QNAP NAS customers told to update now to protect against attack

QNAP TS-864eU-RP
(Image credit: Future)

QNAP customers are again being warned of DeadBolt ransomware attacks against NAS drives, which this time is affecting photo storage management tools.

This isn’t the first time that QNAP customers have had the security of their data threatened. Several attacks have been launched throughout 2022 focusing on varying zero-day vulnerabilities.

In a security notice on the QNAP website, customers are urged to “take immediate action”, with the company saying it “detected the security threat DEADBOLT leveraging exploitation of Photo Station vulnerability to encrypt QNAP NAS that are directly connected to the Internet.”

QNAP DeadBolt ransomware

Initially uncovered on September 3, 2022, “QNAP Product Security Incident Response Team (QNAP PSIRT) had made the assessment and released the patched Photo Station app for the current version within 12 hours.”

Bleeping Computer reports the following security updates that fix the vulnerability:

  • QTS 5.0.1: Photo Station 6.1.2 and later
  • QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later
  • QTS 4.3.6: Photo Station 5.7.18 and later
  • QTS 4.3.3: Photo Station 5.4.15 and later
  • QTS 4.2.6: Photo Station 5.2.14 and later

“We recommend using QuMagie to efficiently manage photo storage in your QNAP NAS”, QNAP added, noting that this is a “simple and powerful alternative to Photo Station.”

Along with keeping their NAS drives up-to-date, QNAP has also advised that its customers avoid directly connecting their devices to the Internet. By placing a drive behind a firewall - such as the company’s own myQNAPcloud Link feature or a VPN - users can reduce their chances of being subject to a ransomware attack. 

Other steps you can take if you are worried that your data may be affected is to take regular snapshots and backups, and to regularly change your password keeping in mind what makes a good password

Via Bleeping Computer

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Digital image of a lock.
QNAP says it has fixed several major vulnerabilities in NAS backup, recovery app
Ransomware
Synology patches critical vulnerabilities, urges users to update devices against zero-click attacks
Representational image of a hacker
TrueNAS device vulnerabilities exposed during hacking competition
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Ransomware
Ransomware defenses are being weakened by outdated backup technology, limited backup data encryption, and failed data backups
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection