Search/western digital
Vendor

western digital

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ibi
Connections
22 relationships
Nobody was checking the drives that encrypt your laptop
Nobody was checking the drives that encrypt your laptop A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came from Samsung, Western Digital, Micron, Kioxia, and others, a mix of new stock and secondhand units pulled from laptops. The team treated each one as a black box and sent it only the commands the Opal2 documentation defines. Several drives failed on basic points. What the drives got wrong Two Lenovo OEM drives encrypt every sector with the same tweak value. AES-XTS relies on that value to make identical data look different depending on where it sits on the disk. With one value across the whole drive, identical content written to two locations produces identical ciphertext. A pattern in your files survives into the encrypted data. The same two drives ship a random number generator that returns a predictable counting sequence on every call. A SanDisk SATA drive leans toward one byte value, 0x8B. The drive emits it roughly double the expected frequency. Opal2 requires every drive to expose this generator and leaves its quality unspecified. The tweak flaw exposes residual pattern information about data a key change was meant to erase, and the researchers rate real exploitation as very limited. The weak generator matters for software that pulls keys from it, and the team searched for a product that does and came up empty. The encryption key itself lives on the drive and stays there. The reset tokens have their own problem. Every Opal2 drive carries a PSID, a code printed on the label that wipes the drive back to factory state. One batch of SanDisk drives generated those codes in sequence, sharing a prefix and a suffix. Recovering one drive’s PSID hands you its neighbors’ by counting up. Six other drives accept any garbage appended to a valid PSID and treat it as correct. Vendors buy hardware encryption, and no one checks it Companies deploy Opal2 drives to satisfy a data-at-rest requirement. A purchasing officer sees “hardware encryption” on a spec sheet and marks the box. The gap between that label and the chip’s behavior went years unmeasured by any independent party. This is the first cross-vendor security comparison of Opal2 drives. The last major public work on self-encrypting SSDs landed in 2019. The Samsung generator bias sat undetected across a drive that researchers had already reverse-engineered. The method that surfaced all of it: buy used SSDs and run a script. The marketing muddies things further. The team began with more than fifty drives and set aside a dozen that support only Pyrite2, a related standard that checks a password and leaves the data in plaintext. Vendors sell those drives with hardware encryption in the copy. The disclosure went nowhere Brož and his team reported every security issue to the affected vendors. Micron shipped a firmware fix for a sector-size bug on its Crucial T500. Every other report came back as already known and unpatched, out of support, or met with silence. Several vendors answer broken encryption firmware by marking the feature dead and pointing customers to software encryption. Firmware updates stay hard to get. Many require a vendor’s Windows-only tool or a bootable image. The Linux Vendor Firmware Service covers a slice of OEM drives, and the rest depend on whichever support site still exists. What got fixed The project shipped code. Opal2 support landed in cryptsetup. Single-user mode is staged for a coming release, along with the Linux kernel changes it needs. The team released the Opal Test Suite so anyone can point the same checks at their own drives. Three of the tested drives turned out unusable for real disk encryption. Single-user mode, the feature that keeps a drive administrator from unlocking a user’s data, tells a similar story. Twenty-four drives advertise it. Fourteen support it well enough to use. Cryptsetup now checks a drive’s single-user-mode firmware before trusting it and drops to a safer configuration when the check fails. The practical guidance runs opposite to the original sales pitch. Layer software encryption over the drive’s own, and let the hardware serve as a second wall. A drive that claims to encrypt your data deserves the same scrutiny as any other security control. The tools to apply that scrutiny are open source now, and the first pass through them found broken firmware in production on machines storing real data. Download: The ultimate guide to network operations management
helpnetsecurity.comJul 21, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
Week in review: Many Cisco ASA firewalls still unsecure, hackers claim Red Hat’s GitLab breach
Week in review: Many Cisco ASA firewalls still unsecure, hackers claim Red Hat’s GitLab breach Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Keeping the internet afloat: How to protect the global cable network The resilience of the world’s submarine cable network is under new pressure from geopolitical tensions, supply chain risks, and slow repair processes. A new report from the Center for Cybersecurity Policy and Law outlines how governments and industry can work together to strengthen this critical infrastructure. Cyber risk quantification helps CISOs secure executive support In this Help Net Security interview, Vivien Bilquez, Global Head of Cyber Resilience at Zurich Resilience Solutions, discusses how organizations are rethinking cyber resilience. He talks about the priorities CISOs should focus on and the risks that are often overlooked. Bilquez also explains how to align cybersecurity efforts with business goals to gain executive support. The hidden risks inside open-source code Open-source software is everywhere. It runs the browsers we use, the apps we rely on, and the infrastructure that keeps businesses connected. For many security leaders, it is simply part of the environment, not something they think about every day. That is where trouble can start. A2AS framework targets prompt injection and agentic AI security risks AI systems are now deeply embedded in business operations, and this introduces new security risks that traditional controls are not built to handle. The newly released A2AS framework is designed to protect AI agents at runtime and prevent real-world incidents like fraud, data theft, and malware spread. Building a mature automotive cybersecurity program beyond checklists In this Help Net Security interview, Robert Sullivan, CIO & CISO at Agero, shares his perspective on automotive cybersecurity. He discusses strategies for developing mature security programs, meeting regulatory requirements, and addressing supply chain risks. Sullivan also looks ahead to how AI and other emerging technologies will shape the future of cybersecurity. Akira ransomware: From SonicWall VPN login to encryption in under four hours Four hours or less: that’s how long it takes for Akira affiliates to break into organizations and deploy the ransomware on their systems, Arctic Wolf researchers have warned. Western Digital My Cloud NAS devices vulnerable to unauthenticated RCE (CVE-2025-30247) Western Digital has fixed a critical remote code execution vulnerability (CVE-2025-30247) in the firmware powering its My Cloud network-attached storage (NAS) devices, and has urged users to upgrade as soon as possible. CISA says it will fill the gap as federal funding for MS-ISAC dries up The cooperative agreement between the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the not-for-profit Center for Internet Security is ending today, the agency has announced on Monday, and CISA will take it upon itself to offer support to US state, local, tribal, and territorial (SLTT) governments by way of grants, tools, and cybersecurity expertise. Hackers love LOTL, this approach shuts them down Every time cyber defenders and companies discover new ways to block intrusions, attackers change their tactics and find a way around the defenses. LOTL is part of a broader approach of hiding malicious activity within normal operations. Unfortunately, what’s normal for one system or user is not normal for another, so static rules and one-size-fits-all policies are not the solution for this problem. Too many Cisco ASA firewalls still unsecure despite zero-day attack alerts Despite Cisco and various cybersecurity agencies warning about attackers actively exploting zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) for months, there are still around 48,000 vulnerable appliances out there. Google Drive for desktop will spot, stop and remedy ransomware damage Google has rolled out AI-powered ransomware detection and file restoration features in Drive for desktop, Google’s official file syncing and access app for Windows and macOS. North Korea’s IT workers are targeting firms beyond tech, crypto, and the U.S. North Korea’s clandestine IT Worker (ITW) program, which is long known for targeting U.S. technology firms and crypto firms, has broadened its scope to attempt to infiltrate a variety of industries worldwide, including finance, healthcare, public administration, and professional services. Oracle customers targeted with emails claiming E-Business Suite breach, data theft Unknown attackers claiming affiliation with the Cl0p extortion gang are hitting business and IT executives at various companies with emails claiming that they have exfiltrated sensitive data from the firms’ Oracle E-Business Suite (EBS). Hackers claim to have plundered Red Hat’s GitLab repos The Crimson Collective, an emerging extortion / hacker group, has made a bombshell claim on their Telegram channel: they have gained access to Red Hat’s GitLab and have exfiltrated data from over 28,000 internal repositories connected to the company’s consulting business. How attackers poison AI tools and defenses Cyberattackers are using generative AI to draft polished spam, create malicious code and write persuasive phishing lures. They are also learning how to turn AI systems themselves into points of compromise. GPT needs to be rewired for security LLMs and agentic systems already shine at everyday productivity, including transcribing and summarizing meetings, extracting action items, prioritizing critical emails, and even planning travel. But in the SOC (where mistakes have real cost), today’s models stumble on work that demands high precision and consistent execution across massive, real-time data streams. Until we close this reliability gap at scale, LLMs alone won’t automate the majority of SOC tasks. 4 ways to use time to level up your security monitoring SIEMs excel at correlating events and firing alerts, but their ingest pipelines can get overwhelmed when scaled. And because most SIEMs rely on general-purpose log storage platforms, even with lower-cost archive tiers, long-term retention at full fidelity remains expensive, forcing teams to choose between visibility and budget. Firezone: Open-source platform to securely manage remote access Firezone is an open-source platform that helps organizations of any size manage secure remote access. Unlike most VPNs, it uses a least-privileged model, giving users only the access they need. Your budget Android phone might be spying on you Researchers have found that many low-cost Android devices come with pre-installed apps that have high-level access to the system. Unlike apps from the Google Play Store, many of these are not subject to thorough checks and can serve as vectors for malware or privacy-invasive features. Biometric spoofing isn’t as complex as it sounds Biometric technologies were originally designed to improve security and streamline authentication, but they’re often misused in ways most people don’t notice. Like any system, biometrics has weaknesses that attackers can exploit. The energy sector is ground zero for global cyber activity A new study from the Karlsruhe Institute of Technology shows how geopolitical tensions shape cyberattacks on power grids, fuel systems, and other critical infrastructure. Chekov: Open-source static code analysis tool Checkov is an open-source tool designed to help teams secure their cloud infrastructure and code. At its core, it’s a static code analysis tool for infrastructure as code (IaC), but it also goes a step further by providing software composition analysis (SCA) for container images and open source packages. Apple strengthens storage flexibility with new disk image formats Apple’s release of macOS 26 Tahoe introduced a new disk image format and updated an older one, both of which are drawing attention from system testers and forensic examiners. When loading a model means loading an attacker You probably think twice before downloading a random app or opening an unfamiliar email attachment. But how often do you stop to consider what happens when your team downloads and loads a machine learning model? The CISO’s guide to stronger board communication In this Help Net Security video, Alisdair Faulkner, CEO of Darwinium, explores how the role of the CISO has changed over the past decade. Faulkner shares insights on how CISOs can communicate with the board, overcome common pitfalls such as overly technical language, and position cybersecurity as a business enabler rather than a cost center. How to stop a single vendor breach from taking down your business In this Help Net Security video, William Dixon, Senior Executive at Intel 471, examines the future of third-party cyber risk and why it is a growing concern for organizations worldwide. As businesses become more interconnected, the digital ecosystem offers transformative opportunities while also introducing new vulnerabilities. Top 10 fastest growing ICT jobs AI is reshaping the workforce in ways that security leaders cannot ignore. The AI Workforce Consortium’s new report, ICT in Motion: The Next Wave of AI Integration, provides a look at how AI is changing job roles and skills across G7 economies. The findings point to risks and opportunities in building teams that can handle the security, ethics, and governance challenges of AI adoption. Cybersecurity leaders underreport cyber incidents to executives Cyberattacks are becoming more frequent and severe, with 71% of surveyed security leaders saying attacks have grown more common in the past year and 61% reporting greater impact when incidents occur, according to a new report from VikingCloud. Ransomware remains the leading cause of costly cyber claims Cyber threats are shifting in 2025, and while large companies are still targets, attackers are turning their attention to smaller and mid-sized firms. According to Allianz’s Cyber Security Resilience 2025 report, hardened defenses at major corporates have pushed criminals to go after easier prey. The data shows ransomware was involved in 88% of breaches at small and medium firms compared to 39% at larger enterprises. Underwriting is shifting to AI-driven, real-time decisions by 2030 Underwriting is undergoing a major transformation as financial institutions push for faster decisions, better fraud detection, and greater personalization, according to a new global Experian report. By 2030, credit decisions are expected to become embedded in everyday transactions, with artificial intelligence and automation taking on a bigger role. Biotech platforms keep missing the mark on security fundamentals A new security posture report on the biotech sector shows how quickly attackers could reach sensitive health data with only basic reconnaissance. Researchers needed less than two hours per company to uncover exposed genomic records, unprotected APIs, and misconfigured systems, according to Sekurno. ProSpy and ToSpy: New spyware families impersonating secure messaging apps ESET researchers have found two Android spyware campaigns aimed at people looking for secure messaging apps such as Signal and ToTok. The attackers spread the spyware through fake websites and social engineering. OpenSSL 3.6.0: New features, crypto support The OpenSSL Project has announced the release of OpenSSL 3.6.0, a feature update that brings significant functionality improvements, standards compliance, and a few key deprecations that developers and security teams will need to keep in mind. AI hype hits a wall when the data doesn’t deliver Companies are pouring money into AI for IT operations, but most projects are still far from maturity. A global survey of 1,200 business leaders, IT leaders, and technical specialists found that while spending and confidence are rising, only 12% of AI initiatives have been fully deployed. Passkeys rise, but scams still hit hard in 2025 Americans are dealing with a growing wave of digital scams, and many are losing money in the process. According to the fourth annual Consumer Cyber Readiness Report, nearly half of U.S. adults have been targeted by cyberattacks or scams, and one in ten lost money as a result. Protegrity Developer Edition: Free containerized Python package to secure AI pipelines Protegrity Developer Edition enables developers, data scientists, ML engineers, and security teams an easy way to add data protection into GenAI and unstructured data workflows, without the need for enterprise setup. Billed as the first enterprise-grade, governance-focused Python package, it is built to help teams create secure, well-governed data pipelines and AI workflows from the ground up. Webinar: The BAS Summit 2025: Redefining Attack Simulation through AI Join Picus Security, SANS, Hacker Valley, and leading CISOs at The BAS Summit 2025 to learn how AI is redefining Breach and Attack Simulation (BAS) and why it’s becoming the new benchmark for cyber resilience. Cybersecurity jobs available right now: September 30, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: October 3, 2025 Here’s a look at the most interesting products from the past week, featuring releases from Acronis, Legit Security, NowSecure, Siemens, and Telus.
