Article Details
Scrape Timestamp (UTC): 2024-08-21 18:23:02.597
Original Article Text
Click to Toggle View
QNAP adds NAS ransomware protection to latest QTS version. Taiwanese hardware vendor QNAP has added a Security Center with ransomware protection capabilities to the latest version of its QTS operating system for network-attached storage (NAS) devices. The new Security Center in QTS 5.2 monitors for suspicious file operations to detect and block ransomware threats. If any unusual activity is detected, customers can choose to have volumes automatically set to read-only mode to prevent files from being modified, create volume snapshots to restore the entire volume when needed, and pause volume snapshot scheduling to avoid crowding out the storage space with abnormal snapshot files. "This feature actively monitors file activities to preemptively protect data security," the company revealed in a press release on Tuesday. "Upon detecting suspicious file behavior, the system swiftly implements protective measures (such as backup or blocking) to mitigate risks and prevent data loss from ransomware threats, attacks, or human error." The latest QTS version also adds faster NAS startup and shutdown speeds (by up to 30%), support for TCG-Ruby self-encrypting drives (SED), as well as speedier backup and restoration of Windows systems, disks, folders, and files to their QNAP NAS via the NetBak PC Agent utility. NAS devices are often used for backing up and sharing sensitive files, which makes them valuable targets for attackers who frequently target them to steal or encrypt valuable documents or deploy information-stealing malware. In recent years, malicious actors have targeted QNAP devices in DeadBolt, Checkmate, and eCh0raix ransomware campaigns, abusing security vulnerabilities to encrypt data on Internet-exposed and vulnerable NAS devices. QNAP regularly warns customers about brute-force attacks against NAS devices exposed online, which frequently lead to ransomware attacks [1, 2, 3]. The NAS maker has also previously shared mitigation measures for customers with Internet-exposed devices, asking them to: QNAP customers should also use this step-by-step procedure to change the system port number, toggle off SSH and Telnet connections, enable IP and account access protection, and change default device passwords.
Daily Brief Summary
QNAP has introduced a Security Center with ransomware protection in the new QTS 5.2 operating system for NAS devices.
The Security Center actively monitors file operations to detect ransomware, allowing preemptive actions to secure data.
Enhanced features include setting volumes to read-only and creating snapshots for recovery during suspicious activity.
Additional updates in QTS 5.2 include faster NAS startup/shutdown, support for encrypted drives, and improved backup and restoration functions.
NAS devices are common targets for cyberattacks, including ransomware, due to their role in file storage and sharing.
Prior ransomware campaigns like DeadBolt, Checkmate, and eCh0raix have specifically targeted QNAP devices.
QNAP advises customers to take preventive measures against brute-force attacks and to secure Internet-exposed NAS devices by changing default settings and enabling security features.