Skip to content
June 15, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • QNAP detects a large number of ransomware attacks
  • Cyber Security

QNAP detects a large number of ransomware attacks

Do Son January 10, 2022 2 minutes read
QNAP ransomware attacks
Add as a preferred
source on Google
QNAP, a maker of network-attached storage devices (NAS), has issued an alert saying the company has detected a large number of ransomware attacks. These cyberattacks are not currently blamed on specific or known hacker groups, and the attack methods are quite common, exploiting known vulnerabilities or brute force. According to QNAP, these attackers indiscriminately target any QNAP’s devices exposed on the public Internet. As a security suggestion, QNAP recommends users not expose the NAS to the public network.

“Your NAS is exposed to the Internet and at high risk if there shows ‘The System Administration service can be directly accessible from an external IP address via the following protocols: HTTP’ on the dashboard.”

QNAP is currently unable to confirm the source of the attack, but QNAP said that if the device is compromised, ransomware may be installed to encrypt all user data. The attack methods are divided into brute force attack and exploiting flaws, in which brute force attack is to use scripts and password dictionaries to continuously try to test the passwords used by users.

Attackers target the devices and try to launch an attack using a vulnerability that has already been disclosed. If the user does not update the firmware in time, it may be infected.
For this reason, QNAP recommends that users upgrade the device firmware immediately and disconnect the public network connection. In theory, just disconnecting the public network connection can successfully solve most of the attacks. Of course, the most important thing is to upgrade the system firmware in time.

If your NAS is exposed to the Internet, please follow the instructions below to ensure NAS security:

Step 1: Disable the Port Forwarding function of the router

Go to the management interface of your router, check the Virtual Server, NAT or Port Forwarding settings, and disable the port forwarding setting of NAS management service port (port 8080 and 433 by default).

Step 2: Disable the UPnP function of the QNAP NAS

Go to myQNAPcloud on the QTS menu, click the “Auto Router Configuration”, and unselect “Enable UPnP Port forwarding”.

 

  • Securely access your QNAP NAS via the Internet through myQNAPcloud Link:
    https://www.qnap.com/go/solution/myqnapcloud-link/
  • Learn more about NAS remote access and network security:
    https://www.qnap.com/go/solution/secure-remote-access/
Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. QNAP Counters Massive Weak Password Onslaught, Shields NAS Devices
  2. Andariel: North Korea’s Cyber Threat Actor Steals Data, Launches Ransomware Attacks
  3. “The Com” Phishing Attacks Escalate, Targeting Businesses with Fake Login Pages
  4. Senate Bill to Classify Ransomware Extortion as Terrorism
  5. Hackers changed and removed a lot of popular music videos on Youtube
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: QNAP ransomware attacks

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-9862CVSS 9.8
    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in...
  • CVE-2026-52704CVSS 10.0
    Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas...
  • CVE-2018-25436CVSS 9.8
    WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload...
  • CVE-2026-8935CVSS 9.8
    The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX...
  • CVE-2026-11526CVSS 9.8
    GD versions before 2.86 for Perl allow OS command injection and file...
  • CVE-2026-12183CVSS 9.8
    Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux...
  • CVE-2026-53609CVSS 9.1
    ApostropheCMS is an open-source Node.js content management system. In versions up to...
  • CVE-2026-53519CVSS 9.1
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
  • CVE-2026-41157CVSS 9.8
    A web page that contains unusual WebGPU content loaded into the GPU...
  • CVE-2026-46716CVSS 9.9
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.