4 ms·
Looks like Seagate NAS software, see https://www.reddit.com/r/computerviruses/comments/189e0j9/comment/kiaavc6/?utm_source=share&utm_medium=web2x&context=3 http
by silent_kyblik 3y ago
Looks like Seagate NAS software, see https://www.reddit.com/r/computerviruses/comments/189e0j9/comment/kiaavc6/?utm_source=share&utm_medium=web2x&context=3 https://www.reddit.com/r/computerviruses/comments/189e0j9/co...
- Demonsult 3y agoInteresting. I'm in the breach but never knowingly used that software, so it's likely buried under some other product or service.
- silent_kyblik 3y agoMe neither, all I had was Western Digital MyCloud NAS years ago, but nothing from Seagate
- great_psy 3y agoI also had a western digital nas that got bricked by a software update. And I am also on the nas.api list.
- upon_drumhead 3y agoI’m relatively certain I never used that software with the email that showed up on the breach warning :(
- toomuchtodo 3y ago> Edit: Fount it. It’s a Seagate NAS operating system. As in Network Attached Storage. NAS.api is their API. So I think someone(s) was using Seagate NAS equipment and the API was insecure. Appears that Seagate is to blame for making an API that has some vulnerabilities https://www.cvedetails.com/vulnerability-list/vendor_id-11967/Seagate.html https://www.cvedetails.com/vulnerability-list/vendor_id-1196...
- 00deadbeef 3y agoI got the email from HIBP but I've only ever owned one Seagate SATA HDD, never any of their NAS products, nothing cloud connected from them at all. This must be more than just Seagate.
- pfak 3y agoI got an email from HIBP and I have a seagate.com account, but not their NAS. I filed a warranty claim once with them.
- AdmiralAsshat 3y agoI've definitely never had a Seagate NAS before, but my email was in the breach. Quite annoying, because it's my personal gmail which I rarely ever use to sign up for anything. Given that I maybe only have 15-20 accounts tied to that email, I wonder if I should just cycle through each password through HaveIBeenPwned's service.
- devrand 3y agoTroy seems to disagree in the linked blog post: > That last number was the real kicker; when a third of the email addresses have never been seen before, that's statistically significant. This isn't just the usual collection of repurposed lists wrapped up with a brand-new bow on it and passed off as the next big thing; it's a significant volume of new data. When you look at the above forum post the data accompanied, the reason why becomes clear: it's from "stealer logs" or in other words, malware that has grabbed credentials from compromised machines. Apparently, this was sourced from the now defunct illicit.services website which (in)famously provided search results for other people's data along these lines