🩹
➝ 🐛 🔓 Actively exploited 0-days in VPN are letting hackers networks
➝ 🔓 🔧 Hackers can infect network-connected wrenches to install ransomware
➝ 🇨🇳 🔓 cracked by , revealing phone number and email address of sender
➝ 🩹 Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products
➝ 🐛 🔓 KyberSlash attacks put projects at risk

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-022024

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

⚠️ Attention Kyocera & #QNAP users:

Kyocera addresses dangerous CVE-2023-50916 flaw, preventing unauthorized access. QNAP tackles CVE-2023-39296, safeguarding against crashes.

https://thehackernews.com/2024/01/alert-new-vulnerabilities-discovered-in.html

#cybersecurity #informationsecurity

rfwaveio, to Cybersecurity
@rfwaveio@mstdn.ca avatar

Security researchers reveal a Mirai-based botnet is exploiting a vulnerability in QNAP VioStor NVR. The botnet has been exploiting two zero-day flaws, tracked as CVE-2023-49897 and CVE-2023-47565, and can result in remote code execution when exploited. QNAP has released software updates to address both vulnerabilities. Administrators are advised to update ASAP. QNAP also recommends a factory reset and changing the default password.

#cybersecurity #qnap #botnet

https://www.bleepingcomputer.com/news/security/qnap-viostor-nvr-vulnerability-actively-exploited-by-malware-botnet/

James, to random
@James@woof.group avatar

My NAS died last night. It's bricked and won't POST. Apparently there's a way to circumvent the CPU clock design flaw that causes this issue, but it involves soldering a 100 Ohm resistor to the main board. This is quickly getting to "fuck it, I'll buy a new NAS" but I need to get the data off of the drives first (my last backup is a couple of months old)

Anyone else on here with a #QNAP NAS have this issue?

avoidthehack, to Cybersecurity

#QNAP Releases Patch for 2 Critical Flaws Threatening Your #NAS Devices

If you've got a QNAP NAS, time to update.

This security patch fixes two command injection vulnerabilities. (CVE-2023-23368 and CVE-2023-23369)

#cybersecurity #networkstorage #security #cve

https://thehackernews.com/2023/11/qnap-releases-patch-for-2-critical.html

YourAnonRiots, to random Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Alert! #QNAP releases patches for 2 critical security flaws in NAS operating system. Remote attackers could execute commands via network.

https://thehackernews.com/2023/11/qnap-releases-patch-for-2-critical.html

Don't wait – update your NAS devices immediately.

governa, to random
@governa@fosstodon.org avatar

#QNAP Releases Patch for 2 Critical Flaws Threatening Your #NAS Devices

https://thehackernews.com/2023/11/qnap-releases-patch-for-2-critical.html

H3liumb0y, to Cybersecurity

Title: "🚨 QNAP blocks extensive brute-force attacks on Internet-exposed NAS devices 🚨"

QNAP, a networking hardware company, successfully thwarted extensive brute-force attacks on Internet-exposed NAS devices by eliminating a malicious server behind the assault. They swiftly responded to the discovery of weak password attacks, blocking numerous compromised network IPs and locating the source C&C server within 7 and 48 hours, respectively. Brute force attacks involve hackers trying various combinations to crack encryption keys or login credentials. To mitigate such risks, QNAP advises users to disable the "admin" account, use strong passwords, keep firmware and apps updated, employ the QuFirewall application, and utilize myQNAPcloud Link's relay service with non-default ports. Protecting internet-facing NAS devices is crucial, and constant network security vigilance is essential, as highlighted by Stanley Huang, Manager of QNAP's Product Security Incident Response Team.

Source: Cyber Security News

Tags: #Cybersecurity #QNAP #Bruteforce #Vulnerability #InfoSec

phranck, to random German
@phranck@chaos.social avatar

Hat hier jemand Erfahrung mit Datenrettungs-/Datenwiederherstellungsdiensten von #QNAP NAS Systemen? Gibt es Empfehlungen aus eigener Erfahrung?

Bitte boosten. Danke.
:BoostOK:

hannsr, to homelab German
@hannsr@metalhead.club avatar

Hallo fediverse,
Ich will/muss ein paar meiner Systeme loswerden und bevor ich direkt zu eBay gehe frag ich Mal hier.
U.a. ein kompletter 4U Ryzen 9 3900x Server, Intel x299 HEDT Board inkl. CPU, ds620 slim, ts-253Be.

Mehr Details gibt's gerne bei Interesse.

tempelorg, to random
@tempelorg@iosdev.space avatar

Well, isn't that just great. Want to leave for vacation today and then I see that my #QNAP NAS (TS-453BT3) has just died, and I cannot access the files I need from it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines