QNAP NAS devices still facing huge number of online attacks

Passwords
(Image credit: Shutterstock)

Several users are reporting that their QNAP Network-Attached Storage (NAS) devices are being subject to brute-force attacks.

Devices from Taiwanese storage manufacturer QNAP have been at the receiving end of various cyber attack campaigns lately.

QNAP has been very active in patching vulnerabilities in their devices. Late last year it fixed a cross-site scripting vulnerability, and issued patches to neutralize malware that used the QNAP device to mine cryptocurrency, earlier this year.  

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

“Recently QNAP has received multiple user reports of hackers attempting to log in to QNAP devices using brute-force attacks – where hackers would try every possible password combination of a QNAP device user account,” warns the company.

Brute force attacks

While the earlier attacks exploit software vulnerabilities on devices that haven’t been patched, the ongoing campaign exploits human behaviour. 

The attackers use simple tools to brute-force their way into the device by trying to log in using a list of common passwords or a list of previously compromised credentials.

“If a simple, weak, or predictable password is used (such as "password" or "12345") hackers can easily gain access to the device, breaching security, privacy, and confidentiality,” says QNAP, urging users to set strong passwords.

QNAP further suggests users to implement password rotation policies, and even disable the default admin account. Also, since the attack is only possible on Internet-facing NAS devices, QNAP suggests users don’t expose their devices on public networks.   

Via: BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Huge cyber attack under way - 2.8 million IPs being used to target VPN devices
Digital image of a lock.
QNAP says it has fixed several major vulnerabilities in NAS backup, recovery app
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
IoT’s botnet problem is up 500% – three things admins must do now
China
Chinese hackers develop effective new hacking technique to go after business networks
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand