Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Has Bitcoin Hit Bottom Yet? Here’s What On-Chain Data Says bitcoin news
  • CA GameFi, Subsidiary of CyberAgent, Announces “ProjectTB” That Delivers “Just Enjoy and Earn” to Players Around the World – Press release Bitcoin News bitcoin news
  • Crypto Investors Dump Small Caps For Blue Chips Like Bitcoin bitcoin news
  • Ripple (XRP) Plunges To $0.43 With Bears In Full Swing bitcoin news
  • Stablecoin Implosion — LUNA and UST Lose Significant Value, Downturn Ripples Across the Crypto Economy – Bitcoin News bitcoin news
  • Facebook Owner Meta Files Trademark Applications for ‘Meta Pay’ Covering Crypto Services – Featured Bitcoin News bitcoin news
  • Elon Musk Discusses Crypto Investing, Dogecoin Support, ‘Unresolved’ Twitter Issues, and Near-Term Recession – Featured Bitcoin News bitcoin news
  • Hyperdex Launches Mainnet to Introduce Advanced Trading Features For DeFi Users bitcoin news

Critical PHP Vulnerability Exposes QNAP NAS Devices to Remote Attacks

Posted on June 23, 2022 By root


QNAP NAS PHP Vulnerability

QNAP, Taiwanese maker of network-attached storage (NAS) devices, on Wednesday said it’s in the process of fixing a critical three-year-old PHP vulnerability that could be abused to achieve remote code execution.

“A vulnerability has been reported to affect PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24, and 7.3.x below 7.3.11 with improper nginx config,” the hardware vendor said in an advisory. “If exploited, the vulnerability allows attackers to gain remote code execution.”

CyberSecurity

The vulnerability, tracked as CVE-2019-11043, is rated 9.8 out of 10 for severity on the CVSS vulnerability scoring system. That said, it’s required that Nginx and php-fpm are running in appliances using the following QNAP operating system versions –

  • QTS 5.0.x and later
  • QTS 4.5.x and later
  • QuTS hero h5.0.x and later
  • QuTS hero h4.5.x and later
  • QuTScloud c5.0.x and later

“As QTS, QuTS hero or QuTScloud does not have nginx installed by default, QNAP NAS are not affected by this vulnerability in the default state,” the company said, adding it had already mitigated the issue in OS versions QTS 5.0.1.2034 build 20220515 and QuTS hero h5.0.0.2069 build 20220614.

The alert comes a week after QNAP revealed that it’s “thoroughly investigating” yet another wave of DeadBolt ransomware attacks targeting QNAP NAS devices running outdated versions of QTS 4.x.

CyberSecurity

Besides urging customers to upgrade to the newest version of QTS or QuTS hero operating systems, it’s also recommending that the devices are not exposed to the internet.

Additionally, QNAP has advised customers who cannot locate the ransom note after upgrading the firmware to enter the received DeadBolt decryption key to reach out to QNAP Support for assistance.

“If your NAS has already been compromised, take the screenshot of the ransom note to keep the bitcoin address, then upgrade to the latest firmware version and the built-in Malware Remover application will automatically quarantine the ransom note which hijacks the login page,” it said.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Cardano Vasil Hard Fork Postponed to Allow for More Testing – Blockchain Bitcoin News
Next Post: Alameda Ventures Bails Out Voyager With $200M & 15K BTC

Related Posts

  • Another Set of Joker Trojan-Laced Android Apps Resurfaces on Google Play Store cyber security news
  • Researchers Demonstrate Ransomware for IoT Devices That Targets IT and OT Networks cyber security news
  • Google Blocks Dozens of Malicious Domains Operated by Hack-for-Hire Groups cyber security news
  • Hackers Using PrivateLoader PPI Service to Distribute New NetDooka Malware cyber security news
  • Google Researchers Detail 5-Year-Old Apple Safari Vulnerability Exploited in the Wild cyber security news
  • OpenSSH to Release Security Patch for Remote Memory Corruption Vulnerability cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Critical Flaw in Cisco Secure Email and Web Manager Lets Attackers Bypass Authentication cyber security news
  • Meme Token King Dogecoin Lost 91% in Value Since Last Year’s High, DOGE Mining Revenue Plummets – Market Updates Bitcoin News bitcoin news
  • Eurovision Winners’ NFT Auction Raises $900K for Charity – Metaverse Bitcoin News bitcoin news
  • Just Above $1 Trillion — Crypto Economy’s Value Slips Lower Than the Lows Recorded Last July – Markets and Prices Bitcoin News bitcoin news
  • Terra Whistleblower Publishes Alleged Chat Log Between Do Kwon and Network Validators – Bitcoin News bitcoin news
  • Has Bitcoin Hit Bottom Yet? Here’s What On-Chain Data Says bitcoin news
  • As LUNA’s Price Drops Over 33% in 24 Hours, Stablecoin UST Slips Below $1 Parity to $0.93 – Bitcoin News bitcoin news
  • 105 Countries Are Exploring Central Bank Digital Currencies, CBDC Tracker Shows – Regulation Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme