Synology is a major vendor of network-attached storage (NAS) devices and the DiskStation Manager (DSM) software.
Synology is a major vendor of network-attached storage (NAS) devices and the DiskStation Manager (DSM) software. Its widespread deployment makes timely vulnerability disclosure and patching critical for cybersecurity risk management, and the company participates in security programs (e.g., Pwn2Own) to address flaws in its products.
A critical zero-day vulnerability in Synology's BeeStation OS allows remote code execution (RCE) on unpatched devices. The flaw, originating from a buffer overflow, has a CVSS score of 9.8, indicating severe risk.…
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
Synology has disclosed two critical vulnerabilities in its SSL VPN Client that could allow remote attackers to access sensitive files and intercept network traffic. These flaws affect users running outdated versions of…
A critical security vulnerability (CVE-2025-12686, CVSS 9.8) was discovered in Synology's BeeStation during Pwn2Own 2025 in Ireland. This vulnerability allows attackers to execute arbitrary code remotely due to a buffer…
Cyber threat actors are exploiting a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform, tracked as CVE-2025-12480. This vulnerability allows unauthorized administrative access and…
A sophisticated spyware named 'Landfall' targeted Samsung Galaxy phones for nearly a year, exploiting a zero-day vulnerability in Samsung's image-processing library. Discovered by Palo Alto Networks' Unit 42, the…
A sophisticated spyware named Landfall targeted Samsung Galaxy phones for nearly a year, exploiting a zero-day vulnerability in Samsung's image processing library. Discovered by Palo Alto Networks' Unit 42, the malware…
A security vulnerability (CVE-2025-64740) has been identified in the Zoom Workplace VDI Client for Windows, enabling attackers to escalate their privileges on affected systems. The flaw arises from improper verification…
Hackers have exploited a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform, allowing them to gain unauthorized administrative access and execute remote code. The…
Ivanti Endpoint Manager (EPM) has multiple high-severity vulnerabilities that allow attackers to write arbitrary files to disk, potentially leading to privilege escalation and malicious code execution. A security patch…