Synology hurries out patches for zero-days exploited at Pwn2Own
ID: 9524157b-93c4-5d7f-8c51-e31731ebc10b
STIX ID: report--9524157b-93c4-5d7f-8c51-e31731ebc10b
Feed Name: Bleeping Computer
Threat Score
Synology patched two critical zero-click vulnerabilities (tracked as CVE-2024-10443 / RISK:STATION) in Synology Photos and BeePhotos for BeeStation after they were demonstrated at Pwn2Own Ireland 2024; the flaws enable remote root code execution on Internet-exposed NAS devices, affect many systems, and pose immediate risk of criminal abuse (e.g., ransomware), so Synology issued advisories and specific version upgrades to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
