sentinelvdx
Very Senior Member
QNAP Security Advisory | Bulletin ID: QSA-21-15
Taipei, Taiwan, April 29, 2021 - QNAP® had published security enhancement against security vulnerabilities that could affect specific versions of QNAP products. Please use the following information and solutions to correct the security issues and vulnerabilities.
AgeLocker Ransomware
Release date: April 29, 2021Security ID: QSA-21-15
Severity rating: High
CVE identifier: N/A
Affected products: All QNAP NAS
Summary
The QNAP security team has detected suspicious ransomware in the wild known as AgeLocker, which has the potential to affect QNAP NAS devices.Recommendation
To secure your device, we strongly recommend regularly updating QTS or QuTS hero and all installed applications to their latest versions to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.To further secure your device, do not expose your NAS to the internet. If you must connect your NAS to the internet, we highly recommend using a trusted VPN or a myQNAPcloud link.
Updating QTS or QuTS hero
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
QTS or QuTS hero downloads and installs the latest available update.
Updating All Installed Applications
- Log on to QTS or QuTS hero as administrator.
- Go to App Center.
- Select My Apps.
- Beside Install Updates, click All.
A confirmation message appears. - Click OK.
QTS or QuTS hero updates all your installed applications to their latest versions.
Revision History: V1.0 (April 29, 2021) - Published
If you have any questions regarding this issue, please contact us at https://www.qnap.com/go/support-ticket/.