[German]NAS manufacturer QNAP has issued a security warning for its QNAP products. There is a critical vulnerability CVE-2022-27596 in the QTS 5.0.1 and QuTS hero h5.0.1 software that allows malicious code injection into the firmware. The critical vulnerability has been assigned a CVSS v3 score of 9.8. Firmware updates are now available to close the vulnerability. An update should be installed immediately. Pver 29,000 devices are vulnearable.
Translate
Blogs
Links
Social networks
Awards
Sponsors
(Paypal-Donations)
[
Do we actually need Microsoft RDS licenses if we run an environment with Citrix Virtual App/Desktop? Citrix has discussed this in the article
A little note about security on Microsoft Teams. Two security researchers @adm1nkyj1 and @jinmo123 participated in pwn2own 2022 in Vancouver. There they tried to hack Microsoft Teams, but failed due to time allocation. Both discovered a bug that allowed an exploit. The deeplink handler for /l/task/:appId in Microsoft Teams can load an arbitrary url in Webview/iframe. Attackers can exploit this using Teams' RPC functionality to execute code outside the sandbox. The security researchers have shared the details in 

