Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Unpatched Vulnerability Leads to Remote Factory Resets in Western Digital My Book NAS Devices

Unpatched Vulnerability Leads to Remote Factory Resets in Western Digital My Book NAS Devices

Imagine going to log into one of your devices only to find that it has been completely wiped of any files located on it. Furthermore, imagine trying to log into your online account to manage the settings of said device, only to find that the password you know is correct is being identified as incorrect. This is the experience that many users of Western Digital’s My Book NAS device are currently going through, and it’s suspected that it is all because of an unpatched vulnerability.

The device in question, the Western Digital My Book, is a network-attached storage device that gives users the ability to remotely access files and manage devices. This is notable, as they can do so even if the NAS device is secured with a firewall or router. Bleeping Computer reports that some users are unable to log into their NAS devices, the reason being an “Invalid Password.” Since the devices appeared to be factory reset, some users tried the default login credentials but had no luck accessing their devices or recovering their files.

After some investigation, users discovered that the devices received a remote command to perform factory resets. Bleeping Computer reports that this attack is an odd one in terms of remote command attacks, mostly because the device in question is secured behind a firewall and communicates exclusively through the My Book Live cloud servers to issue remote access. Therefore, it makes sense for some users to assume that Western Digital’s servers were hacked, although they do mention that it is strange that the attack deleted files rather than issuing ransoms, such as with other threats like ransomware which are designed to steal data or encrypt files.

Although Western Digital is investigating the attack, Bleeping Computer does detail a statement issued by the company, stating the following:

  • “If you own a WD My Book Live NAS device, Western Digital strongly recommends that you disconnect the device from the Internet. ‘At this time, we recommend you disconnect your My Book Live and My Book Live Duo from the Internet to protect your data on the device,’ Western Digital said in an advisory.”

These WD My Book Live devices have not received updates since 2015, so it’s unsurprising that a vulnerability surfaced. Still, this situation should be a reminder that it is beneficial to consider upgrading from unsupported devices to those that are actively receiving patches and security updates. That said, failing to administer patches and security updates as they are released is just as bad as using unsupported devices, so the responsibility falls on your shoulders to make sure that you are using technology that isn’t putting your organization at risk.

Need a Hand with Upgrading?

