QNAP Newsroom

Keep up to date with the latest QNAP news, awards and connect with our team

QNAP, in Collaboration with Digital Ocean, Successfully Prevents NAS Weak Password Attacks to Ensure User Data Security

QNAP, in Collaboration with Digital Ocean, Successfully Prevents NAS Weak Password Attacks to Ensure User Data Security

Taipei, Taiwan, ngày 19 tháng Mười năm 2023 - QNAP® Systems, Inc. recently detected a significant wave of weak password attacks. These attacks targeted NAS devices exposed to the internet, conducting intensive weak password attacks. QNAP detected this activity at 6:42 PM on October 14, 2023. The QNAP Product Security Incident Response Team (QNAP PSIRT) swiftly took action by successfully blocking hundreds of zombie network IPs through QuFirewall within 7 hours, effectively protecting numerous internet-exposed QNAP NAS devices from further attack. Within 48 hours, they also successfully identified the source C&C (Command & Control) server and, in collaboration with the cloud service provider Digital Ocean, took measures to block this C&C server, preventing the situation from escalating further.

"Network security is of critical importance, requiring constant vigilance and 24/7 year-round management, detection, and response,” said Stanley Huang, the Manager of QNAP's Product Security Incident Response Team, continued, “This attack occurred over the weekend, and QNAP promptly identified it through cloud technology, quickly pinpointing the source of the attack and blocking it. This not only assisted QNAP NAS users in avoiding harm but also protected other storage users from being affected by this wave of attacks."

Recommendations for users to protect their NAS

QNAP strongly recommends that NAS users take immediate cybersecurity measures to mitigate the ever-present risks of security attacks.

  1. Disable the "admin" account. (Refer to the security manual, page 30)

  2. Set strong passwords for all user accounts and avoid using weak passwords. (Refer to the security manual, page 34)

  3. Update QNAP NAS firmware and apps to the latest versions. (Refer to the security manual, page 24)

  4. Install and enable the QuFirewall application. (Refer to the security manual, page 46)

  5. Utilize myQNAPcloud Link's relay service to prevent your NAS from being exposed to the internet. If there are bandwidth requirements or specific applications necessitating port forwarding, you should avoid using the default ports 8080 and 443. (Refer to the security manual, page 39)

Về QNAP

QNAP Systems, Inc. (Quality Network Appliance Provider) là tập đoàn công nghệ đến từ Đài Loan, dẫn đầu toàn cầu trong lĩnh vực giải pháp lưu trữ mạng (NAS), giám sát thông minh và hạ tầng mạng. QNAP luôn tiên phong đổi mới, mang đến các sản phẩm và dịch vụ giúp doanh nghiệp và cá nhân lưu trữ, bảo vệ, quản lý và khai thác dữ liệu an toàn, hiệu quả. Các thiết bị NAS của QNAP được đánh giá cao nhờ khả năng hỗ trợ ảo hóa, mở rộng mạng và quản lý đám mây, giúp người dùng tận dụng tối đa tài nguyên lưu trữ.

Media inquiries

marketing@qnap.com

Chọn thông số kỹ thuật

      Xem thêm Thu gọn

      Choose Your Country or Region

      open menu
      back to top