helpnetsecurity.comOct 5, 2025extracted
Critical WD My Cloud bug allows remote command injection
Western Digital has released firmware updates for multiple My Cloud NAS models to patch a critical-severity vulnerability that could be exploited remotely to execute arbitrary system commands. Tracked as CVE-2025-30247, the flaw is an OS command injection in the user interface of My Cloud and can be leveraged through specially crafted HTTP POST requests sent to vulnerable endpoints. The vulnerability was reported to Western Digital by a security researcher using the alias “w1th0ut.” The storage device maker released firmware version 5.31.108 to address the issue that impacts all previous versions for the following models: My Cloud PR2100 My Cloud PR4100 My Cloud EX4100 My Cloud EX2 Ultra My Cloud Mirror Gen 2 My Cloud DL2100 My Cloud EX2100 My Cloud DL4100 My Cloud WDBCTLxxxxxx-10 It is worth noting that two of the devices, My Cloud DL4100 and My Cloud DL2100, have reached end of support (EoS) and updates may not be available, as the security advisory from the company does not provide mitigation action for EoS products. My Cloud is Western Digital’s network-attached storage (NAS) are typically used by small businesses, home offices, and individuals that want to store data on a personal cloud and access it from any device. While not intended for use in critical or enterprise environments, they are popular among the general consumer audience for providing easy remote access to files via mobile apps or browsers, media streaming, and automated backups. Exploitation of CVE-2025-30247 to run shell commands could result in unauthorized file access, modification, deletion, user enumeration, configuration changes, or even binary execution. In the past, hackers have exploited similar flaws on NAS devices to harvest sensitive data, built botnets, use them as proxies, or deploy ransomware and then extort users. My Cloud users should prioritize patching to 5.31.108 as soon as possible. If immediate action cannot be taken, users are recommended to take the device offline until they can apply the update. Even if offline, My Cloud devices can still work as local storage centers in LAN mode, though files stored on Western Digital’s cloud service will not be available. Users who have enabled automatic updates on their device settings should have received the update since September 23, 2025. Checking to ensure you’re running the latest version is recommended. Manual updates are possible (instructions here) by sourcing the correct firmware image for your device model from here and then navigating to Settings > Firmware Update > Update From File > select the downloaded BIN file. A reboot of the device will be required for the update to take effect, and the device must remain plugged in throughout the process to prevent data corruption. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 30, 2025extracted
Western Digital My Cloud NAS devices vulnerable to unauthenticated RCE (CVE-2025-30247)
Western Digital My Cloud NAS devices vulnerable to unauthenticated RCE (CVE-2025-30247) Western Digital has fixed a critical remote code execution vulnerability (CVE-2025-30247) in the firmware powering its My Cloud network-attached storage (NAS) devices, and has urged users to upgrade as soon as possible. About CVE-2025-30247 Western Digital’s My Cloud devices are designed for home and small business users, to store documents and other content and access it via mobile apps or web browser. In small office settings, it’s also often used as a server for backups and a centralized place for project files. CVE-2025-30247 is an OS command injection vulnerability in the firmware’s user interface, and allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST request. The vulnerability’s CVSS string indicates that no prior authentication or user interaction is required for exploitation. A successful attack may result in full system compromise and the attackers having access to all the data stored on it and the ability to encrypt it, delete it, or modify it. A compromised device could also provide a foothold for attackers who want to compromise other systems in the same network. Update your firmware CVE-2025-30247 affects My Cloud firmware prior to v5.31.108, which was released on September 23, for the following supported devices: My Cloud PR2100, My Cloud PR4100, My Cloud EX2 Ultra, My Cloud EX4100, My Cloud Mirror Gen 2, My Cloud EX2100, My Cloud DL2100, My Cloud DL4100, My Cloud WDBCTLxxxxxx-10, and My Cloud. The vulnerability has been privately reported by a researcher, and there’s no mention of it being exploited in the wild. “To take advantage of the latest security fixes, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification,” the company advised. Devices with the automatic firware update option switched on have already been upgraded if they aren’t disconnected or powered off. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comSep 30, 2025extracted