Total Tech Care can help your organization take care of any updates to its technology infrastructure. Especially in today’s age of massive security breaches and considerable cyberthreats, it has never been more important to make sure that your network is protected in every conceivable way. To learn more about what we can do for your business, reach out to us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 23 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Network Security Google Business Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices IT Services Hardware Android VoIP Disaster Recovery communications Smartphones Communication Business Continuity IT Support Miscellaneous Smartphone Mobile Device Browser Small Business Network Collaboration Productivity Quick Tips Cybersecurity Business Management Users Managed IT Services Upgrade Phishing Windows Data Backup Outsourced IT Ransomware Windows 10 Server Save Money Data Recovery Cloud Computing Office Passwords Windows 10 Chrome Social Media Virtualization Tech Term Gadgets Saving Money Holiday Automation Microsoft Office Managed Service Managed IT Services Artificial Intelligence Operating System Facebook Cybercrime Computers Wi-Fi Networking IT Support Hacking Health Internet of Things BYOD Mobile Device Management Office 365 Remote Telephone Systems Managed Service Provider Information Technology Covid-19 Information Spam Alert Social Engineering Mobility Employer-Employee Relationship Recovery Router BDR Bandwidth Password Data Breach Money App History Big Data Encryption Applications Human Resources Mobile Computing Law Enforcement Application Remote Monitoring Apps Office Tips Training Blockchain VPN Paperless Office How To Government Remote Computing Private Cloud Data Storage Mobile Office Patch Management Managed IT Bring Your Own Device Data Management Work/Life Balance Servers Wireless Data Security Gmail Google Drive Settings Flexibility Marketing WiFi Two-factor Authentication Avoiding Downtime IT solutions Infrastructure Entertainment Website Voice over Internet Protocol Mouse Budget HaaS Vulnerability Windows 7 Word Data Protection Cleaning Risk Management Vendor Management Hacker End of Support The Internet of Things Lithium-ion battery Education Physical Security Safety Vendor Managed Services Sports HIPAA Telephone System Staff Redundancy Software as a Service Display Firewall Keyboard Machine Learning Connectivity Remote Work Virtual Reality Employee/Employer Relationship Apple RMM Social USB Conferencing User Error Save Time Meetings Scam IT Management Cryptocurrency Retail Humor Hard Drives Instant Messaging Robot Computing Infrastructure Excel Botnet IT Plan Procurement Going Green Net Neutrality Workplace Strategy Biometrics Comparison Virtual Desktop Unsupported Software CES Help Desk Battery Printing Charger Shadow IT DDoS Business Technology Legal Content Management SharePoint Access Control Compliance Computer Care Managed Services Provider Internet Exlporer OneNote Virtual Assistant Current Events Virus Database Telephony Authentication Customer Service PDF Samsung Remote Workers Environment Unified Threat Management Computer Accessories Fax Server Value Processor Proactive IT Update Best Practice Spam Blocking Electronic Medical Records Hard Drive YouTube SaaS Black Market Google Docs Printer Hiring/Firing Identity Theft Bluetooth Network Congestion Computing eWaste Document Management Solid State Drive Wireless Technology Augmented Reality How to Downtime Fraud Business Intelligence IT Consultant Remote Worker Data storage Digital Signage Worker Wearable Technology Automobile Audit Procedure Public Computer Recycling Saving Time Regulations Wiring dark theme Practices Shopping Monitor Transportation Google Search AI Rootkit Amazon Web Services IT Infrastructure Running Cable Computer Fan Cache Safe Mode FinTech Criminal Memory Bing Streaming Media GDPR Workers Hosted Computing Consultant Social Network Reputation Benefits Online Shopping Analytics Investment Tech Support Content FENG Wireless Internet File Sharing Employees Techology IBM Employee/Employer Relationships Laptop ISP Flash Camera Windows 365 Inventory Best Available Customers Smart Technology Specifications WIndows 7 Video Conferencing Evernote ROI Science Audiobook Wire Software Tips Sales Supercomputer Bitcoin Touchpad Travel Shortcuts Cryptomining Sync Printers Point of Sale Emails Personal Millennials Supply Chain Management Customer Relationship Management Advertising Wireless Charging Distributed Denial of Service Politics Smart Office Monitoring Batteries Analyitcs Notifications Virtual Private Network Windows 8.1 Netflix Digitize Programming Two Factor Authentication Workforce User Cables PowerPoint Windows Server 2008 R2 Windows Media Player Root Cause Analysis HBO Customer relationships Knowledge Music Manufacturing Skype Project Management Email Best Practices Antivirus Nanotechnology IT Assessment Relocation Telecommuting Managing Stress Cortana Windows 8 Data loss Outlook Computer Tips IT service Video Games Leadership Digital Signature Managed IT Service Troubleshooting Security Cameras Cameras Biometric Security Start Menu Warranty Virtual CIO Worker Commute OneDrive Peripheral Loyalty Google Apps Tablet Experience Screen Mirroring HVAC Frequently Asked Questions Digital Security Cameras Domains Scalability Analysis Using Data Books 5G Mobile Administrator Business Owner Windows 10s Devices Copiers Quick Tip Maintenance NarrowBand IaaS Cast Enterprise Content Management Tip of the week MSP Ergonomics Search webinar Accountants Bloatware Emergency Smartwatch Printer Server OLED Professional Services Microchip Public Cloud Thought Leadership Development iPhone Employer Employee Relationship Credit Cards PCI DSS Assessment Password Manager Virtual Machine Tablets Password Management Windows Server 2008 2FA Fiber Optics Entrepreneur Multi-Factor Security Employee Cabling Tools Search Engine Twitter Messaging Files NIST Policy Shortcut Television Business Mangement Hypervisor Chromecast Dark mode Smart Tech Trend Micro Cost Management Trending Social Networking Colocation Amazon Default App Uninterrupted Power Supply Addiction SMS

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code