Synology hurries out patches for zero-days exploited at Pwn2Own

by aborsyon 10/25/25, 10:29 AMwith 2 comments
by aborsyon 10/25/25, 10:29 AM

Security researchers exploited multiple Synology and QNAP devices (NAS, IP cameras, even routers), gaining root access.

In one case, QNAP still had a hard coded password, after all security incidents in previous years. One of the bugs was known to synology and had not been patched.

by CommanderDataon 10/25/25, 12:08 PM

Ah Synology's DSM, packaged with things that are outdated or EOL. Docker being one of them, EOL by about a year.